Expand description
Provider-neutral workspace contracts and default capability behavior.
Structs§
- AckResponse
- Acquire
Space Write Lease Request - Apply
Space Change SetRequest - Build
Builtin Snapshot Request - Bytes
Response - Clone
Workspace Request - CmdOutput
- Output of a command execution.
- Command
Permit Request - Command
Resource - Command
Spec - Command
Transition - Complete
Computer Command Request - Computer
Binding - Computer
Command Output Chunk - Computer
Command Output Page - Computer
Command Output Query - Computer
Command Resource - Computer
Command Transition - Computer
Record - Computer
Resource - Content
Response - Create
Command Request - Create
Computer Command Request - Create
Computer Request - Create
Delegation Request - Create
Preview Request - Create
Sandbox Request - Create
Snapshot Request - Create
Snapshot Resource Request - Create
Space Change SetRequest - Create
Space Grant Request - Create
Space Request - Create
Template Version Request - Create
Upload Request - Create
Workspace Request - Delegation
Record - Delegation
Resource - Delete
Space File Request - DirEntry
- A directory entry returned by
list_dir. - Entries
Response - Environment
Build Observation - Provider build observation captured by caller-driven polling. Logs are bounded by the adapter/runtime and never contain provider credentials.
- Environment
Catalog Config - Environment
Domain Error - Environment
Idempotency Record - Environment
Metadata Snapshot - Durable metadata snapshot for one tenant/project scope.
- Environment
Provider Admin Config - Environment
Provider Slot View - Exec
Request - Exists
Response - File
Visibility Options - Options for directory listing and recursive search operations.
- Find
Files Request - Grep
Match - A grep match result.
- Grep
Request - Grep
Response - Heartbeat
Space Session Request - Install
Sandbox Skill Request - Install
Sandbox Skill Resource - Install
Space Skill Request - Install
Space Skill Resource - IsDir
Response - Issue
Space Access Ticket Request - Issued
Space Access Ticket - Issued
Space Access Ticket Resource - Keep
Alive Request - List
DirRequest - List
Environment Resources Query - List
Space Files Request - Migrate
Workspace Request - Open
Space Session Request - Operation
Transition - Output
Chunk - Output
Page - Owner
Ref - Patch
Owners Request - Path
Request - Paths
Response - PortUrl
- Public preview URL for a port exposed by a workspace backend.
- Port
UrlRequest - Principal
Ref - Provider
Build Handle - Provider
Capabilities - Provider
Command Output - Synchronous provider command result. The control plane may persist chunks.
- Provider
Computer Request - Provider-facing request after product identifiers and access tickets have been resolved. These DTOs cannot be supplied by HTTP callers.
- Provider
File Content - Provider
File Entry - Provider
Request Failure - Provider-neutral failure signal consumed by transport resilience policies.
- Provider
Resource Ref - Provider
Sandbox Mount - Provider
Sandbox Request - Provider
Space Request - Provider
Write Result - Provisioned
Workspace - PutWorkspace
File Request - Body for the resource-scoped
PUT .../files/{path}API. The path belongs to the URL so it cannot disagree with a second body field. - Read
File Tail Request - Read
Space File Request - Release
Space Write Lease Request - Remove
File Request - Resolved
Backend Id - Resolved durable backend ID discovered while initializing a workspace. This remains provider-neutral on the wire.
- Resource
Pressure - Resource
Scope - Resource
Usage Value - Revoke
Space Grant Request - Sandbox
Mount - Sandbox
Mount Record - Persisted mount metadata. The bearer token from
SandboxMountis deliberately replaced by its non-secret ticket id before persistence. - Sandbox
Record - Sandbox
Resource - Secret
Ref - Opaque reference resolved only by a trusted adapter. The secret value is
deliberately impossible to serialize or expose through
Debug. - Skill
Package - Skill
Package File - Skill
Search Item - Skill
Search Page - Skill
Search Query - Snapshot
- Snapshot
Object Ref - Snapshot
Record - Snapshot
Resource - Space
Access Ticket Record - Space
Access Ticket Resource - Space
Change SetRecord - Space
Change SetResource - Space
Collaboration Session - Space
Collaboration Session Resource - Space
File Content - Space
File Entry - Space
Grant - Space
Grant Resource - Space
Record - Space
Resource - Space
Write Lease - Space
Write Lease Resource - Static
Preview Server - Store
Computer Command Request - Durable, scope-qualified command creation input owned by the Workspace command repository. Only hashes of caller idempotency material cross the persistence boundary.
