Skip to main content

Crate alien_core

Crate alien_core 

Source

Re-exports§

pub use permissions::*;
pub use runtime_environment::*;
pub use events::*;
pub use app_events::*;
pub use bindings::*;
pub use presigned::*;
pub use commands_types::*;
pub use import::*;

Modules§

access_request_crd
White-labeled naming for the access-request custom resource.
ai_catalog
Curated, per-cloud model catalog for the AI gateway.
app_events
Application Events
bindings
Type-safe binding parameter definitions
commands_types
compute_planner
Deployment-time compute planner.
crontab_to_eventbridge
debug_session
Wire shapes for alien debug sessions.
embedded_config
Embedded configuration support for alien-deploy-cli and alien-operator binaries.
events
Alien Events System
file_utils
image_rewrite
Image URI utilities for the registry proxy.
import
Typed setup import contract.
instance_catalog
Instance type catalog and selection algorithm for cloud compute infrastructure.
permissions
Core permission types.
presigned
remote_bindings
runtime_environment
sandbox_build_role
The IAM role an AWS sandbox image build runs as, as concrete policy documents.
sandbox_capability
Sandbox capabilities: what the manager mints and the agent verifies.
sandbox_egress
What an AWS sandbox with egress: deny needs in the customer account, as concrete documents: the operator role Lambda assumes to place the connector’s network interfaces, and the AWS::Lambda::NetworkConnector those interfaces belong to.
sandbox_image
What a sandbox image must carry for the agent to serve, and the Dockerfile text carrying it.
sandbox_setup_inputs
The facts an AWS sandbox’s setup renders its scaffolding from. Setup applies them and the runtime never re-reads them, so a change to any of them needs setup to run again.
sync
Sync protocol types for agent ↔ manager communication.
vault_naming
How each vault backend names a secret in the cloud’s own secret store.

