The rules

From SKILL.md, the same document your agent reads.

2. The rules

An app on Whisk is a stateless HTTP server in a container.

  1. Listen on PORT (always 8080) on all interfaces.
  2. Answer GET <health.path> with 200 when ready to serve. Default /health.
  3. Log to stdout and stderr. JSON lines are indexed by field; plain lines are indexed as text.
  4. Write files only under /tmp. Everything else is read-only. /tmp is emptied on every restart; files that must last go to storage (§9, files a job keeps). /tmp is memory: what you keep there and what the process uses share WHISK_MEMORY_BYTES (256 MiB on Free), and a run that goes over is killed without SIGTERM.
  5. Exit cleanly on SIGTERM within the grace period (default 28 seconds).
  6. Read configuration and secrets from the environment. Never from files in the repository.
  7. Trust identity only from the X-Whisk-* headers, which only the platform can set.
  8. Treat every queue delivery and webhook as possibly repeated; use the provided IDs to dedupe.
  9. Start fast. Under five seconds from process start to health 200 is the target, because sleeping apps wake on demand.

Keep it light. Memory is what an app costs to run, and a small app wakes fast and is never killed for running out. Stream large files and query results in chunks (storage reads, CSV and spreadsheet parsing, database cursors) instead of loading them whole into memory or /tmp. Process a big job as many small steps, each handling one batch. Let the database filter, sort and total rather than fetching every row to do it in code. React to an event or webhook when something changes instead of a schedule that checks every few minutes, and choose the longest schedule the business can live with. Load heavy libraries only in the code path that needs them. Pages and API reads that can be a little old should send Cache-Control: private, max-age=<seconds> (public for a page anyone may see): the edge answers repeat requests from its cache, per person and for up to an hour, without waking the app. A response that sets a cookie is never cached.