pub struct Sandbox {
pub id: String,
pub code: SandboxCode,
pub limits: Option<SandboxLimits>,
pub egress: SandboxEgress,
pub lifecycle: SandboxLifecyclePolicy,
pub preview_ports: Vec<u16>,
}Expand description
An isolated environment for running untrusted code, created at runtime.
Fields§
§id: StringIdentifier for the sandbox. Must contain only alphanumeric characters, hyphens, and underscores ([A-Za-z0-9-_]). Maximum 64 characters.
code: SandboxCodeWhere the sandbox’s root filesystem comes from
limits: Option<SandboxLimits>Enforced resource ceilings.
Optional because not every platform can enforce them, and a declaration that names none takes the platform’s own defaults. Naming them on a platform that cannot enforce them is rejected at plan time rather than silently ignored.
egress: SandboxEgressOutbound network policy
lifecycle: SandboxLifecyclePolicySandbox lifetime ceiling and idle behaviour
preview_ports: Vec<u16>Ports eligible for a preview capability. An application reaches its sandbox through the provider, so it cannot widen its own ingress at runtime; a holder of a remote binding’s credentials is bounded by no port condition, which is why a remote sandbox declares none.
Implementations§
Source§impl Sandbox
impl Sandbox
Sourcepub fn new(id: String) -> SandboxBuilder
pub fn new(id: String) -> SandboxBuilder
Create an instance of Sandbox using the builder syntax
Source§impl Sandbox
impl Sandbox
Sourcepub const RESOURCE_TYPE: ResourceType
pub const RESOURCE_TYPE: ResourceType
The resource type identifier for Sandbox
Sourcepub fn resolved_limits(&self) -> SandboxLimits
pub fn resolved_limits(&self) -> SandboxLimits
The declared ceilings, or the defaults a platform applies when none were named.
Backends want a concrete set: a sandbox with no declared ceilings still runs inside
whatever the platform gives it, and a backend that had to branch on None would end up
inventing its own default anyway.
Sourcepub fn validate_for_platform(&self, platform: Platform) -> Result<()>
pub fn validate_for_platform(&self, platform: Platform) -> Result<()>
Validates the declaration against what the target platform can enforce.
Runs at plan time so an unenforceable limit or an unsupported egress mode fails before anything is provisioned, rather than at the first exec.
Sourcepub fn azure_catalog_image(&self) -> Result<&str>
pub fn azure_catalog_image(&self) -> Result<&str>
The catalog disk image Azure creates a sandbox from.
Azure names a public catalog entry rather than pulling a reference, so a registry path, tag or digest has nowhere to go. An allowlist, because the answer to “what else could be in there” is a name the data plane rejects at the first sandbox, long after the apply.
Sourcepub fn azure_sandbox_limits(&self) -> Result<()>
pub fn azure_sandbox_limits(&self) -> Result<()>
Checks the declared ceilings against Azure’s sizing rule (the AZURE_* constants above).
Refused at plan time, like Self::microvm_tier, so a bad value is a declaration to fix
rather than a runtime fault at create.
Sourcepub fn microvm_tier(&self) -> Result<MicrovmTier>
pub fn microvm_tier(&self) -> Result<MicrovmTier>
The MicroVM size that keeps every declared ceiling, or why none does.
AWS sizes are discrete and a running MicroVM bursts to four times its baseline, so the only tier that honours a ceiling is one whose peak fits inside it. A declaration no tier satisfies is refused: shipping the nearest size would give the customer a sandbox that exceeds the bound they wrote down.
Trait Implementations§
Source§impl<'de> Deserialize<'de> for Sandbox
impl<'de> Deserialize<'de> for Sandbox
Source§fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
impl Eq for Sandbox
Source§impl ResourceDefinition for Sandbox
impl ResourceDefinition for Sandbox
Source§fn get_resource_type(&self) -> ResourceType
fn get_resource_type(&self) -> ResourceType
Source§fn get_dependencies(&self) -> Vec<ResourceRef>
fn get_dependencies(&self) -> Vec<ResourceRef>
Source§fn validate_update(&self, new_config: &dyn ResourceDefinition) -> Result<()>
fn validate_update(&self, new_config: &dyn ResourceDefinition) -> Result<()>
Source§fn as_any_mut(&mut self) -> &mut dyn Any
fn as_any_mut(&mut self) -> &mut dyn Any
Source§fn box_clone(&self) -> Box<dyn ResourceDefinition>
fn box_clone(&self) -> Box<dyn ResourceDefinition>
Source§fn resource_eq(&self, other: &dyn ResourceDefinition) -> bool
fn resource_eq(&self, other: &dyn ResourceDefinition) -> bool
Source§fn to_json_value(&self) -> Result<Value>
fn to_json_value(&self) -> Result<Value>
impl StructuralPartialEq for Sandbox
Auto Trait Implementations§
impl Freeze for Sandbox
impl RefUnwindSafe for Sandbox
impl Send for Sandbox
impl Sync for Sandbox
impl Unpin for Sandbox
impl UnsafeUnpin for Sandbox
impl UnwindSafe for Sandbox
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> DeserializeOwned for Twhere
T: for<'de> Deserialize<'de>,
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§fn equivalent(&self, key: &K) -> bool
fn equivalent(&self, key: &K) -> bool
key and return true if they are equal.