WASI: WebAssembly System Interface Cho Server Và Edge

WASI là gì?

WASI (WebAssembly System Interface) là chuẩn giao diện hệ thống cho WebAssembly (WASM) chạy ngoài trình duyệt, cho phép module WASM truy cập file system, network, clocks, random — mà không cần runtime đầy đủ như OS. Ra mắt bởi nhóm đặc tả WASI, WASI giải quyết bài toán “WASM tồn tại ở đâu ngoài Chrome”.

WASM vốn sinh ra trong browser: sandbox, an toàn, near-native speed. Nhưng bài toán lớn hơn là: tại sao không dùng khả năng này cho server, IoT, plugin systems? WASI chính là bridge giữa WASM và thế giới bên ngoài browser.

Tại sao WASI quan trọng?

WASM vốn được thiết kế sandbox: an toàn, portable, fast. Nhưng thiếu system interface — không gọi file, không bind socket. WASI lấp khoảng trống đó, biến WASM thành container thay thế nhẹ: khởi chạy measured trong milliseconds, footprint measured trong megabytes thay vì gigabytes, isolated mặc định.

So với Docker container truyền thống (100MB-1GB image), WASM binary thường nhỏ hơn 100 lần. Cold start từ 500ms của Docker xuống chưa đến 1ms với WASM runtime. Điều này mở khóa serverless functions responds trong microseconds, thay vì milliseconds.

So sánh kích thước và thời gian khởi động giữa Docker container và WASM module trên server environme
So sánh kích thước và thời gian khởi động giữa Docker container và WASM module trên server environment

Thiết kế: Capability-based Security

WASI không dùng permission flags kiểu Unix (read/write/exec bitmask). Thay vào đó, dùng capability: reference mở (handle) phải được cấp tường minh từ host sang guest module. Module không thể mở file trừ khi host explicitly cấp file descriptor.

Model này có 3 ưu điểm: (1) Không privilege escalation — cấp ít nhất có thể (principle of least privilege), (2) Explicit và auditable — không ambient authority, mọi access đều visible, (3) Composable — chain capabilities cho multi-module pipeline.

Các phiên bản WASI

  1. WASI Preview 1: Thư mục file system, POSIX-compatible subset. API ổn định nhưng limited — chỉ cover basic I/O. Được hỗ trợ rộng rãi bởi WasmtimeWasmer.
  2. WASI Preview 2: Async I/O, streams, non-blocking operations. Phản hồi feedback từ implementers về performance bottleneck. Component Model tích hợp.
  3. WASI Core (2024+): Spec chuẩn hóa cuối cùng, ghidra cho interoperability đa runtime. Mục tiêu: WASM module chạy trên bất kỳ WASI-compliant runtime nào.

Runtime hỗ trợ WASI

Runtime Ngôn ngữ Đặc điểm chính
Wasmtime Rust Cranelift JIT compiler, component model support, wasm32-wasi target chuẩn
Wasmer Rust 3 compiler backends (Singlepass/Cranelift/LLVM), WASI packages marketplace
Wasm3 C Interpreter-based, ultra-portable (runs on Arduino, embedded devices)
WasmEdge Rust Focused trên serverless computing và edge AI inference
V8 / SpiderMonkey C++ Built-in WASI trong browser engine, nhưng WASI outside browser cần standalone runtime

WASM Component Model — Architecture mới

Component Model (CM) là binary format mới thay thế truyền thống wasm32-wasi. CM cho phép: cross-runtime interoperability (module từ language A gọi language B), dynamic linking, và module reuse không cần host adapter.

WIT (WebAssembly Interface Types) định nghĩa interface giữa host và guest bằng ngôn ngữ interface-level. Ví dụ: host expose filesystem.open(path), guest gọi trực tiếp — không cần FFI bindings.

Kiến trúc module WASM trên server, guest modules giao tiếp với host qua WASI libc và WIT interfaces
Kiến trúc module WASM trên server, guest modules giao tiếp với host qua WASI libc và WIT interfaces

Ứng dụng thực tế

Serverless Functions thế hệ mới

WASM cold start approximately 1ms so với container approximately 500ms. Framework: Fermyon Spin, Cloudflare Workers WASM. Deploy trên Kubernetes qua runwasi shim.

Cloudflare Workers dùng WASM để isolate user code: mỗi request chạy trong WASM sandbox riêng, zero shared state, natural security boundary. Speed: global cold start under 5ms.

