Functions
Deploy and operate functions over Pulsar or Kafka alongside agents in Orca Agent Engine on StreamNative Cloud.
A function processes messages from one or more Pulsar or Kafka topics and can write results to an output topic. The registry Functions API supports both messaging protocols; the function's connection selects the protocol. Use functions for lightweight filtering, transformation, enrichment, or routing that does not need an agent loop.
This resource is a StreamNative Cloud capability served under /apis/cloud.sn.io/v1. A
self-hosted engine does not advertise the cloud.sn.io extension group. The ork CLI and
TypeScript SDK check GET /apis and report that the capability is unavailable before sending the
resource request.
This page covers user-facing stream-processing functions. The earlier Agent Function runtime is not a public deployment surface in current clients; use triggers to run an agent automatically.
Get your registry endpoint
Registry endpoint
Examples on this page target your registry endpoint - the deployment host root, with no path
suffix. For CLI, set ORCA_REGISTRY_URL and exactly one of ORCA_ACCESS_TOKEN (Bearer) or
ORCA_API_KEY (x-api-key). For TypeScript SDK, set ORCA_BASE_URL / ORCA_API_KEY (Bearer).
To find the endpoint, see Connect to the registry.
Function configuration fields
| Field | Type | Required | Description |
|---|---|---|---|
name | string | Yes | Function name. The route also carries this name. |
tenant, namespace | string | No | Function identity fields. The CLI defaults to public/default; they do not prefix Kafka topic names. |
className | string | Depends on the runtime | Function implementation class or module, such as uppercase.Uppercase for Python. |
jar, py, go | string | One package source | Built-in, uploaded, local, or remote package location. Use only one. |
inputs or topicsPattern | array or string | Usually | Input topics or topic regex for the selected protocol. Use Kafka topic names without a Pulsar URI prefix. |
output | string | No | Output topic for the selected protocol. |
connection | string | Yes on create | Workspace connection of type pulsar or kafka. Immutable after create. |
parallelism | integer | No | Function instances. Defaults to 1 in the CLI. |
processingGuarantees | enum | No | ATLEAST_ONCE, ATMOST_ONCE, EFFECTIVELY_ONCE, or MANUAL. The generic runtime rejects EFFECTIVELY_ONCE. |
customRuntimeOptions | JSON string | For Kafka runtime selection | Runtime options, including genericKind, kafkaConsumerConfig, and kafkaProducerConfig. |
resources | object | No | CPU, RAM, and disk per instance. |
userConfig, secrets | object | No | Function configuration and Secret mappings. |
snServiceAccount | string | No | StreamNative Cloud service account used by the function. |
Function create and update are multipart requests. Supply one package source through an uploaded
data part, a package url, or the matching field in functionConfig.
Choose a messaging protocol
Both protocols use /apis/cloud.sn.io/v1/functions, ork functions, and
orca.cloud.functions. Set connection to a Pulsar or Kafka connection in your Workspace; there is
no separate protocol field on the function. The connection supplies the broker endpoint and
authentication configuration. To change a function's connection or protocol, create a new function.
Kafka functions require the generic runtime. Set genericKind in the JSON-encoded
customRuntimeOptions string to match your package, such as python for a Python function. Your
Workspace must provide the corresponding generic runner image. Optional kafkaConsumerConfig and
kafkaProducerConfig objects carry Kafka client properties such as auto.offset.reset and acks.
Use these objects for Kafka client tuning instead of the Pulsar producerConfig field.
If the Kafka connection defines spec.kafka.schemaRegistry, the function also receives its Schema
Registry URL. External connections can supply Basic or OAuth2 credential references there; internal
connections use Workspace-managed authentication.
Functions do not accept SCRAM authentication from an external Kafka connection. Kafka TLS conversion forwards the enabled setting, but does not copy the connection's custom keystore or truststore configuration into the function.
Create a Pulsar function
This example deploys the built-in word_count function. $ORCA_REGISTRY_URL points at the host
root; each client appends /apis/cloud.sn.io/v1.
ork functions create \
--name word-count \
--function-type word_count \
--inputs persistent://public/default/sentences \
--output persistent://public/default/word-counts \
--connection pulsar-main \
--parallelism 1For a custom package, upload it through Packages and set a package
URL, or pass a local file through the CLI's --jar, --py, or --go flag.
Create a Kafka function
Create a Kafka connection named events-kafka as shown in
Connections, and create the Kafka topics
sentences and uppercase-sentences on that cluster. Save this function as uppercase.py in your
current directory. It returns each input message in uppercase.
class Uppercase:
def process(self, input, context):
return input.upper()Each example uploads that file and selects the Python generic runtime. In the TypeScript example,
reuse the orca client initialized above.
ork functions create \
--name kafka-uppercase \
--py ./uppercase.py \
--classname uppercase.Uppercase \
--inputs sentences \
--output uppercase-sentences \
--connection events-kafka \
--parallelism 1 \
--processing-guarantees ATLEAST_ONCE \
--custom-runtime-options '{"genericKind":"python","kafkaConsumerConfig":{"auto.offset.reset":"earliest"},"kafkaProducerConfig":{"acks":"all"}}'Check the deployment with ork functions status kafka-uppercase -o json. Publish a message such as
hello to sentences using a Kafka producer, then consume uppercase-sentences and check for HELLO.
Operate functions
| Operation | CLI | TypeScript | REST |
|---|---|---|---|
| List | ork functions list | orca.cloud.functions.list() | GET /apis/cloud.sn.io/v1/functions |
| Retrieve config | ork functions get <name> | .retrieve(name) | GET .../functions/{name} |
| Update | ork functions update <name> | .update(name, params) | PUT .../functions/{name} |
| Delete | ork functions delete <name> | .delete(name) | DELETE .../functions/{name} |
| Start/stop/restart | ork functions <action> <name> [instance] | .start, .stop, .restart and instance variants | POST .../{name}:<action> |
| Status | ork functions status <name> [instance] | .retrieveStatus / .retrieveInstanceStatus | GET .../{name}/status |
| Statistics | ork functions stats <name> [instance] | .retrieveStats / .retrieveInstanceStats | GET .../{name}/stats |
| Trigger once (Pulsar only) | ork functions trigger <name> | .trigger(name, params) | POST .../{name}:trigger |
| Read/write state | `ork functions state get | put` | .retrieveState / .updateState |
The CLI reference lists package, schema, windowing, resource, retry, ordering, state, and lifecycle flags.
The function trigger operation returns HTTP 400 for Kafka functions. To invoke a Kafka function, publish a record to one of its input topics with a Kafka producer.
Check status
ork functions status word-count -o jsonPermissions
Treat every credential that can call the Workspace's cloud.sn.io routes as full access to its
functions, and separate access with Workspaces. See
Control registry access.