Structs§

AgentStatus
Status of a single agent in the dev server
Ai
Represents an AI Gateway resource that provides a unified interface to managed AI inference services across cloud providers.
AiAvailabilityObservation
AiBuilder
Use builder syntax to set the inputs and finish with build().
AiHeartbeatStatus
AiModelAvailabilityObservation
AiOutputs
Outputs generated by a successfully provisioned AI Gateway resource.
ArtifactRegistry
Represents an artifact registry for storing container images and other build artifacts. This is a high-level wrapper resource that provides a cloud-agnostic interface over AWS ECR, GCP Artifact Registry, and Azure Container Registry.
ArtifactRegistryBuilder
Use builder syntax to set the inputs and finish with build().
ArtifactRegistryHeartbeatStatus
ArtifactRegistryOutputs
Outputs generated by a successfully provisioned ArtifactRegistry.
AuroraPostgresHeartbeatData
AwsBedrockAiHeartbeatData
AwsClientConfig
AWS client configuration
AwsCodeBuildHeartbeatData
AwsComputeClusterHeartbeatData
AwsCustomCertificateConfig
AwsDaemonHeartbeatData
AwsDynamoDbKeySchemaElement
AwsDynamoDbKvHeartbeatData
AwsEcrArtifactRegistryHeartbeatData
AwsEcrRepositoryHeartbeatData
AwsEnvironmentInfo
AWS-specific environment information
AwsIamRoleServiceAccountHeartbeatData
AwsImpersonationConfig
Configuration for AWS role impersonation
AwsKmsKeyHeartbeatData
AwsLambdaWorkerHeartbeatData
AwsManagementConfig
AWS management configuration extracted from stack settings
AwsMicrovmSandboxHeartbeatData
AWS: the image a sandbox runs from, and the lifecycle state AWS reports for it.
AwsOpenSearch
An Amazon OpenSearch Serverless collection (next generation).
AwsOpenSearchBuilder
Use builder syntax to set the inputs and finish with build().
AwsOpenSearchCapacity
Indexing and search capacity limits for an OpenSearch collection group.
AwsOpenSearchCapacityRange
Minimum and maximum OCU bounds for one OpenSearch compute component.
AwsOpenSearchOutputs
Outputs generated by a successfully provisioned AwsOpenSearch collection.
AwsParameterStoreVaultHeartbeatData
AwsRemoteStackManagementHeartbeatData
AwsS3StorageHeartbeatData
AwsSandboxEgressScaffolding
The objects that keep an AWS deny sandbox’s sessions inside the VPC. Each id is recorded as soon as the object exists and cleared once it is deleted.
AwsServiceOverrides
Service endpoint overrides for testing AWS services
AwsSqsQueueHeartbeatData
AwsVpcNetworkHeartbeatData
AwsWebIdentityConfig
Configuration for AWS Web Identity Token authentication
AzureBlobStorageHeartbeatData
AzureClientConfig
Azure client configuration
AzureComputeClusterHeartbeatData
AzureContainerAppsBuildHeartbeatData
AzureContainerAppsEnvironment
Represents an Azure Container Apps Environment for hosting container applications.
AzureContainerAppsEnvironmentBuilder
Use builder syntax to set the inputs and finish with build().
AzureContainerAppsEnvironmentHeartbeatData
AzureContainerAppsEnvironmentHeartbeatStatus
AzureContainerAppsEnvironmentOutputs
Outputs generated by a successfully provisioned Azure Container Apps Environment.
AzureContainerAppsEnvironmentWorkloadProfile
AzureContainerAppsWorkerHeartbeatData
AzureContainerRegistryHeartbeatData
AzureCustomCertificateConfig
AzureDaemonHeartbeatData
AzureEnvironmentInfo
Azure-specific environment information
AzureFlexibleServerPostgresHeartbeatData
AzureFoundryAiHeartbeatData
AzureImpersonationConfig
Configuration for Azure managed identity impersonation
AzureKeyVaultHeartbeatData
AzureKeyVaultKeyHeartbeatData
AzureManagedIdentityServiceAccountHeartbeatData
AzureManagementConfig
Azure management configuration extracted from stack settings
AzureRemoteStackManagementHeartbeatData
AzureResourceGroup
Represents an Azure Resource Group that acts as a logical container for Azure resources.
AzureResourceGroupBuilder
Use builder syntax to set the inputs and finish with build().
AzureResourceGroupHeartbeatData
AzureResourceGroupHeartbeatStatus
AzureResourceGroupOutputs
Outputs generated by a successfully provisioned Azure Resource Group.
AzureResourceProviderActivationHeartbeatData
AzureSandboxGroupHeartbeatData
Azure: the sandbox group’s ARM state. The data plane has no list operation, so a sandbox count is not available here.
AzureServiceBusNamespace
Represents an Azure Service Bus Namespace for hosting queues and topics.
AzureServiceBusNamespaceBuilder
Use builder syntax to set the inputs and finish with build().
AzureServiceBusNamespaceHeartbeatData
AzureServiceBusNamespaceOutputs
Outputs generated by a successfully provisioned Azure Service Bus Namespace.
AzureServiceBusQueueHeartbeatData
AzureServiceOverrides
Service endpoint overrides for testing Azure services
AzureStorageAccount
Represents an Azure Storage Account for blob, file, table, and queue storage.
AzureStorageAccountBuilder
Use builder syntax to set the inputs and finish with build().
AzureStorageAccountEndpoints
AzureStorageAccountHeartbeatData
AzureStorageAccountOutputs
Outputs generated by a successfully provisioned Azure Storage Account.
AzureTableKvHeartbeatData
AzureVnetNetworkHeartbeatData
Build
Represents a build resource that executes bash scripts to build code. Builds are designed to be stateless and can be triggered on-demand to compile, test, or package application code.
BuildBuilder
Use builder syntax to set the inputs and finish with build().
BuildConfig
Configuration for starting a build.
