Skip to main content

alien_core/import/data/aws/
sandbox.rs

1use serde::{Deserialize, Serialize};
2
3/// AWS Sandbox ImportData.
4///
5/// Carries the sandbox's parent from the setup emitter to the runtime controller. The image
6/// **version** is not decoration: `RunMicrovm` has no `tags`, so image plus version is the only
7/// session identity there is, and a controller holding a stale version would enumerate the wrong
8/// set and orphan every session started on the previous one.
9///
10/// Two shapes arrive here, and which fields are present says which. A Frozen sandbox is built by
11/// stack creation and names its image; a Live one is built by the controller after the deployment
12/// registers, so it names the build role and bundle instead, leaving the image fields empty.
13#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
14#[cfg_attr(feature = "openapi", derive(utoipa::ToSchema))]
15#[cfg_attr(feature = "jsonschema", derive(schemars::JsonSchema))]
16#[serde(rename_all = "camelCase")]
17pub struct AwsSandboxImportData {
18    /// MicroVM image identifier. Absent until a runtime-provisioned image has been built.
19    #[serde(default, skip_serializing_if = "Option::is_none")]
20    pub image_identifier: Option<String>,
21    /// MicroVM image ARN. Absent until a runtime-provisioned image has been built.
22    #[serde(default, skip_serializing_if = "Option::is_none")]
23    pub image_arn: Option<String>,
24    /// Image version the sessions are scoped to. Re-imported on every image roll, and absent
25    /// until a runtime-provisioned image has been built.
26    #[serde(default, skip_serializing_if = "Option::is_none")]
27    pub image_version: Option<String>,
28    /// Role the controller passes to `CreateMicrovmImage`. Setup owns it because
29    /// `sandbox/provision` grants the controller `iam:PassRole` and no `iam:CreateRole`.
30    #[serde(default, skip_serializing_if = "Option::is_none")]
31    pub build_role_arn: Option<String>,
32    /// Bundle the controller builds the image from. Only a runtime-provisioned sandbox carries it.
33    #[serde(default, skip_serializing_if = "Option::is_none")]
34    pub bundle_uri: Option<String>,
35    /// Egress network connectors. Deleting one while MicroVMs still reference it breaks their
36    /// networking, so teardown needs them named rather than rediscovered.
37    #[serde(default, skip_serializing_if = "Vec::is_empty")]
38    pub egress_connector_arns: Vec<String>,
39    /// Ports a preview capability may be minted for; empty means preview is not offered.
40    #[serde(
41        default,
42        skip_serializing_if = "Vec::is_empty",
43        deserialize_with = "crate::import::data::deserialize_u16_vec_from_numbers_or_strings"
44    )]
45    pub preview_ports: Vec<u16>,
46    /// Whether the declaration asked for open egress.
47    ///
48    /// The controller builds the binding from this, and an empty connector list cannot be read
49    /// without it: a stripped `deny` import would otherwise look exactly like an open sandbox.
50    #[serde(
51        default,
52        skip_serializing_if = "std::ops::Not::not",
53        deserialize_with = "crate::import::data::deserialize_bool_from_bool_or_string"
54    )]
55    pub allow_egress: bool,
56}