Two complementary changes to reduce clean workspace build time from
~13min to ~8:43:
1. Per-package codegen-units overrides
Default for all release builds: codegen-units = 16 (parallel LLVM).
Numerical-sensitive crates (ml-* family, ndarray, nalgebra, cudarc,
simba, etc.) override back to 1 to preserve bit-exact LLVM
optimization decisions for the DQN regression suite.
Non-numerical plumbing (arrow, sqlx, tokio, parquet, ...) compiles
in parallel via 16 CGUs, no numerical impact.
2. Dependency deduplication
- axum 0.7 → 0.8 (workspace + services/api): dedupes vs tonic 0.14's
transitive axum 0.8. Eliminates a full duplicate compile of axum
and axum-core.
- statrs 0.17 → 0.18: dedupes nalgebra 0.32 vs 0.33. Also closes a
numerical concern (two nalgebra versions linked simultaneously).
- governor 0.6 → 0.10 (services/api + crates/data): dedupes dashmap
5 vs 6. dashmap is heavy; eliminating one full compile is a real
win.
- hashbrown 0.14 → 0.16 (workspace): partial dedupe (dashmap 6.1
still pulls 0.14 transitively).
- Workspace Cargo.toml documents residual unfixable duplicates with
reasons (base64, chacha20, phf, darling, itertools, getrandom,
hashbrown, syn, thiserror — all blocked by third-party crates we
can't bump without breakage).
Verified: cargo check --workspace passes. Numerical crates remain
at codegen-units = 1 — DQN bit-exact reproducibility preserved.
api
Foxhunt API Service -- unified gRPC gateway with tonic-web for browser access, 6-layer authentication, RBAC, rate limiting, and gRPC proxy routing.
Key Types
TradingServiceProxy-- main gRPC proxy implementationRoleBasedAccessControl-- RBAC authorizationRateLimiter-- 3-tier rate limiting (auth/trading/compute)CircuitBreaker-- upstream service protection
Configuration
JWT_SECRET-- JWT signing secret (min 32 chars)CORS_ORIGINS-- comma-separated allowed origins for gRPC-Web (default: http://localhost:5173)TRADING_SERVICE_URL-- trading service gRPC endpointML_TRAINING_SERVICE_URL-- ML training service gRPC endpoint
Features
mfa(default) -- multi-factor authentication support- Build without:
cargo check -p api --no-default-features --features minimal