Expand description
What a sandbox image must carry for the agent to serve, and the Dockerfile text carrying it.
Two kinds of image exist and neither is built the way the other is. AWS renders one per deployment onto a customer-supplied base image; GCP builds static images in CI. Nothing at build time reads the other side, and a value that disagrees is invisible until a session fails: an agent listening on a port no caller dials, or an exec into a uid the image never created.
So the values live here once and both kinds render the block that carries them from this
module. The GCP Dockerfiles are committed as generated text because the release workflow builds
them with docker build, which cannot call a Rust function.
Structs§
- Sandbox
Image - The values an image must carry for the agent to run in it.
Enums§
- Authorization
- How the agent decides a caller may be served.
- Isolation
- How an image ends, and the isolation that ending permits.
Constants§
- AGENT_
MODE - Mode of the agent binary, owned by
0:0so the exec uid cannot rewrite its supervisor. - AGENT_
PATH - Path the agent binary is installed at inside every sandbox image.
- AGENT_
PORT - Port the agent serves unless the platform pins another.
- AWS_
MICROVM - The Lambda MicroVM image, rendered per deployment onto a customer base image.
- EXEC_
USER - Name of the exec identity’s passwd and group entries.
- GCP_
AGENT_ LOG_ FILTER RUST_LOGfor a GCP image, which the agent needs set before it logs anything.- GCP_
AGENT_ PLATFORM - The GCP Agent Platform image, built once in CI and run with nothing layered on top.
- SESSION_
ROOT_ MODE - Mode of the session root, which the exec uid owns.
Functions§
- contract_
env - The
ENVblock carrying the agent’s configuration contract. - entrypoint
EXPOSE, the image’s ending, and theENTRYPOINT.- gcp_
agent_ platform_ env - Every variable a GCP Agent Platform image sets: the contract, then
RUST_LOG. - identity_
setup - The
RUNstep creating the exec identity and the session root it owns.