How to Build a Custom NeMo Relay Plugin Bundle for Switchyard Using relay-plugin.toml and a Digest
To build a custom NeMo Relay plugin bundle for Switchyard, compile the switchyard-nemo-relay-plugin crate as a dynamic library, calculate a SHA-256 digest of the artifact, and package it with a populated relay-plugin.toml manifest using the provided package_bundle.py script.
The Switchyard framework in the NVIDIA-NeMo/Switchyard repository provides a native NeMo Relay plugin that enables integration with the NeMo ecosystem. Creating a custom bundle allows you to distribute validated plugin artifacts that NeMo Relay can load securely using cryptographic integrity checks. This workflow requires the Rust toolchain, Python for packaging automation, and the NeMo Relay CLI for installation.
Prerequisites
Before building the plugin, ensure you have the Rust toolchain installed and the repository cloned locally.
git clone https://github.com/NVIDIA-NeMo/Switchyard.git
cd Switchyard
rustup toolchain install stable
rustup default stable
The switchyard-nemo-relay-plugin crate is located in crates/switchyard-nemo-relay-plugin/ and contains the source code, build configuration, and packaging scripts necessary to generate the bundle.
Building the Plugin Dynamic Library
The plugin compiles into a platform-specific shared library that NeMo Relay loads at runtime. In crates/switchyard-nemo-relay-plugin/Cargo.toml, the crate is configured to produce a cdylib target suitable for dynamic linking.
Build the release artifact using Cargo:
cargo build --release -p switchyard-nemo-relay-plugin
Upon completion, the compiled library appears in target/release/ with platform-specific extensions:
- Linux:
libswitchyard_nemo_relay_plugin.so - macOS:
libswitchyard_nemo_relay_plugin.dylib - Windows:
switchyard_nemo_relay_plugin.dll
The entry point nemo_relay_register_plugin defined in crates/switchyard-nemo-relay-plugin/src/lib.rs handles plugin registration when the library is loaded.
Generating the SHA-256 Digest
NeMo Relay requires a cryptographic digest to verify bundle integrity. Calculate the SHA-256 hash of the compiled shared library to populate the integrity.sha256 field in the manifest.
On Linux or macOS:
sha256sum target/release/libswitchyard_nemo_relay_plugin.so | awk '{print $1}'
On Windows using PowerShell or Command Prompt:
CertUtil -hashfile target\release\switchyard_nemo_relay_plugin.dll SHA256
Record the resulting hexadecimal string (e.g., abcd1234...), as you will inject this value into relay-plugin.toml during the packaging step.
Packaging the Bundle with relay-plugin.toml
The repository ships a template manifest at crates/switchyard-nemo-relay-plugin/relay-plugin.toml containing placeholders for the library filename and digest. The package_bundle.py script automates substitution and directory structure creation.
Run the packaging script from the repository root:
python crates/switchyard-nemo-relay-plugin/scripts/package_bundle.py \
--library target/release/libswitchyard_nemo_relay_plugin.so \
--sha256 <artifact-sha256>
This script performs the following operations derived from its implementation in package_bundle.py:
- Reads the template
relay-plugin.tomland substitutes<platform-library-file>with the actual library filename - Inserts
sha256:<artifact-sha256>into theintegrity.sha256field - Copies the compiled library and LICENSE files into
./plugins/switchyard/by default
The resulting bundle directory contains:
relay-plugin.toml— Fully populated manifest with integrity metadata- The compiled shared library file
- Required LICENSE files
Installing and Validating the Plugin
Once packaged, validate the bundle structure before registering it with NeMo Relay:
nemo-relay plugins validate ./plugins/switchyard/relay-plugin.toml
Install the plugin for the current user:
nemo-relay plugins add --user ./plugins/switchyard/relay-plugin.toml
NeMo Relay now recognizes the plugin ID nvidia.switchyard and can load the custom bundle when requested by Switchyard applications.
Configuration and Usage
To activate the plugin within a Switchyard deployment, reference the plugin ID in your Switchyard configuration TOML:
[plugins]
nvidia.switchyard = { enabled = true }
Alternatively, set the SWITCHYARD_RELAY_PLUGIN environment variable to point to the bundle directory path. When Switchyard initializes, it queries NeMo Relay for the nvidia.switchyard plugin and loads the validated shared library according to the manifest specifications in relay-plugin.toml.
Summary
- Clone and build the
switchyard-nemo-relay-plugincrate usingcargo build --release -p switchyard-nemo-relay-pluginto generate the platform-specific shared library. - Calculate integrity by generating a SHA-256 digest of the compiled artifact using standard system utilities.
- Automate packaging with
package_bundle.pyto populaterelay-plugin.tomlplaceholders and assemble the bundle directory structure. - Register securely using
nemo-relay plugins addto install the validated bundle into your NeMo Relay environment. - Configure Switchyard to load the plugin via the
nvidia.switchyardID in TOML configuration or environment variables.
Frequently Asked Questions
What is the purpose of the SHA-256 digest in the plugin bundle?
The SHA-256 digest provides cryptographic integrity verification for the compiled shared library. When NeMo Relay loads the plugin specified in relay-plugin.toml, it validates the library against the integrity.sha256 hash to ensure the artifact has not been modified or corrupted since packaging. This security measure prevents the execution of tampered code in production environments.
Can I modify the plugin source code before building the custom bundle?
Yes. The crates/switchyard-nemo-relay-plugin/src/lib.rs file contains the plugin implementation including the nemo_relay_register_plugin entry point. After modifying the source code to customize behavior or add capabilities, rebuild the crate with cargo build --release and regenerate the SHA-256 digest. The package_bundle.py script will package your modified version just like the standard build.
How do I resolve validation errors when running nemo-relay plugins validate?
Validation errors typically indicate missing files, incorrect paths in relay-plugin.toml, or digest mismatches. Ensure the <platform-library-file> placeholder was properly substituted with the actual filename, verify that the integrity.sha256 field contains the full hash string prefixed with sha256:, and confirm the library file exists in the same directory as the manifest. Check that you calculated the digest against the release binary, not a debug build.
Where should I deploy the custom plugin bundle in production environments?
Deploy the bundle directory (containing relay-plugin.toml, the shared library, and licenses) to a persistent path accessible by NeMo Relay, then register it using nemo-relay plugins add --user for user-specific installation or system-wide depending on your deployment requirements. The bundle remains portable as long as the relative paths between the manifest and library files are maintained as structured by package_bundle.py.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →