Skip to content
Apexify.jsDocs
Apexify.js version v5.4.5

Advanced / Runtime Resource Governance.Mdx · architecture

Runtime validation & resource governance

Current Apexify.js 6.0.0 documentation for Runtime validation & resource governance.

apexify.jsRuntime: nodeCURRENTSince 6.0.0

Apexify.js 6 treats runtime validation and bounded resource usage as part of the public contract. TypeScript is not a security boundary: JavaScript/JSON callers, non-finite numbers, oversized images/scenes/media, excessive frame counts, invalid runtime configuration, and unbounded persistent/transient registries are rejected at runtime.

SOURCEtypescript
typescript
Studio
import {  configureApexifyRuntime,  getDefaultApexifyRuntimeConfig,  resolveApexifyRuntimeConfig,  resetApexifyRuntimeConfig,  ApexifyInputError,  ApexifyConfigError,  ApexifyResourceLimitError,} from "apexify.js";

Complete default RenderLimits

These values are the current 6.0.0 defaults from DEFAULT_APEXIFY_RUNTIME_CONFIG.

LimitDefaultGoverns
maxCanvasDimension16,384Maximum width/height of a canvas/surface
maxTotalPixels67,108,864Maximum pixels in one canvas/surface
maxCollectionItems2,048Generic bounded high-cost collections and Phase 14 persistent/transient admission state
maxBackgroundLayers128Canvas background layers
maxFiltersPerOperation64Filter list length
maxSceneLayers2,000Total scene layer count/work
maxSceneTotalPixels268,435,456Aggregate root + nested scene surface pixels
maxNestedSurfaces64Total nested surfaces
maxSceneDepth32Scene/surface nesting depth
maxSceneImages2,000Scene image layer count
maxSceneTextLayers1,000Scene text layer count
maxSceneCharts256Scene chart layer count
maxTextLength1,000,000Governed aggregate/pathological text content
maxRemoteAssets128Remote assets referenced by governed compositions
maxRemoteImageBytes32 MiBRemote image transfer ceiling
maxRemoteVideoBytes512 MiBRemote video transfer ceiling
maxImageSourceBytes64 MiBImage source-byte ceiling
maxDecodedImagePixels67,108,864Decoded raster pixel ceiling
maxDecodedImageFrames128Decoded multi-frame image frame ceiling
maxSvgElements10,000SVG element complexity ceiling
maxGifFrames1,000GIF input/generated frames
maxGifDimension4,096GIF width/height
maxGifResourceCost268,435,456Width × height × effective frame count budget
maxAudioDurationSeconds600Audio duration
maxAudioSampleRate192,000Audio sample rate
maxAudioChannels2Mono/stereo channel count
maxAudioEvents20,000Sequence/timeline events
maxAudioLayers1,024Synthesis/composition layers
maxAudioPartials4,096Harmonic partial budget
maxAudioBytes256 MiBGoverned peak audio working-memory estimate
maxVideoDurationSeconds14,400Video duration
maxVideoFps240Video frame rate
maxVideoBitrateKbps200,000Video bitrate
maxVideoOverlays256Video overlays
maxVideoMergeInputs32Video merge/splice inputs
maxVideoExtractedFrames2,000Extracted video frames
maxVideoAudioTracks64Video audio tracks
maxVideoPipelineLayers256Declarative video pipeline layers
maxBatchOperations256Batch/chain operation count
maxBatchConcurrency4Concurrent batch/layout workers
maxConcurrentRemoteFetches8Global concurrent remote media requests

Most limits must be finite positive integers. maxAudioDurationSeconds, maxVideoDurationSeconds, and maxVideoFps are finite positive continuous limits. Additional configuration invariants include:

  • maxAudioChannels <= 2;
  • maxSceneDepth <= maxNestedSurfaces;
  • maxSceneTotalPixels >= maxTotalPixels;
  • maxBatchConcurrency <= maxBatchOperations;
  • maxRemoteImageBytes <= maxImageSourceBytes.

Phase 14 admission-bound clarification

maxCollectionItems is not only an array-length limit. Final Phase 14 hardening also uses it as the finite admission ceiling for process/instance state that can otherwise grow from caller-controlled unique keys:

  • painter.assets registry entries, nested values and palette entries;
  • plugin API registrations, installed/pending plugin names, and a plugin installation rollback journal;
  • process-wide registered/pending native font keys;
  • unique in-flight decoded-image promises;
  • template flex/grid child collections.

Template flex/grid child measurement is also executed through a worker pool capped by maxBatchConcurrency; it does not create one active measurement promise per user-provided child.

These checks mean a workload can fail with ApexifyResourceLimitError before a registry mutation, decode launch, layout fan-out, or native font admission. Treat that as intentional backpressure/resource policy.