- Stored
Change Set - Stored
Preview - Stored
Snapshot - Template
Version Record - Template
Version Resource - Update
Environment Provider Admin Config Request - Update
Environment Provider Slot Request - Upload
Chunk Request - Upload
Session - Versioned
File - Walk
Tree Request - Workspace
Action Request - Workspace
ApiError - Workspace
Capabilities - Workspace
Change Set - Workspace
Change SetRequest - Workspace
Change Summary - Workspace
Config - Provider-neutral provisioning input. Provider-specific SDK/configuration belongs to an adapter crate; the contract contains only a backend kind, opaque settings and secret references.
- Workspace
Error Details - Workspace
File Change - Workspace
Lease - Workspace
Lease Keep Alive - Workspace
Operation - Workspace
Operation Error - Workspace
Page - Workspace
Record - Workspace
Resource Usage - Workspace
Search Request - One bounded typed search entry point. Fields that do not apply to the selected kind are rejected by the service rather than guessed.
- Workspace
Search Response - Workspace
Session - Workspace
Storage Usage - Workspace
Text Replacement - Workspace
Version Conflict - Write
File Bytes Request - Write
File Request - Write
Space File Request
Enums§
- Change
SetLifecycle - Command
Network Policy - Command
State - Computer
Command Output Stream - Computer
Command State - Computer
Lifecycle - Environment
Build Status - Environment
Error Code - Environment
Idempotency State - Operation
State - Output
Stream - Owner
Kind - Resource owner identity. At least one owner is required on every Environment resource; callers authenticate with runtime, agent, or user credentials.
- Owner
Validation Error - Principal
Kind - Provider
Sandbox Placement - Provider
Snapshot Source - Resource
Pressure Dimension - Resource
Pressure Severity - Resource
Usage Status - Sandbox
Lifecycle - Sandbox
Placement - Snapshot
Build Spec - Snapshot
Lifecycle - Snapshot
Source Record - Snapshot
Visibility - Space
Access Mode - Space
Capability - Space
Lifecycle - Space
Persistence - Space
Session Lifecycle - Store
Computer Command Outcome - Template
Target - Template
Version State - Upload
State - Workspace
Change SetStatus - Workspace
File Change Kind - Workspace
Lifecycle - Workspace
Patch Operation - Workspace
Search Kind
Constants§
- ADMIN_
BUILD_ BUILTIN_ SNAPSHOTS_ PATH - ADMIN_
SNAPSHOTS_ PATH - ADMIN_
SNAPSHOT_ PATH - BUILD_
BUILTIN_ SNAPSHOTS_ PATH - CATALOG_
SNAPSHOTS_ PATH - CATALOG_
SNAPSHOT_ PATH - COMPUTERS_
PATH - COMPUTER_
COMMANDS_ PATH - COMPUTER_
COMMAND_ CANCEL_ PATH - COMPUTER_
COMMAND_ OUTPUT_ PATH - COMPUTER_
COMMAND_ PATH - COMPUTER_
OWNERS_ PATH - COMPUTER_
PATH - DELEGATIONS_
PATH - DELEGATION_
REVOKE_ PATH - E2B_
BUILTIN_ TEMPLATE_ IDS - E2B_
PLATFORM_ TEMPLATE_ ID - Provider-owned images used when product create APIs omit every Workspace catalog snapshot/template selector. A configured catalog default still takes precedence and is resolved to its provider external id by Runtime.
- ENVIRONMENT_
MAX_ FILE_ BYTES - ENVIRONMENT_
MAX_ PATH_ BYTES - MOULIN_
PLATFORM_ SNAPSHOT_ ID - SANDBOXES_
PATH - SANDBOX_
PATH - SANDBOX_
SKILLS_ PATH - Product path for installing a Skills Hub package into a running Sandbox.
