Skip to main content

Module sandbox_image

Module sandbox_image 

Source
Expand description

What a sandbox image must carry for the agent to serve, and the Dockerfile text carrying it.

Two images exist and neither is built the way the other is. AWS renders one per deployment onto a customer-supplied base image; GCP builds one static image in CI. Nothing at build time reads the other side, and a value that disagrees is invisible until a session fails: an agent listening on a port no caller dials, or an exec into a uid the image never created.

So the values live here once and both images render the block that carries them from this module. The GCP image is committed as generated text because the release workflow builds it with docker build, which cannot call a Rust function.

Structs§

SandboxImage
The values an image must carry for the agent to run in it.

Enums§

Authorization
How the agent decides a caller may be served.
Isolation
How an image ends, and the isolation that ending permits.

Constants§

AGENT_PATH
Path the agent binary is installed at inside every sandbox image.
AGENT_PORT
Port the agent serves unless the platform pins another.
AWS_MICROVM
The Lambda MicroVM image, rendered per deployment onto a customer base image.
GCP_AGENT_PLATFORM
The GCP Agent Platform image, built once in CI and run with nothing layered on top.

Functions§

contract_env
The ENV block carrying the agent’s configuration contract.
entrypoint
EXPOSE, the image’s ending, and the ENTRYPOINT.
identity_setup
The RUN step creating the exec identity and the session root it owns.