BuildExecution
Information about a build execution.
BuildHeartbeatStatus
BuildOutputs
Outputs generated by a successfully provisioned Build.
CapacityGroup
Capacity group definition.
CapacityGroupStatus
Status of a single capacity group within a ComputeCluster.
ComputeCapacityBlocker
ComputeCapacityGroupStatus
ComputeCapacityRecommendation
ComputeChoiceRange
Allowed range and default for a count selected by the installer.
ComputeCluster
ComputeCluster resource for running long-running container workloads.
ComputeClusterBuilder
Use builder syntax to set the inputs and finish with build().
ComputeClusterHeartbeatStatus
ComputeClusterOutputs
Outputs generated by a successfully provisioned ComputeCluster.
ComputeDrainBlocker
ComputeDrainProgress
ComputeSettings
Deployment-time compute choices for Alien-managed compute pools.
Container
Container resource for running long-running container workloads.
ContainerAutoscaling
Autoscaling configuration for stateless containers.
ContainerBuilder
Use builder syntax to set the inputs and finish with build().
ContainerGpuSpec
GPU specification for a container.
ContainerImageIdentity
Image a running container reports.
ContainerOutputs
Outputs generated by a successfully provisioned Container.
ContainerPort
Container port configuration.
ContainerSecurity
Container process identity and filesystem security.
ContainerTunnel
A container port reachable from the control plane through the manager.
CustomCertificateConfig
Platform-specific certificate references for custom domains.
CustomDomainConfig
Custom domain configuration for a single resource.
Daemon
DaemonBuilder
Use builder syntax to set the inputs and finish with build().
DaemonOutputs
DaemonRuntime
DaemonRuntimeMount
DeployerSecretEnv
An environment variable a workload reads from a vault-native deployer secret when it starts.
DeployerSecretLocation
Where a deployer writes a vault-native secret.
DeployerSecretLocationContext
What a location needs beyond the vault binding.
DeployerSecretReport
The state of one deployer secret slot, reported with the deployment.
DeployerSecretSlot
A deployer secret input whose value lives in the customer’s secret store.
DeploymentConfig
Deployment configuration
DeploymentConfigBuilder
Use builder syntax to set the inputs and finish with build().
DeploymentState
Deployment state
DeploymentStateBuilder
Use builder syntax to set the inputs and finish with build().
DeploymentStepResult
Result of a deployment step
DevResourceInfo
Information about a deployed resource
DevStatus
Overall status of the dev server
DomainMetadata
Domain metadata for auto-managed public resources (no private keys).
DomainSettings
Domain configuration for the stack.
EcrImageRepository
The ECR repository a private image reference is pulled from.
Email
Email infrastructure for sending and receiving mail on customer-owned domains. On AWS this is backed by SES: a shared configuration set, optional inbound/event wiring, and one email identity (Easy DKIM) per seed domain.
EmailBuilder
Use builder syntax to set the inputs and finish with build().
EmailDkimToken
A single DKIM CNAME record the operator must create in DNS.
EmailDomainOutputs
Per-domain DNS records the operator must create.
EmailEvents
Event configuration for an Email resource.
EmailInbound
Inbound-mail configuration for an Email resource.
EmailOutputs
Outputs generated by a successfully provisioned Email resource.
EnvironmentVariable
Environment variable for deployment
EnvironmentVariablesSnapshot
Snapshot of environment variables at a point in time
ExternalAiHeartbeatData
ExternalBindings
Map from resource ID to external binding.
FailureDomainSelection
Failure-domain policy selected for a compute pool.
GcpAgentPlatformEngine
A Gemini Agent Platform reasoning engine: the durable parent that sandbox environment templates and sandboxes hang under. One per sandbox, provisioned once and addressed by the server-assigned id its controller records.
GcpAgentPlatformEngineBuilder
Use builder syntax to set the inputs and finish with build().
GcpAgentPlatformSandboxHeartbeatData
GCP: the Agent Platform template sandboxes are cut from, and the engine it hangs under.
GcpArtifactRegistryHeartbeatData
GcpClientConfig
GCP client configuration
GcpCloudBuildHeartbeatData
GcpCloudKmsKeyHeartbeatData
GcpCloudRunWorkerHeartbeatData
GcpCloudSqlPostgresHeartbeatData
GcpCloudStorageHeartbeatData
GcpComputeClusterHeartbeatData
GcpCustomCertificateConfig
GcpDaemonHeartbeatData
GcpEnvironmentInfo
GCP-specific environment information
GcpFirestoreKvHeartbeatData
GcpImpersonationConfig
Configuration for GCP service account impersonation
GcpManagementConfig
GCP management configuration extracted from stack settings
GcpPubSubQueueHeartbeatData
GcpRemoteStackManagementHeartbeatData
GcpSecretManagerVaultHeartbeatData
GcpServiceAccountHeartbeatData
GcpServiceOverrides
Service endpoint overrides for testing GCP services
GcpServiceUsageActivationHeartbeatData
GcpVertexAiHeartbeatData
GcpVpcNetworkHeartbeatData
GpuSpec
GPU specification for a capacity group.
HealthCheck
HTTP health check configuration.
HeartbeatCollectionIssue
HorizonAwsMachineImages
AWS Horizon machine image catalog.
HorizonAzureMachineImage
Azure Horizon machine image entry.
HorizonAzureMachineImages
Azure Horizon machine image catalog.
HorizonClusterConfig
Configuration for a single container worker cluster.
HorizonConfig