- SANDBOX_
SKILL_ DEFAULT_ PROVIDER - Default sandbox provider when the caller omits
provider. - SANDBOX_
SKILL_ DEFAULT_ VERSION - Default Skills Hub version selector when the caller omits
version. - SANDBOX_
SKILL_ INSTALL_ ROOT - Sandbox-root directory that receives unpacked skill packages.
- SANDBOX_
STOP_ PATH - SKILLS_
SEARCH_ PATH - Product path for searching published Skills Hub packages.
- SNAPSHOTS_
PATH - SNAPSHOT_
DOCKERFILE_ MAX_ BYTES - Product-facing snapshot recipe size limits. The build adapters impose additional limits on fetched repository contents and generated archives.
- SNAPSHOT_
PATH - SNAPSHOT_
TEMPLATE_ PACKAGES_ MAX_ BYTES - SPACES_
PATH - SPACE_
CHANGE_ SETS_ PATH - SPACE_
CHANGE_ SET_ APPLY_ PATH - SPACE_
FILES_ LIST_ PATH - SPACE_
FILES_ PATH - SPACE_
FILES_ READ_ PATH - SPACE_
GRANTS_ PATH - SPACE_
GRANT_ REVOKE_ PATH - SPACE_
LEASES_ PATH - SPACE_
LEASE_ PATH - SPACE_
OWNERS_ PATH - SPACE_
PATH - SPACE_
SESSIONS_ PATH - SPACE_
SESSION_ CLOSE_ PATH - SPACE_
SESSION_ HEARTBEAT_ PATH - SPACE_
SKILLS_ PATH - Product path for installing a Skills Hub package into a Runtime-bound Space.
- SPACE_
SKILL_ INSTALL_ ROOT - Space-relative directory that Runtime workspace tools expose to the agent.
- SPACE_
TICKETS_ PATH - TEMPLATES_
PATH - TEMPLATE_
VERSIONS_ PATH - TEMPLATE_
VERSION_ DEPRECATE_ PATH - TEMPLATE_
VERSION_ PATH - TEMPLATE_
VERSION_ PUBLISH_ PATH - WORKSPACES_
PATH - WORKSPACE_
CLONE_ PATH - WORKSPACE_
COMMANDS_ PATH - WORKSPACE_
COMMAND_ CANCEL_ PATH - WORKSPACE_
COMMAND_ OUTPUT_ PATH - WORKSPACE_
COMMAND_ PATH - WORKSPACE_
LEASE_ PATH - WORKSPACE_
MAX_ COMMAND_ BYTES - WORKSPACE_
MAX_ COMMAND_ CPU_ MILLIS - WORKSPACE_
MAX_ COMMAND_ DISK_ BYTES - WORKSPACE_
MAX_ COMMAND_ MEMORY_ BYTES - WORKSPACE_
MAX_ COMMAND_ OUTPUT_ BYTES - WORKSPACE_
MAX_ COMMAND_ PROCESSES - WORKSPACE_
MAX_ COMMAND_ TIMEOUT_ MS - WORKSPACE_
MAX_ FILE_ BYTES - WORKSPACE_
MAX_ OUTPUT_ CHUNKS - WORKSPACE_
MAX_ PAGE_ SIZE - WORKSPACE_
MAX_ PATH_ BYTES - WORKSPACE_
MAX_ RESULTS - WORKSPACE_
MAX_ RETENTION_ MS - WORKSPACE_
MAX_ SEARCH_ OUTPUT_ BYTES - WORKSPACE_
MAX_ SNAPSHOT_ BYTES - WORKSPACE_
MAX_ UPLOAD_ BYTES - WORKSPACE_
MIGRATE_ PATH - WORKSPACE_
MISSING_ FILE_ REVISION - Reserved compare-and-swap revision representing an absent file.
