Manifest
whisk.yaml at the repository root declares the app: the name, which routes are public, the database, secrets by name, functions, webhooks, storage and the rest. Everything below is read from whisk.schema.json, which whisk doctor validates against and whisk schema prints. Required fields are marked.
| Field | Type | Default | Meaning |
|---|---|---|---|
whiskrequired | exactly 1 | Conventions version this repository follows. Changes within a version are additive. | |
namerequired | string matching ^[a-z0-9]([a-z0-9-]*[a-z0-9])?$ | App slug. The hostname <name>.<org>.whisk.page derives from it. | |
routes | object | none | |
routes.public | list of string matching ^/[^?#\s]*$ | none | Route globs reachable without identity. Everything else requires a signed-in team or customer identity. |
routes.challenge | list of string matching ^/[^?#\s]*$ | none | Public routes whose POSTs must carry a solved Altcha challenge. |
routes.csrf_off | list of string matching ^/[^?#\s]*$ | none | Routes exempt from the platform CSRF check. Rare; for embeds. |
routes.headers | map of string | none | Response headers to add or override on every response from this app. |
health | object | none | |
health.path | string matching ^/[^?#\s]*$ | "/health" | An absolute URL path without query or fragment. |
health.timeout | integer | 90 | Seconds allowed from container start to the first 200 from the health path. |
database | string matching ^(app|none|shared:[a-z0-9]([a-z0-9-]*[a-z0-9])?)$ | "app" | app: one database per app. shared:<name>: a schema inside an org-shared database. none: no database. |
migrate | string | Command run before traffic switches to a new deploy. A snapshot is taken first. | |
build | object | none | |
build.dockerfile | string | Path to a Dockerfile. Absent: the platform detects the stack with Railpack. | |
build.secrets | list of string matching ^[A-Z][A-Z0-9_]{1,63}$ | none | Secret names available only at build time, as BuildKit secret mounts. |
secrets | list of string matching ^[A-Z][A-Z0-9_]{1,63}$ | none | Names of secrets the app reads from the environment. Humans set values in the dashboard. |
env | map of string | none | Non-secret configuration injected into the environment. |
queue | object | none | |
queue.endpoint | string matching ^/[^?#\s]*$ | "/.whisk/inngest" | Path where the platform delivers function runs using the Inngest protocol. |
functions | list of any or any | none | |
functions[].namerequired | string matching ^[a-z0-9]([a-z0-9-]*[a-z0-9])?$ | ||
functions[].cron | string matching ^\S+\s+\S+\s+\S+\s+\S+\s+\S+$ | Five-field cron expression, evaluated in tz (default UTC). | |
functions[].tz | string matching ^[A-Za-z_]+(/[A-Za-z0-9_+-]+)*$ | IANA time zone name for cron, for example Pacific/Auckland. | |
functions[].event | string matching ^[a-z0-9]+([._/-][a-z0-9]+)*$ | Event name that triggers this function, for example po.created. | |
functions[].graphrequired | string matching ^(([^/.][^/]*|\.[^/.][^/]*|\.\.[^/]+|\.)/)*[^/]*\.graph\.ya?ml$ | Path, relative to the repository root, of the declared workflow graph. No segment may be "..". | |
functions[].concurrency | integer | ||
functions[].retries | integer | 3 | |
webhooks | list of object | none | |
webhooks[].namerequired | string matching ^[a-z0-9]([a-z0-9-]*[a-z0-9])?$ | ||
webhooks[].presetrequired | string matching ^[a-z0-9]([a-z0-9-]*[a-z0-9])?$ | A preset name from webhook-presets.yaml, hmac with inline settings, or token for unsigned providers. | |
webhooks[].secret | string matching ^[A-Z][A-Z0-9_]{1,63}$ | Name of the secret holding the signing secret. Must also appear in secrets. | |
webhooks[].handlerrequired | string matching ^/[^?#\s]*$ | Route in this app that receives verified deliveries. Reached only by the platform. | |
webhooks[].ip_allowlist | list of string matching ^([0-9]{1,3}\.){3}[0-9]{1,3}(/[0-9]{1,2})?$|^[0-9a-fA-F:]+(/[0-9]{1,3})?$ | none | |
webhooks[].hmac | object | Inline signature settings for preset hmac. Same fields as a preset in webhook-presets.yaml. | |
webhooks[].hmac.headerrequired | string matching ^[A-Za-z][A-Za-z0-9-]*$ | ||
webhooks[].hmac.algorithmrequired | "sha1" | "sha256" | "sha512" | ||
webhooks[].hmac.encodingrequired | "hex" | "base64" | ||
webhooks[].hmac.payloadrequired | string | ||
webhooks[].hmac.timestamp | object | ||
webhooks[].hmac.timestamp.fromrequired | "header" | "header_name" | ||
webhooks[].hmac.timestamp.name | string matching ^[A-Za-z][A-Za-z0-9-]*$ | ||
webhooks[].hmac.timestamp.pattern | string | ||
webhooks[].hmac.timestamp_format | "unix" | "unix_ms" | "rfc3339" | "unix" | |
webhooks[].hmac.id | object | ||
webhooks[].hmac.id.fromrequired | "header" | "header_name" | ||
webhooks[].hmac.id.name | string matching ^[A-Za-z][A-Za-z0-9-]*$ | ||
webhooks[].hmac.id.pattern | string | ||
webhooks[].hmac.signature_pattern | string | ||
webhooks[].hmac.signature_prefix | string | ||
webhooks[].hmac.tolerance_seconds | integer | ||
static | list of object | none | Folders published to object storage at deploy and served with immutable caching. |
static[].dirrequired | string matching ^(([^/.][^/]*|\.[^/.][^/]*|\.\.[^/]+|\.)/)*([^/.][^/]*|\.[^/.][^/]*|\.\.[^/]+|\.)/?$ | Folder, relative to the repository root, whose files are published. No segment may be "..". | |
static[].pathrequired | string matching ^/[^?#\s]*$ | An absolute URL path without query or fragment. | |
storage | boolean | false | true requests a bucket prefix and injects WHISK_STORAGE_*. |
kv | boolean | false | true gives this app a Valkey of its own as WHISK_KV_URL. Plan-gated. |
email | boolean | false | true allows this app to POST to the email send API. |
always_on | boolean | false | true keeps the app awake. Plan-gated. |
calls | list of string matching ^[a-z0-9]([a-z0-9-]*[a-z0-9])?$ | none | Slugs of apps in the same org this app may call with its service identity. |
network | "internal" | "public" | Where the app is served on Whisk On-Premise: internal (the default there) on the company's network only, public also on the outside address. whisk.run serves every app publicly and refuses internal. | |
customer_identity | "none" | "app" | "org" | "none" | Second audience for public-facing apps: none, a pool per app, or a pool shared across the org. |
previews | object | none | |
previews.database | "empty" | "empty" | Previews start with an empty database; empty is the only value. Seed test data from the app's migrations or a script. |
previews.ttl_days | integer | 3 | Days a preview lives after its last push, start or visit. |