ROM Extras overview
Optional providers with explicit host boundaries and bounded qualification evidence..
Database providers and optional integrations for ROM. ROM-extras preserves the Resource → action → atomic commit → event contract.
Project status
ROM-extras is under development. Full ROM Storage providers are not supported yet. The components below have implementation and test evidence within the limits stated in their guides.
Databases
A shared bounded SQL executor has real transaction and restart tests for six database engines:
These are executor profiles. Full ROM Storage integration remains pending.
Integrations
| Extension | Implemented and verified | Remaining work |
|---|---|---|
| Webhooks | Bounded JSON, signatures, HTTPS receivers and SQLite/redb Runtime recovery. | Production receiver profiles and release acceptance. |
| NATS JetStream | Acknowledgements, deduplication, Runtime recovery, TLS and reconnect. | Production topology and release acceptance. |
| RabbitMQ | Mandatory confirms, persistence, redelivery, uncertainty handling and TLS. | Replicated failover and release acceptance. |
| Kafka | Offsets, duplicates, Runtime recovery, TLS/SASL, restart and independent consumers. | Additional notification connectors and release acceptance. |
| Azure Blob | Public blob port and persistent Azurite conformance. | Cloud profiles and further lifecycle faults. |
| S3-compatible | RustFS local public-port qualification; SeaweedFS strict burst failure retained. | Cloud profiles and further lifecycle faults. |
| OIDC presets | Explicit issuers and signed synthetic-token verification. | Live provider login and discovery profiles. |
| Secrets and KMS | Host contracts, OpenBao acceptance cases and reference-only native host preparation. | Further provider profiles and family acceptance. |
Search and projections
| Component | Implemented and verified | Remaining work |
|---|---|---|
| Shared core | Durable checkpoints, bounded workers, public SQLite/redb history and authorized search. | Generation switching and full projection-family acceptance. |
| OpenSearch | Native writes and typed search with current authorization. | Generation switching and final provider acceptance. |
| Qdrant | Rust wire transport, native revision-fence and restart probes. | Full projection target, vector queries and Runtime integration. |
Maps
Generic map providers are in scope. The local typed-core increment has boundary and public-consumer tests. Nominatim search/reverse has controlled HTTPS and public-consumer tests; native-service qualification remains pending. OSRM routing passed qualification on an authored driving graph before and after restart. Configured raster/vector TileJSON and MapLibre styles have controlled HTTPS and independent-consumer tests. A local Nginx fixture qualifies metadata delivery before and after restart; tile content and rendering remain unqualified. MapTiler search/reverse has controlled HTTPS and independent-consumer tests; native-service qualification and styles/tiles remain pending. Browser URLs reject query credentials by default; an explicit host grant can admit one browser-intended token. The ROM/UI integration example remains in progress.
Roadmap
OpenTelemetry, additional notification connectors, and backup, migration and provenance-preserving import tools remain in scope.
Verify locally
Use Rust 1.99, a native linker, CMake, Make, pkg-config, maintained OpenSSL development files, and Node.js. OpenSSL also generates ephemeral synthetic test signing keys. See Kafka build requirements. Run:
./scripts/check The full actual-backend verifier is ./scripts/check-all. It requires the configured services and Python 3 for projection probes.
GitHub hosts source code. GitHub Actions is disabled.