Advanced / Runtime Resource Governance.Mdx · architecture
Runtime validation & resource governance
Current Apexify.js 6.0.0 documentation for Runtime validation & resource governance.
Apexify.js 6 treats runtime validation and bounded resource usage as part of the public contract. TypeScript is not a security boundary: JavaScript/JSON callers, non-finite numbers, oversized images/scenes/media, excessive frame counts, invalid runtime configuration, and unbounded persistent/transient registries are rejected at runtime.
Complete default RenderLimits
These values are the current 6.0.0 defaults from DEFAULT_APEXIFY_RUNTIME_CONFIG.
| Limit | Default | Governs |
|---|---|---|
maxCanvasDimension | 16,384 | Maximum width/height of a canvas/surface |
maxTotalPixels | 67,108,864 | Maximum pixels in one canvas/surface |
maxCollectionItems | 2,048 | Generic bounded high-cost collections and Phase 14 persistent/transient admission state |
maxBackgroundLayers | 128 | Canvas background layers |
maxFiltersPerOperation | 64 | Filter list length |
maxSceneLayers | 2,000 | Total scene layer count/work |
maxSceneTotalPixels | 268,435,456 | Aggregate root + nested scene surface pixels |
maxNestedSurfaces | 64 | Total nested surfaces |
maxSceneDepth | 32 | Scene/surface nesting depth |
maxSceneImages | 2,000 | Scene image layer count |
maxSceneTextLayers | 1,000 | Scene text layer count |
maxSceneCharts | 256 | Scene chart layer count |
maxTextLength | 1,000,000 | Governed aggregate/pathological text content |
maxRemoteAssets | 128 | Remote assets referenced by governed compositions |
maxRemoteImageBytes | 32 MiB | Remote image transfer ceiling |
maxRemoteVideoBytes | 512 MiB | Remote video transfer ceiling |
maxImageSourceBytes | 64 MiB | Image source-byte ceiling |
maxDecodedImagePixels | 67,108,864 | Decoded raster pixel ceiling |
maxDecodedImageFrames | 128 | Decoded multi-frame image frame ceiling |
maxSvgElements | 10,000 | SVG element complexity ceiling |
maxGifFrames | 1,000 | GIF input/generated frames |
maxGifDimension | 4,096 | GIF width/height |
maxGifResourceCost | 268,435,456 | Width × height × effective frame count budget |
maxAudioDurationSeconds | 600 | Audio duration |
maxAudioSampleRate | 192,000 | Audio sample rate |
maxAudioChannels | 2 | Mono/stereo channel count |
maxAudioEvents | 20,000 | Sequence/timeline events |
maxAudioLayers | 1,024 | Synthesis/composition layers |
maxAudioPartials | 4,096 | Harmonic partial budget |
maxAudioBytes | 256 MiB | Governed peak audio working-memory estimate |
maxVideoDurationSeconds | 14,400 | Video duration |
maxVideoFps | 240 | Video frame rate |
maxVideoBitrateKbps | 200,000 | Video bitrate |
maxVideoOverlays | 256 | Video overlays |
maxVideoMergeInputs | 32 | Video merge/splice inputs |
maxVideoExtractedFrames | 2,000 | Extracted video frames |
maxVideoAudioTracks | 64 | Video audio tracks |
maxVideoPipelineLayers | 256 | Declarative video pipeline layers |
maxBatchOperations | 256 | Batch/chain operation count |
maxBatchConcurrency | 4 | Concurrent batch/layout workers |
maxConcurrentRemoteFetches | 8 | Global concurrent remote media requests |
Most limits must be finite positive integers. maxAudioDurationSeconds, maxVideoDurationSeconds, and maxVideoFps are finite positive continuous limits. Additional configuration invariants include:
maxAudioChannels <= 2;maxSceneDepth <= maxNestedSurfaces;maxSceneTotalPixels >= maxTotalPixels;maxBatchConcurrency <= maxBatchOperations;maxRemoteImageBytes <= maxImageSourceBytes.
Phase 14 admission-bound clarification
maxCollectionItems is not only an array-length limit. Final Phase 14 hardening also uses it as the finite admission ceiling for process/instance state that can otherwise grow from caller-controlled unique keys:
painter.assetsregistry entries, nested values and palette entries;- plugin API registrations, installed/pending plugin names, and a plugin installation rollback journal;
- process-wide registered/pending native font keys;
- unique in-flight decoded-image promises;
- template flex/grid child collections.