Horizon control-plane configuration for container orchestration.
HorizonContainerHeartbeatData
HorizonGcpMachineImage
GCP Horizon machine image entry.
HorizonGcpMachineImages
GCP Horizon machine image catalog.
HorizonMachineBaseImage
Base image metadata for the Horizon machine image.
HorizonMachineImage
Horizon machine image catalog.
HorizondArtifact
Download artifact for one horizond release platform.
IdConfig
Configuration for ID generation
Key
A customer-managed encryption key.
KeyBuilder
Use builder syntax to set the inputs and finish with build().
KeyHeartbeatStatus
KeyOutputs
Outputs generated by a successfully provisioned Key.
KubernetesBuildHeartbeatData
KubernetesCloudReference
Optional provider-specific identity for a cloud-backed Kubernetes cluster.
KubernetesCluster
Runtime substrate for Kubernetes deployments.
KubernetesClusterBuilder
Use builder syntax to set the inputs and finish with build().
KubernetesClusterHeartbeatData
KubernetesClusterNodeStatus
KubernetesClusterOutputs
Outputs produced once the Kubernetes substrate is ready for workloads.
KubernetesClusterSettings
Kubernetes cluster setup settings.
KubernetesContainerHeartbeatData
KubernetesCustomCertificateConfig
KubernetesDaemonHeartbeatData
KubernetesEventInvolvedObject
KubernetesEventSnapshot
KubernetesEventSource
KubernetesGatewayRouteProfile
Shared Gateway API route profile values.
KubernetesHttpProbe
HTTP probe used by Kubernetes for workload liveness or readiness.
KubernetesIngressRouteProfile
Shared Ingress route profile values.
KubernetesNodeConditionStatus
KubernetesNodeResources
KubernetesNodeUsage
KubernetesOwnerReference
KubernetesPodRuntimeUnitStatus
KubernetesSandboxHeartbeatData
Kubernetes: pods carrying the sandbox label, in the deployment’s namespace.
KubernetesSecretMount
Mounts an existing, setup-owned Kubernetes Secret into a Container pod. The Secret must exist in the deployment namespace before the workload starts.
KubernetesSecretVaultHeartbeatData
KubernetesSettings
Kubernetes runtime substrate configuration.
KubernetesTlsSecretRef
Namespace-scoped Kubernetes TLS Secret reference.
KubernetesWorkerHeartbeatData
KubernetesWorkloadCondition
KubernetesWorkloadStatus
Kv
Represents a key-value storage resource that provides a minimal, platform-agnostic API compatible across DynamoDB, Firestore, Redis, and Azure Table Storage.
KvBuilder
Use builder syntax to set the inputs and finish with build().
KvHeartbeatStatus
KvOutputs
Outputs generated by a successfully provisioned KV store.
LifecycleRule
Defines a rule for managing the lifecycle of objects within a storage bucket.
LoadBalancerEndpoint
Load balancer endpoint information for DNS management. This is optional metadata used by the DNS controller to create domain mappings.
LocalArtifactRegistryHeartbeatData
LocalComputeClusterHeartbeatData
LocalContainerHeartbeatData
LocalDaemonHeartbeatData
LocalEnvironmentInfo
Local platform environment information
LocalKvHeartbeatData
LocalPostgresHeartbeatData
LocalQueueHeartbeatData
LocalRuntimeEventSnapshot
LocalRuntimeEventSubject
LocalRuntimeUnitStatus
LocalSandboxHeartbeatData
Local: containers Docker still holds for this sandbox.
LocalServiceAccountHeartbeatData
LocalStorageHeartbeatData
LocalVaultHeartbeatData
LocalWorkerHeartbeatData
MachineProfile
Machine resource profile for a capacity group.
MachinesComputeClusterHeartbeatData
MachinesComputeMachineStatus
MachinesDaemonHeartbeatData
ManagedDomainInfo
Certificate and DNS metadata for a managed hostname.
ManagedRuntimeEventInvolvedObject
ManagedRuntimeEventSnapshot
ManagedRuntimeEventSource
ManagedRuntimeUnitStatus
MetricSample
MicrovmTier
One of the five sizes a Lambda MicroVM can be built at.
MonitoringConfig
Configuration for monitoring and observability.
NamedResourceDetail
Network
Represents cloud-agnostic networking infrastructure (VPC, VNet, subnets, etc.).
NetworkBuilder
Use builder syntax to set the inputs and finish with build().
NetworkHeartbeatStatus
NetworkOutputs
Outputs generated by a successfully provisioned Network.
ObservedCounts
ObservedInventoryBatch
ObservedResourceSample
OtlpConfig
OTLP log export configuration for a deployment.
PersistentStorage
Persistent storage configuration for stateful containers.
Postgres
A managed PostgreSQL database. The target platform decides the backend (AWS Aurora Serverless v2, GCP Cloud SQL, Azure Flexible Server, or an embedded native process on Local); the database is never publicly reachable.
PostgresBuilder
Use builder syntax to set the inputs and finish with build().
PostgresHeartbeatStatus
PostgresOutputs
Outputs generated by a successfully provisioned Postgres database.
ProviderFleetStatus
PublicEndpoint
Public endpoint configuration for port-backed workload resources.
PublicEndpointOutput
Runtime-resolved public endpoint metadata.
Queue
Represents a message queue resource with minimal, portable semantics. Queue integrates with platform-native services (AWS SQS, GCP Pub/Sub, Azure Service Bus).
QueueBuilder
Use builder syntax to set the inputs and finish with build().
QueueHeartbeatStatus
QueueOutputs
Outputs generated by a successfully provisioned Queue.
RawHeartbeatSnippet
ReadinessProbe
Configuration for HTTP-based readiness probe. This probe is executed after worker provisioning/update to verify the worker is ready to serve traffic. Only works with workers that have Public ingress.
RegistryAccess
