Changes for version 0.24 - 2026-08-20
- Large uploads no longer cost what they weigh. A multipart part over 64KB is written to a temp file as it arrives rather than copied into memory, and Punk::Upload carries a `path` and an `fh` to it. Measured end to end through a socket into a handler holding the upload, a 128MB upload costs a worker 15.5MB of RSS against roughly 275MB before.
- ADDS: the `upload_dir` keyword, naming where a large part is spilled. It decides the filesystem, which decides whether save() is a rename, and it decides what shares a filesystem with attacker controlled bytes. Temp file names owe nothing to the client's filename, and every file is removed when its request ends.
- ADDS: Punk::Plugin::Blob stores an on-disk upload without reading it into memory: hashed where it lies through Apophis's identify_fh, then moved into the store.
- ADDS: Punk::Plugin::Idempotency - Idempotency-Key on unsafe methods, replaying the stored response.
- ADDS: Punk::Plugin::Metrics - a Prometheus /metrics endpoint
- ADDS: Punk::Plugin::Health - /healthz and /readyz,
- ADDS: Punk::Plugin::CSP - Content-Security-Policy with a per request nonce.
- ADDS: Punk::Plugin::ConditionalGet - ETags and 304s for dynamic responses.
- ADDS: Punk::Plugin::Blob, content addressed uploads on Apophis. $c->blob_put stores by contents, so a user's filename never becomes a filesystem path. $c->blob_send serves through send_file as a download.
- ADDS: Apophis to the prerequisites.
Documentation
the Punk command line
Modules
a MVC web framework
the per-application registry and boot compiler
the authentication battery
password hashing
cross-origin resource sharing
single-use CSRF tokens
a pluggable cache with TTL
a cache store on disk, shared by the whole worker pool
an in process cache store, bounded by bytes
the punk command line: registry, dispatcher and commands
YAML configuration with secrets kept out of the file
the per-request object
base class for Punk controllers
the development error page
an async result that runs on the loop, or blocks
scaffold a new Punk application
security response headers
a level-based logger
the storage-agnostic model tier
the default DBI backend for Punk models
a non-blocking backend for Punk models
a directory of markdown as a documentation site
the api mount: spec-first operations
base class for Punk plugins
content addressed storage for uploads
Content-Security-Policy with a per request nonce
ETags and 304s for dynamic responses
liveness and readiness probes that mean different things
Idempotency on unsafe methods
a Prometheus endpoint whose labels cannot run away
give every request an id
sitemap.xml and robots.txt from the route table
rate limiting and IP blocking over Hyperman's shared arena
a lazy wrapper over the PSGI environment
a response builder
the compiled-at-boot route tables (XS)
the handle an under returns
a Server-Sent Events stream
the bounded body of a ranged send_file response
signed cookie sessions
serving files from a directory
an in-process test client for Punk applications
a pure-Perl RFC 6455 codec for testing WebSocket servers
the client side of one WebSocket connection
the outbound HTTP agent on the context
an uploaded file from a multipart form
collecting request validation
the Template::Stencil view engine
the pluggable view engine registry (XS)
a WebSocket connection
pub/sub groups of WebSocket connections
Examples
- example/Chat/README.pod
- example/Chat/app.psgi
- example/Chat/bin/make-cert
- example/Chat/bin/punk-chat
- example/Chat/bin/tls-proxy
- example/Chat/docs/api.md
- example/Chat/docs/index.md
- example/Chat/docs/reference/config.md
- example/Chat/docs/running.md
- example/Chat/docs/websockets.md
- example/Chat/lib/Chat.pm
- example/Chat/lib/Chat/Auth.pm
- example/Chat/lib/Chat/Bus.pm
- example/Chat/lib/Chat/Controller/API/Message.pm
- example/Chat/lib/Chat/Controller/WS/Chat.pm
- example/Chat/lib/Chat/Controller/Web/Chat.pm
- example/Chat/lib/Chat/Model/Message.pm
- example/Chat/lib/Chat/Schema.pm
- example/Chat/openapi.json
- example/Chat/root/static/chat.css
- example/Chat/root/static/chat.js
- example/Chat/root/templates/index.tmpl
- example/Chat/root/templates/layout.tmpl
- example/Chat/root/templates/room.tmpl
- example/Chat/tls/server.crt
- example/Chat/tls/server.key