- WORKSPACE_
OPERATIONS_ PATH - WORKSPACE_
OPERATION_ CANCEL_ PATH - WORKSPACE_
OUTPUT_ CHUNK_ BYTES - WORKSPACE_
PATH - WORKSPACE_
PREVIEW_ TTL_ MS - WORKSPACE_
RECONCILE_ PATH - WORKSPACE_
RESOURCE_ EXHAUSTED_ CODE - WORKSPACE_
RESOURCE_ FILE_ PATH - Resource-scoped file API used by leftover managed callers.
filePathis an axum catch-all and therefore may contain workspace-relative/separators. - WORKSPACE_
RESOURCE_ SEARCH_ PATH - WORKSPACE_
RESUME_ PATH - WORKSPACE_
SERVICE_ NAME - WORKSPACE_
SNAPSHOTS_ PATH - WORKSPACE_
SNAPSHOT_ ARCHIVE_ MAGIC - WORKSPACE_
SNAPSHOT_ RESTORE_ PATH - WORKSPACE_
SUSPEND_ PATH - WORKSPACE_
UPLOADS_ PATH - WORKSPACE_
UPLOAD_ CHUNK_ BYTES - Resumable uploads deliberately use small chunks so request memory is bounded independently from the maximum completed file size.
- WORKSPACE_
UPLOAD_ PATH - WORKSPACE_
UPLOAD_ TTL_ MS - WORKSPACE_
USAGE_ PATH - WORKSPACE_
VERSION_ CONFLICT_ CODE
Traits§
- Command
Permit Repository - Computer
Provider - Environment
Build Port - Build-only port. Implementations must not create Computer or Sandbox instances.
- Environment
Command Repository - Command metadata and output are stored independently from the Environment aggregate snapshot. This keeps output appends O(chunks) instead of copying every resource in a tenant/project scope.
- Environment
Metadata Repository - Environment
Provider Registry - Environment
Repository - Production Environment persistence owns both aggregate metadata and the independently indexed command log.
- Preview
Lifecycle Provider - Provider
Resilience Policy - Narrow strategy port for provider retry and circuit-opening decisions.
- Sandbox
Provider - Secret
Resolver - Skill
HubClient - Downloads a published skill archive. Implementations live in adapter crates.
- Snapshot
Object Reader - Bounded, random-access reader used across application and object-store
ports. Implementations must never return more than
max_bytes. - Snapshot
Object Store - Snapshot
Object Upload - Snapshot
Provider - Snapshot
Provider Port - Space
Provider - Template
Provider Port - Workspace
- The core workspace trait. All filesystem and command execution flows through this.
- Workspace
Advanced Repository - Workspace
Command Executor - Workspace
Commands - Narrow command capability. Possession of this port is an explicit privilege.
- Workspace
Control Repository - Workspace
Files - Narrow file capability for consumers that must not gain command execution.
- Workspace
Provider Adapter - Workspace
Provider Registry - Workspace
Repository - Aggregate metadata port used by the application layer. Concrete SQL/storage technology belongs in adapter crates.
- Workspace
Search - Narrow bounded-search capability.
- Workspace
Session Resolver - Workspace
Upload Writer
Functions§
- content_
revision - Collision-resistant content revision shared by CAS and idempotency paths.
- is_
workspace_ resource_ exhausted_ message - normalize_
owners - Normalize owners: non-empty, deduplicated, stable order.
- normalize_
workspace_ operation_ error - owners_
intersect - True when caller and resource owners share at least one identity.
- owners_
subset_ of - True when
candidateis a subset ofparent(every element of candidate in parent). - required_
workspace_ capability - Return the capability required by both the public Gateway alias and the internal Workspace service route. Keeping this decision in the contract prevents the Gateway-issued downstream credential from drifting away from the capability independently enforced by the Workspace server.
- revision_
matches - snapshot_
digest - space_
directory_ path - Logical directory for a Space on its parent Computer filesystem.
- strip_
environment_ api_ prefix - Strip
/internal/v1or/v1, then the Environment domain prefix/workspacewhen it is a full path segment./workspaces(plural managed API) is left intact. - valid_
computer_ command_ transition - workspace_
error_ details