The cross-account read a manager opened on Alien’s registry for one deployment.
ReleaseInfo
Release metadata
RemoteBindingGrant
RemoteBindings
Setup-owned identity used to issue short-lived application credentials for explicitly published resources.
RemoteBindingsBuilder
Use builder syntax to set the inputs and finish with build().
RemoteBindingsOutputs
RemoteStackManagement
Represents cross-account management access configuration for a stack deployed on AWS, GCP, or Azure platforms. This resource sets up the necessary IAM/RBAC configuration to allow another cloud account to manage the stack.
RemoteStackManagementBuilder
Use builder syntax to set the inputs and finish with build().
RemoteStackManagementHeartbeatStatus
RemoteStackManagementOutputs
Resource outputs for RemoteStackManagement. Different platforms will provide different outputs based on their implementation.
ReplicaStatus
Status of a single container replica.
Resource
ResourceDomainInfo
Certificate and DNS metadata for a public resource.
ResourceEntry
ResourceHeartbeat
ResourceOutputs
New Resource outputs wrapper that can hold any ResourceOutputsDefinition. This replaces the old ResourceOutputs enum to enable runtime extensibility.
ResourceOwnershipPolicy
ResourceRef
Reference to a resource by its stable id and resource type.
ResourceSpec
Resource specification with min/desired values.
ResourceType
Type alias for resource type identifiers
RuntimeMetadata
Runtime metadata for deployment
Sandbox
An isolated environment for running untrusted code, created at runtime.
SandboxBuilder
Use builder syntax to set the inputs and finish with build().
SandboxCapabilities
What a platform’s sandbox backend can actually do.
SandboxHeartbeatStatus
SandboxLifecyclePolicy
How long a sandbox may live and when it is paused.
SandboxLimits
Hard ceilings enforced on a sandbox.
SandboxOutputs
Outputs generated by a successfully provisioned Sandbox parent.
SandboxPrivilegedSupervisor
Opt-in supervisor-owned network enforcement. Caller requests cannot change this identity.
ServiceAccount
Represents a non-human identity that can be assumed by compute services such as Lambda, Cloud Run, ECS, Container Apps, etc.
ServiceAccountBuilder
Use builder syntax to set the inputs and finish with build().
ServiceAccountHeartbeatStatus
ServiceAccountOutputs
Outputs generated by a successfully provisioned ServiceAccount.
ServiceActivation
Represents a service activation that can be enabled on cloud platforms. For GCP: enables project services (e.g., iam.googleapis.com, compute.googleapis.com). For Azure: registers resource providers (e.g., Microsoft.DocumentDB, Microsoft.Storage).
ServiceActivationBuilder
Use builder syntax to set the inputs and finish with build().
ServiceActivationHeartbeatStatus
ServiceActivationOutputs
Outputs generated by a successfully activated service.
SetupUpdateAuthorization
One-shot authority for a setup re-import to replace setup-owned resources.
Stack
A bag of resources, unaware of any cloud.
StackBuilder
Use builder syntax to set the inputs and finish with build().
StackInputDefinition
Stack input definition serialized into a release stack.
StackInputEnvironmentMapping
How a resolved stack input is injected into runtime environment variables.
StackInputGenerate
Asks Alien to generate a secret input’s value.
StackInputValidation
Portable stack input validation constraints.
StackResourceState
Represents the state of a single resource within the stack for a specific platform.
StackResourceStateBuilder
Use builder syntax to set the inputs and finish with build().
StackSettings
User-customizable deployment settings specified at deploy time.
StackState
Represents the collective state of all resources in a stack, including platform and pending actions.
Storage
Represents an object storage bucket.
StorageBuilder
Use builder syntax to set the inputs and finish with build().
StorageHeartbeatStatus
StorageOutputs
Outputs generated by a successfully provisioned Storage bucket.
TestEnvironmentInfo
Test platform environment information (mock)
TypeGateability
Per-lifecycle gateability of one resource type, derived from the ownership table and the gate refusals. Serialized into the generated manifest the TypeScript SDK’s surface test consumes.
Vault
Represents a secure vault for storing secrets. This resource provides a platform-agnostic interface over cloud-native secret management services:
VaultBuilder
Use builder syntax to set the inputs and finish with build().
VaultHeartbeatStatus
VaultOutputs
Outputs generated by a successfully provisioned Vault.
VolumeBackups
Scheduled snapshots of a persistent volume.
VolumeBackupsStatus
Whether a container’s snapshot schedule is in place.
VolumeOutput
A replica’s persistent volume and its latest completed snapshot.
VolumeRestoreOutput
A completed volume restore.
VolumeRestoreRequest
Replace one replica’s persistent volume with a new volume made from a snapshot.
Worker
Represents a serverless worker that executes code in response to triggers or direct invocations. Workers are the primary compute resource in serverless applications, designed to be stateless and ephemeral.
WorkerBuilder
Use builder syntax to set the inputs and finish with build().
WorkerOutputs
Outputs generated by a successfully provisioned Worker.
WorkerPublicEndpoint
Public endpoint configuration for Worker resources.
WorkloadHeartbeatStatus
WorkloadReplicaStatus