Network policy defaults

FieldDefault
allowedProtocolshttp:, https:
timeoutMs15,000
maxRedirects5
retryAttempts3
retryBaseDelayMs200
retryMaxDelayMs3,000
retryJitterRatio0.2
honorRetryAftertrue
trustedNetworkAccessfalse
allowedHostsempty
userAgentApexify.js/6

trustedNetworkAccess: true is invalid without at least one explicit allowedHosts entry. See Security deployment for DNS/SSRF/redirect behavior.

Cache policy defaults

SOURCEtypescript
typescript
Studio
{  enabled: true,  ttlMs: 5 * 60_000,  maxEntries: 128,  maxBytes: 128 * 1024 * 1024,}

The decoded resource cache is bounded by both entry count and bytes and expires entries by TTL. Unique in-flight decodes are separately bounded and are removed from the in-flight map in finally. Disable/reduce caching when process memory is more constrained; do not wrap Apexify with an unbounded global cache.

FFmpeg policy defaults

SOURCEtypescript
typescript
Studio
{  processTimeoutMs: 5 * 60_000,  probeTimeoutMs: 5_000,  maxStdoutBytes: 10 * 1024 * 1024,  maxStderrBytes: 30 * 1024 * 1024,}

ffmpegPath / ffprobePath are optional. The session layer can also use APEXIFY_FFMPEG_PATH / APEXIFY_FFPROBE_PATH before falling back to commands on PATH.

Temp policy defaults

SOURCEtypescript
typescript
Studio
{  rootDirectory: undefined,  retainFiles: false,}

Temporary workspace parent precedence is explicit operation/session option → runtime config → APEXIFY_TEMP_DIR → OS temp. APEXIFY_RETAIN_TEMP_FILES=true is a compatibility/debug override and should remain false in production.

Diagnostics

diagnostics.handler is optional and receives structured { level, code, message, details? } events. The configuration validator rejects a non-function handler.

Read and override policy

SOURCEtypescript
typescript
Studio
const current = getDefaultApexifyRuntimeConfig();console.log(current.limits.maxTotalPixels); configureApexifyRuntime({  limits: {    maxCanvasDimension: 8192,    maxTotalPixels: 32_000_000,    maxDecodedImagePixels: 32_000_000,    maxBatchConcurrency: 2,    maxAudioDurationSeconds: 120,    maxAudioBytes: 128 * 1024 * 1024,  },  network: {    timeoutMs: 10_000,  },}); resetApexifyRuntimeConfig();

configureApexifyRuntime() merges supplied sections into the current process-wide config and validates the resulting whole configuration. resolveApexifyRuntimeConfig() validates/normalizes without changing the process-wide default.

Do not raise a limit merely to silence ApexifyResourceLimitError. A higher canvas/decoded-image/GIF/audio/video/concurrency/registry budget increases worst-case memory, CPU, I/O, native-state, or process pressure.

Validation coverage

Resource/validation policy is enforced across the high-cost public surface, including:

  • canvases, backgrounds, gradients, patterns and filters;
  • image placement/decode, crop/mask/distortion/mesh/filter utilities, collage/stitch/blend/palette;
  • text arrays/content/coordinates/typography effects and native-font registration admission;
  • scene roots, nested surfaces, layer/domain counts, aggregate pixels/text/remote assets and transforms;
  • templates, including bounded flex/grid child collections and measurement fan-out;
  • assets and plugin registries/installation journals;
  • GIF dimensions/frames/generated frames/resource cost/overlays;
  • audio duration/sample rate/channels/events/layers/partials and peak working-memory estimates;
  • video time/FPS/dimensions/bitrate/overlays/merge inputs/frame extraction/audio tracks/pipeline layers;
  • paths/pixels/hit-detection collections;
  • batch/chain work;
  • output/upload/save validation.

Apexify also inspects image metadata so oversized decoded images can be rejected before full decode where practical, and validates audio/video structures before the largest allocation/process work where practical.

Error handling

SOURCEtypescript
typescript
Studio
try {  await painter.createCanvas({ width: 50_000, height: 50_000 });} catch (error) {  if (error instanceof ApexifyResourceLimitError) {    console.error(error.limit, error.maximum, error.actual);  }}

Resource-limit errors are policy failures. Do not automatically retry the unchanged request. Reduce the work or deliberately adjust deployment policy after measuring available capacity.

Apexify 6 runtime code uses the structured ApexifyError hierarchy for runtime/public failure contracts. Do not depend on generic Error messages for branching logic; use the concrete error class/code and documented metadata.

Audio memory accounting

maxAudioBytes is a peak-allocation guard. It accounts for relevant coexisting Float32 render/mix/source/transformed buffers and final PCM16 WAV allocation rather than checking only final output bytes.

Concurrency

batch() is bounded by maxBatchOperations and maxBatchConcurrency. Template flex/grid measurement uses the same bounded worker concept. Remote media acquisition is separately bounded by maxConcurrentRemoteFetches, while unique in-flight image decodes additionally have a finite collection admission limit. A deployment may therefore accept a large high-level job while allowing only a small number of active heavy operations and remote requests.

Use Performance & memory for tuning and Security deployment for untrusted services.

Next steps