pub struct SandboxLimits {
pub cpu: String,
pub memory: String,
pub disk: String,
pub max_processes: Option<u32>,
}Expand description
Hard ceilings enforced on a sandbox.
These are limits, not scheduling requests. Untrusted code does not respect a hint, so every field is enforced by the platform and a platform that cannot enforce one is rejected at plan time rather than silently ignoring it.
Fields§
§cpu: StringCPU ceiling in cores or millicores (e.g. "1", "500m")
memory: StringMemory ceiling (e.g. "2Gi", "512Mi")
disk: StringDisk ceiling (e.g. "20Gi")
max_processes: Option<u32>Maximum number of processes, which bounds fork bombs.
Optional because only a container runtime has the primitive: Kubernetes sets a pid ceiling per node, not per pod, and neither AWS MicroVMs nor Azure sandboxes expose one. Declaring it on a platform that cannot apply it is refused at plan time.
Trait Implementations§
Source§impl Clone for SandboxLimits
impl Clone for SandboxLimits
Source§impl Debug for SandboxLimits
impl Debug for SandboxLimits
Source§impl<'de> Deserialize<'de> for SandboxLimits
impl<'de> Deserialize<'de> for SandboxLimits
Source§fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
Deserialize this value from the given Serde deserializer. Read more
impl Eq for SandboxLimits
Source§impl PartialEq for SandboxLimits
impl PartialEq for SandboxLimits
Source§impl Serialize for SandboxLimits
impl Serialize for SandboxLimits
impl StructuralPartialEq for SandboxLimits
Auto Trait Implementations§
impl Freeze for SandboxLimits
impl RefUnwindSafe for SandboxLimits
impl Send for SandboxLimits
impl Sync for SandboxLimits
impl Unpin for SandboxLimits
impl UnsafeUnpin for SandboxLimits
impl UnwindSafe for SandboxLimits
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> DeserializeOwned for Twhere
T: for<'de> Deserialize<'de>,
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§fn equivalent(&self, key: &K) -> bool
fn equivalent(&self, key: &K) -> bool
Compare self to
key and return true if they are equal.