Installation¶
Three equal-status install paths — Docker, prebuilt binary, or build from source. Pick whichever fits your workflow.
Docker¶
Multi-arch signed image (linux/amd64 + linux/arm64), distroless runtime,
~25 MB.
curl -O https://raw.githubusercontent.com/vidaiUK/VidaiMock/main/docker/docker-compose.yml
docker compose up -d
curl http://localhost:8100/health # {"status":"ok"}
Proper restart policy, override-friendly via ./overrides/ next to the
compose file, isolated-mode via one env var. See
Docker Compose recipe for the full flow.
For CI use, pin to a specific digest for reproducibility — see CI/CD Integration.
Binary download¶
Each archive extracts to a vidaimock/ directory containing the binary plus
config/ and examples/.
OS security notice (macOS / Windows)
Because VidaiMock is an unsigned open-source binary, your OS may block it on first run.
- macOS:
xattr -d com.apple.quarantine vidaimock - Windows: click More info in the SmartScreen dialog, then Run anyway
Build from source¶
Requires a recent stable Rust toolchain (1.70+).
git clone https://github.com/vidaiUK/VidaiMock.git
cd VidaiMock
cargo build --release
./target/release/vidaimock
The bundled config/ (providers + templates) is embedded into the binary at
compile time, so the binary works standalone with no files alongside it. A
local config/ directory or --config-dir only overrides the embedded
defaults — see Overriding bundled defaults.
Rust library¶
Rust projects can embed the server directly in their tests rather than running it as a separate process:
use vidaimock::MockServer;
let server = MockServer::builder().bind("127.0.0.1:0").start().await?;
let base_url = server.base_url();
This is the same server, providers and templates as the binary — it simply runs inside your test process. See Rust Library for parallel tests, config overrides, and shutdown semantics.
Verify release signatures (cosign)¶
Every release artefact — the Docker image, the tarball, and the bare binary
inside it — is signed with the Vidai release key, published at
https://vidai.uk/.well-known/cosign.pub. The key is served over
Vidai-controlled TLS, a separate trust path from GitHub and GHCR — an
attacker who tampers with an artefact would also have to compromise
vidai.uk to swap the trust anchor.
The --insecure-ignore-tlog flag is required because VidaiMock does not
publish to the Sigstore transparency log — the trust anchor is the
keyed signature against the vidai.uk public key, not a public log
entry. The flag name sounds scary but is correct for keyed (non-keyless)
cosign flows.
Smoke check¶
Next: Quickstart.