Template flex/grid child measurement is also executed through a worker pool capped by maxBatchConcurrency; it does not create one active measurement promise per user-provided child.
These checks mean a workload can fail with ApexifyResourceLimitError before a registry mutation, decode launch, layout fan-out, or native font admission. Treat that as intentional backpressure/resource policy.
Network policy defaults
| Field | Default |
|---|---|
allowedProtocols | http:, https: |
timeoutMs | 15,000 |
maxRedirects | 5 |
retryAttempts | 3 |
retryBaseDelayMs | 200 |
retryMaxDelayMs | 3,000 |
retryJitterRatio | 0.2 |
honorRetryAfter | true |
trustedNetworkAccess | false |
allowedHosts | empty |
userAgent | Apexify.js/6 |
trustedNetworkAccess: true is invalid without at least one explicit allowedHosts entry. See Security deployment for DNS/SSRF/redirect behavior.
Cache policy defaults
The decoded resource cache is bounded by both entry count and bytes and expires entries by TTL. Unique in-flight decodes are separately bounded and are removed from the in-flight map in finally. Disable/reduce caching when process memory is more constrained; do not wrap Apexify with an unbounded global cache.
FFmpeg policy defaults
ffmpegPath / ffprobePath are optional. The session layer can also use APEXIFY_FFMPEG_PATH / APEXIFY_FFPROBE_PATH before falling back to commands on PATH.
Temp policy defaults
Temporary workspace parent precedence is explicit operation/session option → runtime config → APEXIFY_TEMP_DIR → OS temp. APEXIFY_RETAIN_TEMP_FILES=true is a compatibility/debug override and should remain false in production.
Diagnostics
diagnostics.handler is optional and receives structured { level, code, message, details? } events. The configuration validator rejects a non-function handler.
Read and override policy
configureApexifyRuntime() merges supplied sections into the current process-wide config and validates the resulting whole configuration. resolveApexifyRuntimeConfig() validates/normalizes without changing the process-wide default.
Do not raise a limit merely to silence ApexifyResourceLimitError. A higher canvas/decoded-image/GIF/audio/video/concurrency/registry budget increases worst-case memory, CPU, I/O, native-state, or process pressure.
Validation coverage
Resource/validation policy is enforced across the high-cost public surface, including:
- canvases, backgrounds, gradients, patterns and filters;
- image placement/decode, crop/mask/distortion/mesh/filter utilities, collage/stitch/blend/palette;
- text arrays/content/coordinates/typography effects and native-font registration admission;
- scene roots, nested surfaces, layer/domain counts, aggregate pixels/text/remote assets and transforms;
- templates, including bounded flex/grid child collections and measurement fan-out;
- assets and plugin registries/installation journals;
- GIF dimensions/frames/generated frames/resource cost/overlays;
- audio duration/sample rate/channels/events/layers/partials and peak working-memory estimates;
- video time/FPS/dimensions/bitrate/overlays/merge inputs/frame extraction/audio tracks/pipeline layers;
- paths/pixels/hit-detection collections;
- batch/chain work;
- output/upload/save validation.
Apexify also inspects image metadata so oversized decoded images can be rejected before full decode where practical, and validates audio/video structures before the largest allocation/process work where practical.
Error handling
Resource-limit errors are policy failures. Do not automatically retry the unchanged request. Reduce the work or deliberately adjust deployment policy after measuring available capacity.
Apexify 6 runtime code uses the structured ApexifyError hierarchy for runtime/public failure contracts. Do not depend on generic Error messages for branching logic; use the concrete error class/code and documented metadata.
Audio memory accounting
maxAudioBytes is a peak-allocation guard. It accounts for relevant coexisting Float32 render/mix/source/transformed buffers and final PCM16 WAV allocation rather than checking only final output bytes.
Concurrency
batch() is bounded by maxBatchOperations and maxBatchConcurrency. Template flex/grid measurement uses the same bounded worker concept. Remote media acquisition is separately bounded by maxConcurrentRemoteFetches, while unique in-flight image decodes additionally have a finite collection admission limit. A deployment may therefore accept a large high-level job while allowing only a small number of active heavy operations and remote requests.
Use Performance & memory for tuning and Security deployment for untrusted services.