Expand description
What a sandbox image must carry for the agent to serve, and the Dockerfile text carrying it.
Two kinds of image exist and neither is built the way the other is. AWS renders one per deployment onto a customer-supplied base image; GCP builds static images in CI. Nothing at build time reads the other side, and a value that disagrees is invisible until a session fails: an agent listening on a port no caller dials, or an exec into a uid the image never created.
So the values live here once and both kinds render the block that carries them from this
module. The same holds for the default sandbox base both kinds start from: its toolchain is
listed here once, and a probe reads that list rather than restating it. The Dockerfiles and the
tool list are committed as generated text because CI builds them with docker build and probes
them from a shell, neither of which can call a Rust function.
Structs§
- Sandbox
Image - The values an image must carry for the agent to run in it.
- Sandbox
Image Command - Root-owned metadata copied from the base image at bundle creation, never from an exec caller.
- Sandbox
Tool - A tool the default sandbox base ships, and the command that shows it runs.
Enums§
- Authorization
- How the agent decides a caller may be served.
- Isolation
- How an image ends, and the isolation that ending permits.
Constants§
- AGENT_
MODE - Mode of the agent binary, owned by
0:0so the exec uid cannot rewrite its supervisor. - AGENT_
PATH - Path the agent binary is installed at inside every sandbox image.
- AGENT_
PORT - Port the agent serves unless the platform pins another.
- AWS_
MICROVM - The Lambda MicroVM image, rendered per deployment onto a customer base image.
- DEFAULT_
SANDBOX_ BASE_ IMAGE - The image every default sandbox builds on, by index digest so both architectures are pinned.
- DEFAULT_
SANDBOX_ TOOLS - The toolchain of the default sandbox base, and the one list its probes read.
- DEFAULT_
SANDBOX_ UV_ IMAGE - The image uv and uvx are copied out of, by index digest.
- EXEC_
USER - Name of the exec identity’s passwd and group entries.
- GCP_
AGENT_ LOG_ FILTER RUST_LOGfor a GCP image, which the agent needs set before it logs anything.- GCP_
AGENT_ PLATFORM - The GCP Agent Platform image, built once in CI and run with nothing layered on top.
- IMAGE_
COMMAND_ PATH - Installed outside the command-writable session directory.
- SESSION_
ROOT_ MODE - Mode of the session root, which the exec uid owns.
Functions§
- contract_
env - The
ENVblock carrying the agent’s configuration contract. - entrypoint
EXPOSE, the image’s ending, and theENTRYPOINT.- gcp_
agent_ platform_ env - Every variable a GCP Agent Platform image sets: the contract, then
RUST_LOG. - identity_
setup - The
RUNstep creating the exec identity and the session root it owns.