Extension Marketplace
The LabHit Extension Marketplace will be a registry for publishing,
discovering, and installing pipeline extensions. It is rolling out: the
registry data model and .lhx packaging format exist today,
but there is not yet a hosted marketplace, any published extensions, or
a client-side publish path. You can build and package extensions now and
share .lhx files directly until hosted publishing
lands.
Overview
Extensions are sandboxed WASM modules that add capabilities to your pipelines. Each extension declares its category, required permissions, and interface through a manifest file.
Extension Categories
| Category | Purpose | Examples |
|---|---|---|
source |
Code checkout and repository management | Git clone, SVN, Mercurial |
build |
Compilation and artifact generation | Container build, Cargo, npm |
test |
Test execution and reporting | Unit tests, integration tests, fuzzing |
scan |
Security scanning and code analysis | SAST, dependency audit, license check |
deploy |
Deployment to target environments | Kubernetes, cloud functions, CDN |
notify |
Notifications and alerting | Slack, email, webhook |
report |
Reporting and metrics | Coverage, performance, changelog |
utility |
General-purpose tools | Cache management, file manipulation |
Searching Extensions
Discovery is rolling out with the hosted marketplace. The
labhit extension searchCLI is currently a stub (not yet connected to a remote registry). The GraphQL query and dashboard below run against the extension registry, which has no published extensions yet.
CLI
# Search by keyword
labhit extension search "kubernetes"
# Search by category
labhit extension search --category deploy
# List all extensions
labhit extension search ""
GraphQL API
query {
extensions(query: "kubernetes", category: "deploy", limit: 10) {
id
name
description
category
downloadCount
}
}
Dashboard
Visit the Marketplace page in the dashboard to browse extensions with category filters and search.
Installing Extensions
Today, labhit extension install installs a local
.lhx package file. There is no hosted registry to install
from yet, so installing by name and version rolls out with the
marketplace.
# Install a local .lhx package
labhit extension install ./my-deployer-1.0.0.lhx
A .lhx package is a gzip-compressed tar archive
containing the WASM module, manifest, and documentation. Package
integrity is verified via SHA-256 hash.
Once the hosted marketplace is live, you will be able to install by name and version:
# Coming soon: install from the hosted registry
labhit extension install deploy/kubernetes
labhit extension install deploy/kubernetes --version 1.2.0
Packaging Extensions for Distribution
Build and pack your extension into a portable .lhx
package today. Hosted publishing to the marketplace registry is rolling
out. Until it lands, share the .lhx file directly or
install it locally with labhit extension install.
Prerequisites
- The extension WASM module compiled for
wasm32-wasip1orwasm32-wasip2 - An
extension.yamlmanifest
Extension Manifest
id: deploy/my-deployer
name: My Deployer
description: Deploy to my cloud provider
version: 1.0.0
category: deploy
capabilities:
- network
- env:MY_CLOUD_TOKEN
Build and Pack
# Initialize a new extension project
labhit extension init my-deployer
# Build the WASM module
labhit extension build
# Test locally
labhit extension test
# Pack into a distributable .lhx package
labhit extension pack
pack produces a
<name>-<version>.lhx file and prints its size
and SHA-256 hash.
Package Format (.lhx)
A .lhx file is a gzip-compressed tar archive
containing:
| File | Required | Description |
|---|---|---|
extension.yaml |
Yes | Extension manifest |
*.wasm |
Yes | Compiled WASM module |
README.md |
No | Documentation shown on the marketplace page |
LICENSE |
No | License file |
Maximum package size: 50 MB.
Using Extensions in Pipelines
Reference installed extensions with the use:
directive:
engine: "1"
pipeline:
name: deploy-pipeline
stages:
checkout:
use: source/git
with:
repository: https://github.com/my-org/my-app
branch: main
build:
after: [checkout]
use: build/container
with:
dockerfile: ./Dockerfile
tag: my-app:latest
deploy:
after: [build]
use: deploy/kubernetes
with:
cluster: production
manifest: ./k8s/deployment.yaml
An extension's required permissions (network, filesystem, secrets)
are declared in its own extension.yaml manifest, not in the
pipeline's sandbox: block.
Extension Permissions
Extensions run in sandboxed environments with deny-by-default permissions. Each extension must declare the capabilities it needs in its manifest.
| Capability | What It Grants |
|---|---|
filesystem |
Read/write access to the pipeline workspace |
network |
Outbound network access |
env:VAR_NAME |
Access to a specific environment variable |
Capabilities are enforced at runtime. An extension that attempts to access a resource it hasn't declared will receive a permission denied error.
Paid Extensions
Paid extensions with revenue sharing for publishers are planned, not yet available. Billing is not implemented today. See labhit.dev for marketplace updates.
Version Management
Extensions follow semantic versioning. The registry data model supports version management. Once hosted publishing is available, publishers will be able to:
- Publish new versions at any time
- Yank a version to hide it from search and install (metadata preserved)
- View download counts and version history
Yanked versions will remain accessible to pipelines that already reference them by exact version number.