Enums§

AiAccessTest
AiAvailabilityBlocker
AiAvailabilitySource
Provider control plane used to observe model availability without invoking a model, spending customer quota, or accepting provider terms.
AiHeartbeatData
AiModelAvailability
ApplicationLogLevel
A recognized application-provided log level.
ArtifactRegistryHeartbeatData
AwsCredentials
Supported AWS authentication methods
AwsOpenSearchCollectionType
Workload type for an OpenSearch Serverless collection.
AzureCredentials
Represents Azure authentication credentials
AzureSandboxImage
What an Azure sandbox starts from.
BinaryTarget
Target OS and architecture for compiled binaries.
BuildHeartbeatData
BuildHost
Operating system and architecture of the machine running a build.
BuildStatus
Status of a build execution.
BundleUri
A bundle URI split around its region token, or carried whole when it has none.
CapacityGroupScalePolicy
Source-declared scale policy for a capacity group.
CargoBuildStrategy
Build strategy for cross-compilation.
CertificateStatus
Certificate status in the certificate lifecycle
ClientConfig
Configuration for different cloud platform clients
ComputeBackend
Compute backend for Container and Worker resources.
ComputeCapacityBlockerCategory
ComputeClusterHeartbeatData
ComputeDrainProgressStatus
ComputeKind
A compute resource kind that receives injected environment variables.
ComputePoolSelection
User-selected deployment settings for one compute pool.
ComputeType
Compute type for build resources.
ContainerCode
Specifies the source of the container’s executable code.
ContainerHeartbeatData
ContainerSecurityProfile
Security profile shared by container runtimes.
ContainerStatus
Container status in the managed container backend.
DaemonCode
DaemonHeartbeatData
DeployerSecretStatus
Whether a deployer secret slot holds a usable value. Alien learns this from metadata only and never reads the value.
DeployerSecretStore
The secret store a deployer writes a vault-native secret into.
DeploymentModel
Deployment model: how updates are delivered to the remote environment.
DeploymentStatus
Deployment status in the deployment lifecycle.
DevStatusState
Overall dev server status
DnsRecordStatus
DNS record status in the DNS lifecycle
EcrImageRegion
Where a private ECR image’s region comes from.
EndpointAccess
Reachability of the deployment’s public endpoints, fixed at setup.
EnvironmentInfo
Platform-specific environment information
EnvironmentVariableType
Type of environment variable
ErrorData
Core error data exposed by the alien-core crate.
ExposeProtocol
Protocol for public workload endpoints.
ExternalBinding
Represents a binding to pre-existing infrastructure.
GateInputIssue
Why a gate input failed render-time validation; the caller owns the backend-specific error message.
GateRefusal
Why a resource cannot carry an .enabled() gate.
GcpCredentials
Authentication options for talking to GCP APIs.
HeartbeatBackend
HeartbeatCollectionIssueReason
HeartbeatIssueSeverity
HeartbeatsMode
How heartbeat health checks are handled.
HorizonMachineArchitecture
Horizon machine image architecture.
HorizonWorkloadSchedulingMode
HttpMethod
HTTP method for readiness probe requests.
IdType
Defines different ID types with their configuration
ImpersonationConfig
Cloud-agnostic impersonation configuration
InitialSetupAuthority
Actor that owns structural work during the initial setup phase.
KeyFingerprint
Stable identity of a provider key family.
KeyHeartbeatData
KubernetesCertificateMode
Certificate publication or reference mode for Kubernetes public endpoints.
KubernetesClientConfig
Configuration mode for Kubernetes access
KubernetesClusterOwnership
Ownership model for the Kubernetes cluster.
KubernetesClusterProvider
Kubernetes provider backing the runtime substrate.
KubernetesExposureSettings
Kubernetes public HTTPS exposure mode.
KubernetesHeartbeatMode
How Alien should heartbeat this Kubernetes substrate.
KubernetesRouteProfile
Kubernetes route API selected for public endpoints.
KubernetesRouteProviderOptions
Provider-specific route options required by supported managed profiles.
KubernetesWorkloadKind
KvHeartbeatData
LocalRuntimeUnitKind
ManagementConfig
Management configuration for different cloud platforms.
MetricUnit
NetworkHeartbeatData
NetworkSettings
Network configuration for the stack.
ObservedHealth
Platform
Represents the target cloud platform.
PostgresBackend
Cloud backend for a Postgres resource. Only Aurora Serverless v2 ships in v1; the enum reserves the slot so provisioned RDS is an additive variant later.
PostgresHeartbeatData
ProviderLifecycleState
PublicEndpointTargetSettings
DNS target mode for public endpoints.
QueueHeartbeatData
RawHeartbeatSnippetFormat
RemoteStackManagementHeartbeatData
ResourceHeartbeatData
ResourceLifecycle
Describes the lifecycle of a resource within a stack, determining how it’s managed and deployed.
ResourceStatus
Represents the high-level status of a resource during its lifecycle.
SandboxCapability
Names a single sandbox capability, so an unsupported call can report which one it needed.
SandboxCode
Specifies where the sandbox’s root filesystem comes from.
SandboxEgress
Outbound network policy for a sandbox.
SandboxHeartbeatData
Content-free telemetry about what a sandbox resource is running.
SecretDelivery
The mechanism by which Secret-typed env vars are delivered to a workload.
ServiceAccountHeartbeatData
ServiceActivationHeartbeatData
SetupEmission
When a resource type contributes anything to the setup artifact.
SetupScaffolding
Cloud objects a direct setup created so a runtime-owned resource can run.
SourceBinaryType
Types of source binaries used for package building
StackInputDefaultValue
Stack input default value.
StackInputEnvironmentVariableType
Environment variable handling for a stack input mapping.
StackInputKind
Primitive stack input kind.
StackInputProvider
Who can provide a stack input value.
StackRef
Reference to a stack for management permissions
StackStatus
Represents the overall status of a stack based on its resource states.
StorageHeartbeatData
TelemetryMode
How telemetry (logs, metrics, traces) is handled.
ToolchainConfig
Configuration for different programming language toolchains. Each toolchain provides type-safe build configuration and auto-detection capabilities.
UpdatesMode
How updates are delivered to the deployment.
VaultHeartbeatData
VolumeBackupsState
State of a container’s snapshot schedule.
WorkerCode
Specifies the source of the worker’s executable code. This can be a pre-built container image or source code that the system will build.
WorkerHeartbeatData
WorkerTrigger
Defines what triggers a worker execution.

