Skip to main content

AwsSandboxBinding

Struct AwsSandboxBinding 

Source
pub struct AwsSandboxBinding {
    pub image_arn: BindingValue<String>,
    pub image_version: BindingValue<String>,
    pub region: BindingValue<String>,
    pub execution_role_arn: Option<BindingValue<String>>,
    pub egress_connector_arns: Vec<BindingValue<String>>,
    pub preview_ports: Vec<u16>,
    pub idle_suspend_seconds: Option<u32>,
    pub max_lifetime_seconds: Option<u32>,
    pub allow_egress: bool,
}
Expand description

AWS sandbox binding configuration.

Fields§

§image_arn: BindingValue<String>

MicroVM image ARN that scopes this sandbox’s sessions

§image_version: BindingValue<String>

Image version. Sessions are enumerated by image and version together, so a rolled version remains a cleanup scope until its own MicroVMs are gone.

§region: BindingValue<String>

Region the MicroVMs run in

§execution_role_arn: Option<BindingValue<String>>

Execution role attached to each MicroVM, distinct from the workload’s own role

§egress_connector_arns: Vec<BindingValue<String>>

Egress connectors every session is started with.

Carried rather than implied: a MicroVM started with no connector reaches the public internet, so an empty list here is allow, not deny. The declared mode is realised by which connector setup built, and the session has to be started with it.

§preview_ports: Vec<u16>

Ports a preview capability may be minted for.

Carried because the token is what grants ingress: CreateMicrovmAuthToken mints access to whatever port it is asked for, so “a port not listed here can never be exposed” is only true if the declared list reaches the code that mints.

§idle_suspend_seconds: Option<u32>

Idle seconds after which a session suspends, if the declaration asked for one.

§max_lifetime_seconds: Option<u32>

Wall-clock ceiling on a session, if the declaration asked for one.

Enforced by Lambda rather than by us: RunMicrovm takes it as maximumDurationInSeconds and terminates the MicroVM when it elapses.

§allow_egress: bool

Whether the declaration asked for open egress.

Carried because an empty connector list cannot otherwise be read: a MicroVM started with no connector reaches the internet, so a deny binding stripped of its connectors would be indistinguishable from allow. Absent means deny, which is the answer that fails closed.

Trait Implementations§

Source§

impl Clone for AwsSandboxBinding

Source§

fn clone(&self) -> AwsSandboxBinding

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for AwsSandboxBinding

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl<'de> Deserialize<'de> for AwsSandboxBinding

Source§

fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>
where __D: Deserializer<'de>,

Deserialize this value from the given Serde deserializer. Read more
Source§

impl Eq for AwsSandboxBinding

Source§

impl PartialEq for AwsSandboxBinding

Source§

fn eq(&self, other: &AwsSandboxBinding) -> bool

Equality operator ==. Read more
1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Inequality operator !=. Read more
Source§

impl Serialize for AwsSandboxBinding

Source§

fn serialize<__S>(&self, __serializer: __S) -> Result<__S::Ok, __S::Error>
where __S: Serializer,

Serialize this value into the given Serde serializer. Read more
Source§

impl StructuralPartialEq for AwsSandboxBinding

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> DeserializeOwned for T
where T: for<'de> Deserialize<'de>,

Source§

impl<Q, K> Equivalent<K> for Q
where Q: Eq + ?Sized, K: Borrow<Q> + ?Sized,

Source§

fn equivalent(&self, key: &K) -> bool

Checks if this value is equivalent to the given key. Read more
Source§

impl<Q, K> Equivalent<K> for Q
where Q: Eq + ?Sized, K: Borrow<Q> + ?Sized,

Source§

fn equivalent(&self, key: &K) -> bool

Compare self to key and return true if they are equal.
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self> ⓘ

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self> ⓘ

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V

Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self> ⓘ
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self> ⓘ

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more