pub struct AwsSandboxBinding {
pub image_arn: BindingValue<String>,
pub image_version: BindingValue<String>,
pub region: BindingValue<String>,
pub execution_role_arn: Option<BindingValue<String>>,
pub egress_connector_arns: Vec<BindingValue<String>>,
pub preview_ports: Vec<u16>,
pub idle_pause_seconds: Option<u32>,
pub max_lifetime_seconds: Option<u32>,
pub allow_egress: bool,
}Expand description
AWS sandbox binding configuration.
Fields§
§image_arn: BindingValue<String>MicroVM image ARN that scopes the sandboxes this binding creates
image_version: BindingValue<String>Image version. Sandboxes are enumerated by image and version together, so a rolled version remains a cleanup scope until its own MicroVMs are gone.
region: BindingValue<String>Region the MicroVMs run in
execution_role_arn: Option<BindingValue<String>>Execution role attached to each MicroVM, distinct from the workload’s own role
egress_connector_arns: Vec<BindingValue<String>>Egress connectors every sandbox is started with.
Carried rather than implied: a MicroVM started with no connector reaches the public
internet, so an empty list here is allow, not deny. The declared mode is realised by
which connector setup built, and the sandbox has to be started with it.
preview_ports: Vec<u16>Ports a preview capability may be minted for.
Carried because the token is what grants ingress: CreateMicrovmAuthToken mints access to
whatever port it is asked for, so “a port not listed here can never be exposed” is only
true if the declared list reaches the code that mints.
idle_pause_seconds: Option<u32>Idle seconds after which a sandbox pauses, if the declaration asked for one.
max_lifetime_seconds: Option<u32>Wall-clock ceiling on a sandbox, if the declaration asked for one.
Enforced by Lambda rather than by us: RunMicrovm takes it as
maximumDurationInSeconds and terminates the MicroVM when it elapses.
allow_egress: boolWhether the declaration asked for open egress.
Carried because an empty connector list cannot otherwise be read: a MicroVM started with
no connector reaches the internet, so a deny binding stripped of its connectors would be
indistinguishable from allow. Absent means deny, which is the answer that fails closed.
Trait Implementations§
Source§impl Clone for AwsSandboxBinding
impl Clone for AwsSandboxBinding
Source§fn clone(&self) -> AwsSandboxBinding
fn clone(&self) -> AwsSandboxBinding
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read moreSource§impl Debug for AwsSandboxBinding
impl Debug for AwsSandboxBinding
Source§impl<'de> Deserialize<'de> for AwsSandboxBinding
impl<'de> Deserialize<'de> for AwsSandboxBinding
Source§fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
impl Eq for AwsSandboxBinding
Source§impl PartialEq for AwsSandboxBinding
impl PartialEq for AwsSandboxBinding
Source§impl Serialize for AwsSandboxBinding
impl Serialize for AwsSandboxBinding
impl StructuralPartialEq for AwsSandboxBinding
Auto Trait Implementations§
impl Freeze for AwsSandboxBinding
impl RefUnwindSafe for AwsSandboxBinding
impl Send for AwsSandboxBinding
impl Sync for AwsSandboxBinding
impl Unpin for AwsSandboxBinding
impl UnsafeUnpin for AwsSandboxBinding
impl UnwindSafe for AwsSandboxBinding
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> DeserializeOwned for Twhere
T: for<'de> Deserialize<'de>,
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§fn equivalent(&self, key: &K) -> bool
fn equivalent(&self, key: &K) -> bool
key and return true if they are equal.