Constants§

ALIEN_MANAGED_BY_TAG_KEY
ALIEN_MANAGED_BY_TAG_VALUE
ALIEN_RESOURCE_TAG_KEY
ALIEN_STACK_TAG_KEY
ALIEN_SYSTEM_RESOURCE_ATTRIBUTE
Resource-attribute key marking OTLP telemetry as Alien system-component output (infrastructure daemons and internal runtimes) rather than user workload. Log consumers — the CLI log viewer and the dashboard — hide telemetry carrying this attribute by default. The value is the string "true".
ALPHABET_LOWERCASE
ALPHABET_MIXED_CASE
APEX_HOST_LABEL
Host label that places a generated public endpoint at the deployment base hostname.
AZURE_DISK_IMAGE_LABEL
Label key the controller writes on every disk image it builds, and the provider finds it by.
BUNDLE_REGION_TOKEN
The one token a sandbox bundle URI may carry, replaced with the deploying region.
CURRENT_DEPLOYMENT_PROTOCOL_VERSION
Deployment protocol version this binary writes. Bump when making incompatible changes to DeploymentState semantics.
DEFAULT_ALIEN_LABEL_DOMAIN
DEPLOYER_SECRET_KEY_PREFIX
Prefix of every vault key that holds a deployer secret, so these keys never collide with the env-var-named keys Alien syncs itself.
DEPLOYER_SECRET_VALUE_PLACEHOLDER
Placeholder for the secret value in the CLI commands Alien shows.
DEPLOYMENT_PROTOCOL_VERSION
Backwards-compatible alias for older call sites.
ENV_ALIEN_DEPLOYER_SECRETS
Env var that carries a natively projected workload’s DeployerSecretEnv list to its hosting controller, which resolves each entry before the process starts (a secretKeyRef on Kubernetes, a vault read on the local platform). It holds names only, never values.
MANIFEST_TYPES
The built-in user resource types listed in the generated manifest. The SDK builder surface is asserted against exactly this set.
MAX_WORKER_TIMEOUT_SECONDS
Longest Worker execution supported by every Commands delivery path.
MIN_SUPPORTED_DEPLOYMENT_PROTOCOL_VERSION
Oldest deployment protocol version this binary can read.
POSTGRES_DATABASE_NAME
The fixed inner database (and admin user) name for cloud Postgres backends. AWS rejects hyphens in DatabaseName, and the cluster/instance/server name already carries the resource id, so the inner database is a fixed label rather than the id. Every cloud emitter and controller derives its database name from this single constant so a frozen import always binds to a database that exists. (Local names its database after the resource id and does not use this.)
RESOURCE_PREFIX_ERROR_MESSAGE
SECRETS_VAULT_ID
Reserved id of the deployment secrets vault.
STACK_INPUT_GENERATE_MAX_LENGTH
Longest value Alien generates for a secret input.
STACK_INPUT_GENERATE_MIN_LENGTH
Shortest value Alien generates for a secret input.
VERSION
VOLUME_BACKUP_INTERVAL_HOURS
Hours between snapshots that every cloud’s native snapshot scheduler supports.
VOLUME_BACKUP_MAX_RETENTION_DAYS
Longest a snapshot may be kept. Azure Disk Backup keeps operational snapshots for at most a year; the same limit applies everywhere for portability.
VOLUME_BACKUP_MAX_SNAPSHOTS
Most snapshots a volume may hold at once. Azure Disk Backup keeps at most 450 scheduled snapshots per disk; the same limit applies everywhere so a stack is portable across clouds.

Traits§

ResourceDefinition
Trait that defines the interface for all resource types in the Alien system. This trait enables extensibility by allowing new resource types to be registered and managed alongside built-in resources.
ResourceLinks
A resource definition that owns resource links.
ResourceOutputsDefinition
Trait that defines the interface for all resource output types in the Alien system. This trait enables extensibility by allowing new resource output types to be registered and managed alongside built-in resource outputs.

