serverless-llrt-analyzer
v0.1.1
Published
Serverless Framework plugin to flip Lambda functions to AWS LLRT (llrt: true) for ~10x faster cold starts, with a deploy-time compatibility guard powered by llrt-analyzer.
Maintainers
Readme
serverless-llrt-analyzer
Serverless Framework plugin to flip Lambda functions to AWS LLRT (QuickJS, ~10x faster cold starts) with one line per function — plus a deploy-time compatibility guard so you can't ship an incompatible function.
Thin Serverless adapter over the @davidwells/llrt-analyzer core.
Install
npm i -D serverless-llrt-analyzer # pulls in @davidwells/llrt-analyzerUse
plugins:
- serverless-esbuild # (your bundler, if any)
- serverless-llrt-analyzer
custom:
llrt:
layerArn: arn:aws:lambda:us-east-1:xxxx:layer:llrt-arm64:1 # required
verify: true # default true — fail the deploy on a real blocker
functions:
api: { handler: src/app.handler, llrt: true } # -> provided.al2023 + arm64 + LLRT layer
warmer: { handler: src/warmer.warm, llrt: true }
processImg: { handler: src/img.handler } # stays nodejs (mixed-runtime is fine)Reverting is deleting the llrt: true line.
What it does at package time
For each llrt: true function:
api -> runtime: provided.al2023 architecture: arm64 layers: [ <llrt layer> ]Unflagged functions are untouched.
The guard (custom.llrt.verify, default on)
Before packaging, it runs llrt-analyzer's static tier against each flagged
function and aborts the deploy on a fatal blocker:
Error: [llrt] function "api" is NOT LLRT-compatible:
- node:crypto.timingSafeEqual: LLRT's node:crypto does not export
"timingSafeEqual" — use a supported alternative or keep this on Node.
Remove `llrt: true` or fix the blocker(s). (set custom.llrt.verify:false to bypass)For the definitive verdict (actually runs the handler under the LLRT binary and
diffs behavior), run the core in CI: llrt-analyzer <service> --local.
Getting the layer ARN (one command)
llrt-analyzer publish-layer --arch arm64 --region us-east-1 \
--ssm /my-svc/prod/llrt-layer-arnThis downloads the pinned LLRT lambda bootstrap, publishes it as a layer, prints
the ARN, and (with --ssm) writes it to SSM — then reference it as
custom.llrt.layerArn: ${ssm:/my-svc/${self:provider.stage}/llrt-layer-arn}.
llrt-analyzer init prints the whole snippet to paste.
Bundler wiring (automatic)
If you use serverless-esbuild, the plugin auto-wires it for LLRT: it marks
@aws-sdk/* / @smithy/* / @aws-crypto/* external (LLRT ships its own SDK)
and sets format: esm. These are safe for the Node functions too (the Lambda
Node runtimes also provide @aws-sdk), so llrt: true really is the whole
change. Opt out with custom.llrt.autoEsbuild: false.
