Part 10 · 1 chapters · ~8 min

In Production: What Rust Is Paired With

Rust's usual role as the hot path in a polyglot platform, static musl binaries in scratch or distroless images, Tokio runtime sizing in containers, tonic for gRPC behind Envoy, tracing and OpenTelemetry, Kafka and NATS clients, and the hiring and maintenance trade-offs of adding Rust.

14

The stack around a Rust service

code
# Dockerfile: static binary on scratch
FROM rust:1.96 AS build
RUN rustup target add x86_64-unknown-linux-musl
WORKDIR /src
COPY . .
RUN cargo build --release --target x86_64-unknown-linux-musl
FROM gcr.io/distroless/static:nonroot
COPY --from=build /src/target/x86_64-unknown-linux-musl/release/ledger /ledger
ENTRYPOINT ["/ledger"]

// size the Tokio runtime to the CPU quota, not the host
let rt = tokio::runtime::Builder::new_multi_thread().worker_threads(cpu_quota()).enable_all().build()?;

Adding Rust to a team buys performance and safety and costs hiring difficulty, longer onboarding and slower compile times. It pays off most for services where latency predictability, memory safety and CPU efficiency are the product: matching engines, proxies, parsers, cryptography and high-volume ledgers.

WHAT RUST IS PAIRED WITH IN PRODUCTION
often the hot path inside a polyglot platform
Envoy / gatewaymesh-friendlyRust serviceAxum or tonic on Tokioscratch / distrolesssmall static imageGo / Java / Node servicesthe rest of the platformtracing + OpenTelemetryKafka (rdkafka) / NATS
swipe the figure sideways, or tap expand for full screen
1/5
the hot path
Teams often adopt Rust for one performance- or safety-critical service: a matching engine, a ledger posting service, a proxy, a parser, while the rest of the platform stays in Go, Java or Node.
one critical service in Rustthe rest in other languages