Skip to main content

Sandbox

Struct Sandbox 

Source
pub struct Sandbox {
    pub id: String,
    pub code: SandboxCode,
    pub limits: Option<SandboxLimits>,
    pub egress: SandboxEgress,
    pub lifecycle: SandboxLifecyclePolicy,
    pub preview_ports: Vec<u16>,
}
Expand description

An isolated environment for running untrusted code, created at runtime.

Fields§

§id: String

Identifier for the sandbox. Must contain only alphanumeric characters, hyphens, and underscores ([A-Za-z0-9-_]). Maximum 64 characters.

§code: SandboxCode

Where the sandbox’s root filesystem comes from

§limits: Option<SandboxLimits>

Enforced resource ceilings.

Optional because not every platform can enforce them, and a declaration that names none takes the platform’s own defaults. Naming them on a platform that cannot enforce them is rejected at plan time rather than silently ignored.

§egress: SandboxEgress

Outbound network policy

§lifecycle: SandboxLifecyclePolicy

Sandbox lifetime ceiling and idle behaviour

§preview_ports: Vec<u16>

Ports eligible for a preview capability. An application reaches its sandbox through the provider, so it cannot widen its own ingress at runtime; a holder of a remote binding’s credentials is bounded by no port condition, which is why a remote sandbox declares none.

Implementations§

Source§

impl Sandbox

Source

pub fn new(id: String) -> SandboxBuilder

Create an instance of Sandbox using the builder syntax

Source§

impl Sandbox

Source

pub const RESOURCE_TYPE: ResourceType

The resource type identifier for Sandbox

Source

pub fn id(&self) -> &str

Returns the sandbox’s unique identifier.

Source

pub fn resolved_limits(&self) -> SandboxLimits

The declared ceilings, or the defaults a platform applies when none were named.

Backends want a concrete set: a sandbox with no declared ceilings still runs inside whatever the platform gives it, and a backend that had to branch on None would end up inventing its own default anyway.

Source

pub fn validate_for_platform(&self, platform: Platform) -> Result<()>

Validates the declaration against what the target platform can enforce.

Runs at plan time so an unenforceable limit or an unsupported egress mode fails before anything is provisioned, rather than at the first exec.

Source

pub fn azure_catalog_image(&self) -> Result<&str>

The catalog disk image Azure creates a sandbox from.

Azure names a public catalog entry rather than pulling a reference, so a registry path, tag or digest has nowhere to go. An allowlist, because the answer to “what else could be in there” is a name the data plane rejects at the first sandbox, long after the apply.

Source

pub fn azure_sandbox_limits(&self) -> Result<()>

Checks the declared ceilings against Azure’s sizing rule (the AZURE_* constants above). Refused at plan time, like Self::microvm_tier, so a bad value is a declaration to fix rather than a runtime fault at create.

Source

pub fn microvm_tier(&self) -> Result<MicrovmTier>

The MicroVM size that keeps every declared ceiling, or why none does.

AWS sizes are discrete and a running MicroVM bursts to four times its baseline, so the only tier that honours a ceiling is one whose peak fits inside it. A declaration no tier satisfies is refused: shipping the nearest size would give the customer a sandbox that exceeds the bound they wrote down.

Trait Implementations§

Source§

impl Clone for Sandbox

Source§

fn clone(&self) -> Sandbox

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for Sandbox

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl<'de> Deserialize<'de> for Sandbox

Source§

fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>
where __D: Deserializer<'de>,

Deserialize this value from the given Serde deserializer. Read more
Source§

impl Eq for Sandbox

Source§

impl PartialEq for Sandbox

Source§

fn eq(&self, other: &Sandbox) -> bool

Equality operator ==. Read more
1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Inequality operator !=. Read more
Source§

impl ResourceDefinition for Sandbox

Source§

fn get_resource_type(&self) -> ResourceType

Returns the resource type for this instance
Source§

fn id(&self) -> &str

Returns the unique identifier for this specific resource instance
Source§

fn get_dependencies(&self) -> Vec<ResourceRef>

Returns the list of other resources this resource depends on
Source§

fn validate_update(&self, new_config: &dyn ResourceDefinition) -> Result<()>

Validates if an update from the current configuration to a new configuration is allowed
Source§

fn as_any(&self) -> &dyn Any

Provides access to the underlying concrete type for downcasting
Source§

fn as_any_mut(&mut self) -> &mut dyn Any

Provides mutable access to the underlying concrete type for downcasting
Source§

fn box_clone(&self) -> Box<dyn ResourceDefinition>

Creates a boxed clone of this resource definition
Source§

fn resource_eq(&self, other: &dyn ResourceDefinition) -> bool

For equality comparison between resource definitions
Source§

fn to_json_value(&self) -> Result<Value>

Serialize this resource to a JSON value (without the “type” tag - that’s added by Resource)
Source§

fn get_permissions(&self) -> Option<&str>

Returns the permission profile name for this resource, if it has one. Read more
Source§

impl Serialize for Sandbox

Source§

fn serialize<__S>(&self, __serializer: __S) -> Result<__S::Ok, __S::Error>
where __S: Serializer,

Serialize this value into the given Serde serializer. Read more
Source§

impl StructuralPartialEq for Sandbox

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> DeserializeOwned for T
where T: for<'de> Deserialize<'de>,

Source§

impl<Q, K> Equivalent<K> for Q
where Q: Eq + ?Sized, K: Borrow<Q> + ?Sized,

Source§

fn equivalent(&self, key: &K) -> bool

Checks if this value is equivalent to the given key. Read more
Source§

impl<Q, K> Equivalent<K> for Q
where Q: Eq + ?Sized, K: Borrow<Q> + ?Sized,

Source§

fn equivalent(&self, key: &K) -> bool

Compare self to key and return true if they are equal.
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self> ⓘ

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self> ⓘ

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V

Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self> ⓘ
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self> ⓘ

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more