| DISTRIBUTED OBJECT STORAGE - RUST - APACHE-2.0
Keldra.
Distributed object storage for application state.
Stable paths and opaque bytes, with the coordination primitives applications usually have to assemble around a blob store: streaming writes, compare-and-swap, immutable namespaces, bounded atomic programs, Zanzibar authorization, change notification, and materialized search indices.
View on GitHub
Read the guide
CURRENT RELEASE
0.11.3
Keldra system map
FIG. 02
objects
surface
indices
surface
Keldra
app model
gateways
surface
One authorized storage core serves objects, indices, and standard protocol gateways from any active node.
Any node
can accept public requests
2+1
fixed erasure-coded payload durability
8
materialized index engines
3 APIs
native gRPC, S3, and Git on one endpoint
SECTION
Storage primitives that compose.
The object API keeps each operation explicit, so applications can select the ordering and durability contract they actually need.
Objects
Streaming writes and stable paths
Put, get, head, delete, batch reads, bulk writes, prefix listing, optional retained versions, content deduplication, and change watches.
Coordination
CAS and write-once data
PutIfAbsent, exact-version compare-and-swap, conditional delete, and immutable puts make publication intent visible at the API boundary.
State transitions
Bounded atomic programs
Deterministic JSON programs can protect a small multi-path invariant without routing ordinary objects or large media through a transaction engine.
Scale out without changing the API.
Start with one process, then add capacity and availability while clients continue addressing the same tenant, bucket, and path model.
DISTRIBUTED CORE
01
Any-node ingress
Every active node can accept a request and route work to the correct authority.
02
Weighted placement
Capacity-weighted rendezvous hashing places data across heterogeneous nodes.
03
Separated authority
Raft carries compact membership and publication decisions, not object bodies or index files.
04
Online growth
Large objects use complete replicas below erasure width, then move online to the fixed erasure profile as nodes join.
One authoritative object model.
Every successful write creates immutable content and advances one exact-path head. Derived structures remain reconstructible.
AUTHORITY MODEL
Request
→
Immutable content
→
Exact-path head
Stable numeric IDs
BLAKE3 identity
Ordered journals
Disposable caches
SECTION
Search is a materialized view, not a second database.
Bucket-local definitions consume ordered object journals, publish complete immutable generations, and return freshness evidence with every query.
P
Path
Prefix discovery and stable pagination over object paths.
M
Metadata
Predicates over path, content type, length, and retained head fields.
J
Typed JSON
Declared predicates, ordering, facets, full text, and numeric aggregates.
T
Full text
Fielded text and phrase search over selected JSON pointers.
V
Vector
Cosine, dot-product, or Euclidean similarity with fixed dimensions.
H
Hybrid
Weighted full-text and vector retrieval in one definition.
G
Git source
Commit and tree-path lookup over Git manifests and pack locations.
X
Tensor
Model and tensor-name lookup over typed tensor manifests.
Ordered journals → bounded immutable segments → complete generation → freshness-bearing results
NO PARTIAL GENERATIONS
SECTION
Protocol-native at the edge.
Keldra exposes native storage capabilities and familiar ecosystem protocols on the same authorized public listener.
Native API
gRPC and Rust client
Generated versioned contracts cover objects, indices, authorization, administration, accounting, and PersonalDB, with authenticated Rust helpers for common workflows.
Object ecosystem
S3 SigV4 gateway
Path-style S3 requests work with the AWS CLI and official SDKs while Keldra application credentials and Zanzibar policy remain authoritative.
Source control
Git smart HTTP
Authenticated push, pull, and clone use ordinary Keldra authorization; bucket owners can explicitly enable anonymous reads for public repositories.
SECTION
Private by default, observable in production.
Authentication, authorization, placement, and operational evidence are designed as first-class parts of the storage system.
Z
Zanzibar authorization
Tenant and bucket roles, customer schemas, relationship tuples, and authorization-filtered index results.
TLS
Authenticated peers
Short-lived client JWTs protect public APIs while mandatory peer mTLS isolates cluster traffic.
DB
PersonalDB
Witnessed predecessor-linked SQLite changeset logs, explicit projections, catch-up streams, and signed descriptors.
Σ
Usage accounting
Authorized bucket or path-prefix aggregates report objects, logical bytes, traffic, and source freshness.
From one node to a cluster.
The published multi-platform container runs on Linux AMD64 and ARM64. The repository includes Docker Compose and single- and three-node qualification workflows.
FIVE-MINUTE PATH
$
docker compose -f crates/keldra/docker-compose.yml up -d
$
keldra create-bucket objects
$
keldra put example objects hello.txt ./hello.txt
$
keldra get example objects hello.txt
Public, executable evidence.
Release gates exercise the same public interfaces clients use, including real S3 SDK traffic, Git clients, index queries, rolling restarts, and online cluster growth.
RELEASE EVIDENCE
01
Single-node qualification
02
Three-node cluster qualification
03
All eight index engines
04
S3 and Git real-client workflows
05
Linux AMD64 + ARM64 image
OPEN SOURCE
Read the code, contracts, and qualification evidence.
Keldra is Apache-2.0 licensed. The repository is the source of truth for released capabilities, setup, architecture RFCs, and current operational limits.
Explore Keldra
CR
Courtney Robinson
zcourts.com
Building the infrastructure for the agentic future.
LET'S CONNECT
courtney@crlog.info
Based in London
© 2025 Courtney Robinson. All rights reserved.