Expand description
What a sandbox image must carry for the agent to serve, and the Dockerfile text carrying it.
Two images exist and neither is built the way the other is. AWS renders one per deployment onto a customer-supplied base image; GCP builds one static image in CI. Nothing at build time reads the other side, and a value that disagrees is invisible until a session fails: an agent listening on a port no caller dials, or an exec into a uid the image never created.
So the values live here once and both images render the block that carries them from this
module. The GCP image is committed as generated text because the release workflow builds it
with docker build, which cannot call a Rust function.
Structs§
- Sandbox
Image - The values an image must carry for the agent to run in it.
Enums§
- Authorization
- How the agent decides a caller may be served.
- Isolation
- How an image ends, and the isolation that ending permits.
Constants§
- AGENT_
PATH - Path the agent binary is installed at inside every sandbox image.
- AGENT_
PORT - Port the agent serves unless the platform pins another.
- AWS_
MICROVM - The Lambda MicroVM image, rendered per deployment onto a customer base image.
- GCP_
AGENT_ PLATFORM - The GCP Agent Platform image, built once in CI and run with nothing layered on top.
Functions§
- contract_
env - The
ENVblock carrying the agent’s configuration contract. - entrypoint
EXPOSE, the image’s ending, and theENTRYPOINT.- identity_
setup - The
RUNstep creating the exec identity and the session root it owns.