Skip to main content
A runtime on Square Cloud is the complete, isolated environment your application runs inside: the language interpreter or virtual machine, the system libraries it links against, the tooling it can shell out to, and the security boundary that keeps it separated from every other application on the host. You never build or maintain that environment. You ship your source code and a small configuration file; Square Cloud detects the language, resolves your dependencies, provisions an isolated container and runs it. The same pipeline powers Discord/WhatsApp/Telegram bots, websites and APIs, background workers and long-running services, on the same fast, hardened infrastructure.

Supported languages

JavaScript

Bun

Deno

Python

Java

Rust

Elixir

PHP

Go

C#

Ruby

HTML/CSS

Beyond the languages above, most other stacks and libraries run out of the box. The runtime images are built to be permissive: if your language installs on Linux, it very likely runs on Square Cloud.

Versions

Every runtime ships two update channels, selectable through the VERSION field in your configuration file:
  • recommended: the version we harden and run in production for the majority of applications. Choose it unless you have a specific reason not to.
  • latest: the newest release, for teams that need a just-shipped language feature.
VERSION accepts only these two values: any other value, including an exact version number, fails the deploy with INVALID_VERSION.
Choose recommended unless you need a feature that only latest has. See the configuration file reference for the RUNTIME and VERSION fields.

How a deploy works

From upload to a live process, every deploy runs through the same deterministic pipeline:

Language detection

Square Cloud takes the language from the RUNTIME field of your configuration file or, when it is not set, from the extension of the MAIN file: .js for Node.js, .ts for TypeScript, .py for Python, .go for Go, .jar for Java, and so on. It then checks that the language’s dependency file is at the root of your upload: package.json for Node.js and TypeScript, requirements.txt or pyproject.toml for Python, go.mod or go.work for Go, Cargo.toml for Rust, Gemfile for Ruby and mix.exs for Elixir. If it is missing or empty, the deploy fails with INVALID_DEPENDENCY.

Dependency resolution

Dependencies are installed server-side, inside the container, before your app starts: npm install when there is no node_modules folder (a node_modules folder at the root of your upload is discarded), pip install for Python, bundle install for Ruby and mix deps.get for Elixir, while Go, Rust and .NET download their packages when they build your code. You don’t need to ship node_modules or a virtualenv inside the .zip. Java is the exception: the default command runs a JAR you built (java -jar MAIN), so upload the compiled .jar.

Provisioning

An isolated container is created with the CPU and memory declared in your configuration file. Resources are enforced at the kernel level, so one application can never starve another on the same host.

Start

Without START, Square Cloud runs the language’s default command, such as node MAIN, python MAIN, go run MAIN or java -jar MAIN (Rust and Elixir build and run the whole project with cargo run --release and mix run --no-halt). Need a build step or a custom command? Set START and it runs verbatim.

Inside every runtime image

Each image starts from the official image of its language and adds the system tools applications commonly need:

Node.js and Python together

Node.js and Python apps run on the same image, which ships both Node.js and Python 3.14, so a bot can call a script written in the other language. The PHP image also includes Node.js 24 and npm for asset builds.

ffmpeg & Chromium

ffmpeg is preinstalled in the Node.js, Python, Java, Go, Rust, Ruby, Elixir and .NET images, and the Node.js and Python image also includes headless Chromium, ready for media bots, web scraping, and PDF or screenshot generation without extra setup.

Unprivileged by default

Applications run as a non-root user inside an isolated container. A compromised dependency stays contained, with no privileged access to the host.

Static sites, no runtime

No interpreter needed? Set RUNTIME=static to serve a plain HTML/CSS/JS site directly, with the same CDN and TLS as any other application.

Isolation and security

Every application is a fully isolated container with kernel-enforced CPU and memory limits, never a shared process. Running unprivileged means an application cannot reach the host or its neighbors, and resource caps guarantee that a spike in one project has no effect on the performance of another. This is the same model that lets Square Cloud host tens of thousands of workloads on shared clusters without them interfering with each other.

Next steps

Configuration file

Master MAIN, START, RUNTIME, VERSION and MEMORY: the fields that control your runtime.

Language guides

Step-by-step setup for Node.js, Bun, Deno, Python, Go, Rust, Java, static HTML and more.