Functions§

azure_disk_image_label
The label value naming the disk image built from reference: a digest, since a label value may not carry a reference’s /, : and @.
branded_standard_resource_tags
branded_tag_key
classify_azure_sandbox_image
Classifies a declared code.image for Azure, or None when it is neither kind. A bare [A-Za-z0-9._-]+ is checked first and always a catalog name; anything else must carry /, : or @ and parse as an OCI reference.
declined_live_resources
The ids of the gated live resources whose input resolves false.
default_branded_standard_resource_tags
deployer_secret_environment
The environment variables workloads read from vault-native deployer secrets, each with the resources its mapping targets (None = all).
deployer_secret_location
Where the deployer writes the value for vault_key of the secrets vault described by binding.
deployer_secret_slots
The vault-native deployer secret slots of a deployment on platform.
deployer_secret_value_refusal
Why a setup path refuses a value for the deployer secret name (its label or id), with what to do instead.
deployer_secret_vault_key
The secrets vault key for a deployer secret input: input- plus the input id in lowercase kebab case (databasePassword → input-database-password).
find_boolean_gate_input
Finds the boolean deployer input a gate references, for render-time re-validation. The compile-time preflight enforces the same two rules; generators repeat them so a caller that renders without preflights cannot ship a template whose gate variable is undeclared or non-boolean.
frozen_gate_of
The gate input of a setup-created gated resource, None for anything else.
frozen_gated
Every gated resource setup creates, as (resource_id, input_id).
gate_refusal
Whether a resource may carry an .enabled() gate at all. None means gateable. Lifecycle legality is not decided here — a lifecycle the type does not allow is refused by the lifecycle rules regardless of gating.
gate_resolves_true
The deployer’s answer for a live gate: the provided value, else the input’s declared boolean default. The error is the reason, for the caller to wrap.
gate_value_as_bool
A gate value from the wire: JSON booleans stay booleans, and the CloudFormation parameter strings “true”/“false” coerce — CloudFormation has no boolean parameter type, so its registration payloads deliver gate answers as strings. Anything else is None, refused loudly by callers.
generate_id_example
Generate a deterministic ID example for a given type
id_error_message
Generate an error message for invalid IDs
id_regex_pattern
Generate a regex pattern for validating IDs of a specific type
is_deployer_secret_input
Whether the deployer may provide this secret input.
is_valid_resource_prefix
kubernetes_build_service_account_name
Canonical Kubernetes ServiceAccount for build jobs.
kubernetes_compute_architecture
Architecture shared by source images built for this Kubernetes stack. Unspecified pools and Workers inherit this build constraint, so their Pods cannot land on incompatible nodes in a cluster with mixed architectures.
kubernetes_compute_node_selector
Match Pod placement to the architecture used by the stack’s source images. This does not associate Workers with a compute pool or reserve node capacity.
kubernetes_container_pool
Resolve placement, inferring a single declared cluster and its general or sole pool. Legacy stacks without a declaration keep default scheduling.
kubernetes_daemon_pool
Resolve a daemon’s pool without changing its per-node DaemonSet behavior.
kubernetes_dynamic_pool
Resolve the one pool admitted for release-independent containers.
kubernetes_manager_service_account_name
Canonical Kubernetes ServiceAccount for the Alien agent/manager pod.
kubernetes_resource_name
Canonical Kubernetes workload name for stack resources.
kubernetes_service_account_name
Canonical Kubernetes ServiceAccount for a permission profile.
links_of
The links a resource owns, empty when it owns none.
live_gate_of
The gate input of a runtime-created gated resource, None for anything else. The mirror of frozen_gate_of — which side of the setup boundary a gated resource falls on is decided in exactly these two places.
live_gate_resolves_true
A live gate’s answer: the provided value, else the answer recorded when the deployment was created (frozen dominance — a live resource sharing a frozen-gating input follows the fixed answer, not the declared default), else the declared default.
live_gated
Every gated resource the runtime creates, as (resource_id, input_id).
millicores
A CPU quantity in millicores.
new_id
Generate a new ID for the specified type
ownership_policy_for_resource_type
parse_application_log_level
Reads an unambiguous severity from a structured application log.
parse_application_log_message
Extracts a readable message only from recognized structured stdout formats. The caller can keep the original line as log.record.original when this succeeds. Unknown JSON stays untouched rather than guessing a message key.
parse_bundle_uri
Reads a sandbox bundle URI, refusing anything an image build would only reject later.
parse_ecr_image_repository
Reads privateBaseImage as the one repository a build role may pull from.
parse_public_endpoint_assignment
Parse a public endpoint assignment in <resource-id>.<endpoint-name>=<absolute-url> form.
permission_profile_from_service_account_id
ServiceAccount resource IDs are generated as {permission_profile}-sa.
public_url_host
Return the host part of an already-validated public URL.
public_url_port
Return the effective port of an already-validated public URL.
quantity_mib
A memory or disk quantity in whole MiB, rounded down.
remove_declined_resources
Take declined gated resources out of stack with every link, ordering edge and grant naming them. The deployment strips and the preflight runner’s digest projection share it, so the installed stack and the target they compare are stripped the same way.
resolve_stack_input_environment_variables
Environment variables produced by stack inputs that declare env mappings, from the deployment’s input values (or each input’s default).
resource_links
The link-owning view of a resource, or None when it owns no links.
resource_links_mut
Mutable counterpart of resource_links.
restricts_network_mode
Whether the artifact being rendered restricts which network modes it accepts.
setup_resource_tags
The tags the template setups put on what they create for a resource, with the stack name replaced by the resource prefix. A direct setup creating the same objects uses these.
stable_bundle_key_prefix
The prefix a rebuild’s new key still sits under: everything above the file name and the version segment beneath it. None when nothing sits there, meaning no prefix can be granted without also granting objects a rebuild never reads. Shared so both emitters agree on it.
stack_needs_named_subnets_at_setup
Whether any setup-owned resource forces setup to name subnets.
standard_resource_tags
surviving_frozen_gate_answers
Frozen-gate answers read off a stack whose Frozen declines were already stripped: a surviving gated setup-created resource reads as yes, even when its gate was never answered. So a strip built on it never drops what the real strip keeps: a digest can miss a match, never fake one.
targets_resource
Whether an environment variable with these target_resources reaches resource_id: every resource when unset, else an exact id or a prefix* pattern. Env delivery and the permissions that follow from it (such as reading a deployer secret) share this one rule.
type_gateability
Gateability of one built-in user resource type, keyed for the manifest.
validate_binding_type
Validates that an external binding type matches the resource type.
validate_endpoint_host_label
Validates a single DNS label used in generated endpoint hostnames.
validate_endpoint_name
Validates a public endpoint name within a resource.
validate_kubernetes_compute
Validate logical pools without querying or provisioning Kubernetes nodes.
validate_public_endpoint_url
Validate one externally supplied endpoint URL.
validate_public_endpoint_urls
Validate endpoint URL overrides keyed by resource ID and endpoint name.

Type Aliases§

GateAnswers
Answers for inputs gating Frozen resources, keyed by input id.
PublicEndpointDomainInfo
Certificate and DNS metadata for a public endpoint.
PublicEndpointUrls
Public endpoint URL overrides keyed by resource ID, then endpoint name.
Result

Attribute Macros§

alien_event
A procedural macro that wraps a function with an AlienEvent scope.