pub struct Sandbox {
pub id: String,
pub code: SandboxCode,
pub private_base_image: Option<String>,
pub limits: Option<SandboxLimits>,
pub egress: SandboxEgress,
pub privileged_supervisor: Option<SandboxPrivilegedSupervisor>,
pub lifecycle: SandboxLifecyclePolicy,
pub preview_ports: Vec<u16>,
}Expand description
An isolated environment for running untrusted code, created at runtime.
Fields§
§id: StringIdentifier for the sandbox. Must contain only alphanumeric characters, hyphens, and underscores ([A-Za-z0-9-_]). Maximum 64 characters.
code: SandboxCodeWhere the sandbox’s root filesystem comes from
private_base_image: Option<String>Private ECR base image an AWS build pulls; code.image names only the S3 bundle, so this is
what the cross-account grant opens. Live only: the grant needs the customer account,
which registration reports. Absent means the base image is pulled anonymously.
limits: Option<SandboxLimits>Enforced resource ceilings.
Optional because not every platform can enforce them, and a declaration that names none takes the platform’s own defaults. Naming them on a platform that cannot enforce them is rejected at plan time rather than silently ignored.
egress: SandboxEgressOutbound network policy
privileged_supervisor: Option<SandboxPrivilegedSupervisor>Have Alien’s agent install the declared egress policy before running any image code. Unsupported backends refuse this at plan time.
lifecycle: SandboxLifecyclePolicySandbox lifetime ceiling and idle behaviour.
Stored state written before the rename calls this session. A stack state or release
that old must stay readable, otherwise its deployment can no longer be updated or deleted.
preview_ports: Vec<u16>Ports eligible for a preview capability. An application reaches its sandbox through the provider, so it cannot widen its own ingress at runtime; a holder of a remote binding’s credentials is bounded by no port condition, which is why a remote sandbox declares none.
Implementations§
Source§impl Sandbox
impl Sandbox
Sourcepub fn new(id: String) -> SandboxBuilder
pub fn new(id: String) -> SandboxBuilder
Create an instance of Sandbox using the builder syntax
Source§impl Sandbox
impl Sandbox
Sourcepub const RESOURCE_TYPE: ResourceType
pub const RESOURCE_TYPE: ResourceType
The resource type identifier for Sandbox
Sourcepub fn cloud_egress(&self) -> &SandboxEgress
pub fn cloud_egress(&self) -> &SandboxEgress
Cloud routing stays open when the agent owns enforcement.
Sourcepub fn supervisor_environment(&self) -> BTreeMap<String, String>
pub fn supervisor_environment(&self) -> BTreeMap<String, String>
Startup contract for the privileged agent; never supplied by an exec caller.
Sourcepub fn resolved_limits(&self) -> SandboxLimits
pub fn resolved_limits(&self) -> SandboxLimits
The declared ceilings, or the defaults a platform applies when none were named.
Backends want a concrete set: a sandbox with no declared ceilings still runs inside
whatever the platform gives it, and a backend that had to branch on None would end up
inventing its own default anyway.
Sourcepub fn validate_for_platform(&self, platform: Platform) -> Result<()>
pub fn validate_for_platform(&self, platform: Platform) -> Result<()>
Validates the declaration against what the target platform can enforce.
Runs at plan time so an unenforceable limit or an unsupported egress mode fails before anything is provisioned, rather than at the first exec.
Sourcepub fn azure_image(&self) -> Result<AzureSandboxImage<'_>>
pub fn azure_image(&self) -> Result<AzureSandboxImage<'_>>
What Azure creates this sandbox from: a catalog name or a registry image, told apart by
classify_azure_sandbox_image. Refused while planning, because a value the data plane
rejects would otherwise surface at the first sandbox, long after the apply.
Sourcepub fn azure_sandbox_limits(&self) -> Result<()>
pub fn azure_sandbox_limits(&self) -> Result<()>
Checks the declared ceilings against Azure’s sizing rule (the AZURE_* constants above).
Refused at plan time, like Self::microvm_tier, so a bad value is a declaration to fix
rather than a runtime fault at create.
Sourcepub fn microvm_tier(&self) -> Result<MicrovmTier>
pub fn microvm_tier(&self) -> Result<MicrovmTier>
The MicroVM size that keeps every declared ceiling, or why none does.
AWS sizes are discrete and a running MicroVM bursts to four times its baseline, so the only tier that honours a ceiling is one whose peak fits inside it. A declaration no tier satisfies is refused: shipping the nearest size would give the customer a sandbox that exceeds the bound they wrote down.
Trait Implementations§
Source§impl<'de> Deserialize<'de> for Sandbox
impl<'de> Deserialize<'de> for Sandbox
Source§fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
impl Eq for Sandbox
Source§impl ResourceDefinition for Sandbox
impl ResourceDefinition for Sandbox
Source§fn get_resource_type(&self) -> ResourceType
fn get_resource_type(&self) -> ResourceType
Source§fn get_dependencies(&self) -> Vec<ResourceRef>
fn get_dependencies(&self) -> Vec<ResourceRef>
Source§fn validate_update(&self, new_config: &dyn ResourceDefinition) -> Result<()>
fn validate_update(&self, new_config: &dyn ResourceDefinition) -> Result<()>
Source§fn as_any_mut(&mut self) -> &mut dyn Any
fn as_any_mut(&mut self) -> &mut dyn Any
Source§fn box_clone(&self) -> Box<dyn ResourceDefinition>
fn box_clone(&self) -> Box<dyn ResourceDefinition>
Source§fn resource_eq(&self, other: &dyn ResourceDefinition) -> bool
fn resource_eq(&self, other: &dyn ResourceDefinition) -> bool
Source§fn to_json_value(&self) -> Result<Value>
fn to_json_value(&self) -> Result<Value>
impl StructuralPartialEq for Sandbox
Auto Trait Implementations§
impl Freeze for Sandbox
impl RefUnwindSafe for Sandbox
impl Send for Sandbox
impl Sync for Sandbox
impl Unpin for Sandbox
impl UnsafeUnpin for Sandbox
impl UnwindSafe for Sandbox
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> DeserializeOwned for Twhere
T: for<'de> Deserialize<'de>,
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§fn equivalent(&self, key: &K) -> bool
fn equivalent(&self, key: &K) -> bool
key and return true if they are equal.