LabHit Docs

Extension Marketplace

The LabHit Extension Marketplace will be a registry for publishing, discovering, and installing pipeline extensions. It is rolling out: the registry data model and .lhx packaging format exist today, but there is not yet a hosted marketplace, any published extensions, or a client-side publish path. You can build and package extensions now and share .lhx files directly until hosted publishing lands.

Overview

Extensions are sandboxed WASM modules that add capabilities to your pipelines. Each extension declares its category, required permissions, and interface through a manifest file.

Extension Categories

Category Purpose Examples
source Code checkout and repository management Git clone, SVN, Mercurial
build Compilation and artifact generation Container build, Cargo, npm
test Test execution and reporting Unit tests, integration tests, fuzzing
scan Security scanning and code analysis SAST, dependency audit, license check
deploy Deployment to target environments Kubernetes, cloud functions, CDN
notify Notifications and alerting Slack, email, webhook
report Reporting and metrics Coverage, performance, changelog
utility General-purpose tools Cache management, file manipulation

Searching Extensions

Discovery is rolling out with the hosted marketplace. The labhit extension search CLI is currently a stub (not yet connected to a remote registry). The GraphQL query and dashboard below run against the extension registry, which has no published extensions yet.

CLI

# Search by keyword
labhit extension search "kubernetes"

# Search by category
labhit extension search --category deploy

# List all extensions
labhit extension search ""

GraphQL API

query {
  extensions(query: "kubernetes", category: "deploy", limit: 10) {
    id
    name
    description
    category
    downloadCount
  }
}

Dashboard

Visit the Marketplace page in the dashboard to browse extensions with category filters and search.

Installing Extensions

Today, labhit extension install installs a local .lhx package file. There is no hosted registry to install from yet, so installing by name and version rolls out with the marketplace.

# Install a local .lhx package
labhit extension install ./my-deployer-1.0.0.lhx

A .lhx package is a gzip-compressed tar archive containing the WASM module, manifest, and documentation. Package integrity is verified via SHA-256 hash.

Once the hosted marketplace is live, you will be able to install by name and version:

# Coming soon: install from the hosted registry
labhit extension install deploy/kubernetes
labhit extension install deploy/kubernetes --version 1.2.0

Packaging Extensions for Distribution

Build and pack your extension into a portable .lhx package today. Hosted publishing to the marketplace registry is rolling out. Until it lands, share the .lhx file directly or install it locally with labhit extension install.

Prerequisites

  • The extension WASM module compiled for wasm32-wasip1 or wasm32-wasip2
  • An extension.yaml manifest

Extension Manifest

id: deploy/my-deployer
name: My Deployer
description: Deploy to my cloud provider
version: 1.0.0
category: deploy
capabilities:
  - network
  - env:MY_CLOUD_TOKEN

Build and Pack

# Initialize a new extension project
labhit extension init my-deployer

# Build the WASM module
labhit extension build

# Test locally
labhit extension test

# Pack into a distributable .lhx package
labhit extension pack

pack produces a <name>-<version>.lhx file and prints its size and SHA-256 hash.

Package Format (.lhx)

A .lhx file is a gzip-compressed tar archive containing:

File Required Description
extension.yaml Yes Extension manifest
*.wasm Yes Compiled WASM module
README.md No Documentation shown on the marketplace page
LICENSE No License file

Maximum package size: 50 MB.

Using Extensions in Pipelines

Reference installed extensions with the use: directive:

engine: "1"
pipeline:
  name: deploy-pipeline
stages:
  checkout:
    use: source/git
    with:
      repository: https://github.com/my-org/my-app
      branch: main

  build:
    after: [checkout]
    use: build/container
    with:
      dockerfile: ./Dockerfile
      tag: my-app:latest

  deploy:
    after: [build]
    use: deploy/kubernetes
    with:
      cluster: production
      manifest: ./k8s/deployment.yaml

An extension's required permissions (network, filesystem, secrets) are declared in its own extension.yaml manifest, not in the pipeline's sandbox: block.

Extension Permissions

Extensions run in sandboxed environments with deny-by-default permissions. Each extension must declare the capabilities it needs in its manifest.

Capability What It Grants
filesystem Read/write access to the pipeline workspace
network Outbound network access
env:VAR_NAME Access to a specific environment variable

Capabilities are enforced at runtime. An extension that attempts to access a resource it hasn't declared will receive a permission denied error.

Paid extensions with revenue sharing for publishers are planned, not yet available. Billing is not implemented today. See labhit.dev for marketplace updates.

Version Management

Extensions follow semantic versioning. The registry data model supports version management. Once hosted publishing is available, publishers will be able to:

  • Publish new versions at any time
  • Yank a version to hide it from search and install (metadata preserved)
  • View download counts and version history

Yanked versions will remain accessible to pipelines that already reference them by exact version number.