Plugin System an toàn

WASM sandbox lý tưởng cho third-party plugins: crash isolation, predictable resource usage, zero side effects trên host. Docker dùng WASM cho plugins intern. Figma dùng WASM plugin runtime từ 2021 — cho phép designers chạy custom code an toàn. Shopify Extensions dùng WASM cho merchant apps.

Edge Computing lightweight

WASM footprint nhỏ (approximately 100KB binary) phù hợp IoT và edge. Fermyon Spin deploy ở edge, giữ state cục bộ, sync lên cloud khi kết nối available. Dữ liệu nhạy cảm giữ tại device — compliance requirement cho healthcare, finance.

Microservices composition

WASM modules composing thành microservices pipeline: module A xử lý input → module B gọi database → module C format output. Mỗi module independent, sandboxed, composable. Resources sharing controlled bởi host runtime.

So sánh WASM vs Docker

Khía cạnh Docker Container WASM (WASI)
Khởi động (cold start) approximately 500ms approximately 1ms
Kích thước image 100MB-1GB 1-10MB
Isolation model Namespaces + cgroups Capability-based sandbox
Security Linux capabilities, seccomp Explicit capability grant, zero ambient authority
Language support Bất kỳ (packaged trong image) Compiles to WASM (Rust, C, Go, AssemblyScript)
Orchestration Kubernetes mature ecosystem SpinKube, containerd shim (emerging)

Bắt đầu với WASI

Cài đặt toolchain (Rust + wasm-pack + WASI target), tạo project và chạy:

  • rustup target add wasm32-wasi
  • cargo new --lib my_wasi_app
  • Thêm wasi = "0.11" vào Cargo.toml dependencies
  • cargo build --target wasm32-wasi
  • wasmtime run target/wasm32-wasi/debug/my_wasi_app.wasm

Hoặc dùng Wasmer với wasmer run --dir=. my_wasi_app.wasm — directory mount trực tiếp.

Thách thức hiện tại

  • Ecosystem non-standard: WASI Preview 1 chưa hoàn thiện — code cần recompile khi spec thay đổi. Component Model hứa hẹn nhưng chưa stable.
  • Tooling chưa trưởng thành: Debugging WASM ngoài trình duyệt phức tạp — không gdb truyền thống, cần dedicated debugging tools.
  • Language support unequal: Rust, AssemblyScript, C support tốt nhất. Python và Go trên WASM vẫn experimental (GC overhead lớn).
  • Adoption: Thiếu killer app mainstream — serverless vẫn niche so với AWS Lambda và Cloudflare Workers truyền thống. Docker ecosystem quá mature.
  • State management: WASM module stateless — persistent storage cần external solution (Redis, SQLite).

Kết luận

WASI là mảnh ghép quan trọng cho WASM outside browser — mở khóa serverless thế hệ mới, plugin secure, và edge computing lightweight. Không thay thế container ngay hôm nay, nhưng với cold start measured trong milliseconds và footprint measured trong kilobytes, WASM đang chiếm mảng compute short-lived workloads. Developer Rust và C nên bắt đầu dùng WASI now; ngôn ngữ khác chờ Component Model ổn định để ecosystem mature hơn.

Nguồn: WASI Spec, Bytecode Alliance, W3C WASM, Docker, Fermyon Spin, Wasmer

Tôi là một lập trình viên IOS. Code chính là IOS nhưng thỉnnh thoảng vẫn đá sang Android hoặc web. Mặc dù không quá thông thạo nhưng tôi sẽ chia sẻ những kiến thức mà mình đã tìm hiểu, áp dụng qua.

Bài viết liên quan

Apache Iceberg: Table Format Hiện Đại Cho Data Lakehouse

Apache Iceberg là một table format nguồn mở được thiết kế cho data lake quy mô lớn. Khác với cách lưu trữ truyền thống dùng thư mục file, Iceberg mang…

Xem thêm

Docker Compose: Quản lý multi-container đơn giản chỉ với một file

Docker Compose là gì? Kiến trúc Docker Compose —nhiềucontainer web app, database, cache kết nối qua mạng nội bộ Docker Compose là công cụ định nghĩa và chạy ứng dụng…

Xem thêm

Celestia là gì? Giải pháp Data Availability mô-đun cho Blockchain

Celestia là gì? Giải pháp Data Availability mô-đun cho Blockchain Blockchain hiện đại đang đối mặt với thách thức mở rộng quy mô data availability (DA) khi khối lượng giao…

Xem thêm
0 0 đánh giá
Article Rating
Theo dõi
Thông báo của
guest
0 Comments
Cũ nhất
Mới nhất Được bỏ phiếu nhiều nhất