finds.dev← search

// the find

thetanil/qwe

C · Apache-2.0 · updated Sep 2026

Qualified Workflow Engine

qwe is a single static C99 binary that runs GitHub-Actions-style YAML workflows locally or over ssh, with LuaJIT plugins for individual steps and no daemon or runtime to install. It's for someone who wants Ansible-style idempotent task running without pulling in Python, or who wants CI-shaped job graphs (needs:, outputs, secrets) on a bare VM without standing up a full CI/CD stack.

The engine is process-per-step with a forked group and timeout, so a stuck plugin can't wedge the whole run and cancel/timeout kills the group cleanly. Secrets are handled properly: encrypted at rest with libsodium, injected only via env/with templating, never on a command line, and redacted from logs. Plugin loading has a genuinely enforced restriction — no top-level code outside local/require/return — checked statically at validate time before any plugin code executes, which is a real static guarantee rather than a lint suggestion. CI discipline is unusually high for a 0-star project: asan/ubsan/valgrind on every push, an 85%-per-file coverage gate that fails the build, and nightly fuzzing on the YAML parser.

Linux x86_64 only — no macOS or Windows, which rules out a lot of local dev use and mixed-OS fleets. The plugin trust model is honestly documented but still thin: check/apply run with full io and os.execute, so the top-level-code restriction stops accidents, not a malicious or compromised plugin — you're trusting the workflow directory outright. `qwe serve` is a stub that just exits 2, so anything beyond one-shot run/validate isn't there yet. Onboarding cost is real: Bazel 8.7.0 pinned exactly, every dependency vendored under third_party/, no `cargo install`/`go install` equivalent, so building from source is heavier than the binary-only story suggests.

View on GitHub →

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →