Skip to main content Crate alien_core Copy item path Source pub use permissions ::*;pub use runtime_environment ::*;pub use events ::*;pub use app_events ::*;pub use bindings ::*;pub use presigned ::*;pub use commands_types ::*;pub use import ::*;access_request_crd White-labeled naming for the access-request custom resource. ai_catalog Curated, per-cloud model catalog for the AI gateway. app_events Application Events bindings Type-safe binding parameter definitions commands_types compute_planner Deployment-time compute planner. crontab_to_eventbridge debug_session Wire shapes for alien debug sessions. embedded_config Embedded configuration support for alien-deploy-cli and alien-operator binaries. events Alien Events System file_utils image_rewrite Image URI utilities for the registry proxy. import Typed setup import contract. instance_catalog Instance type catalog and selection algorithm for cloud compute infrastructure. permissions Core permission types. presigned remote_bindings runtime_environment sandbox_build_role The IAM role an AWS sandbox image build runs as, as concrete policy documents. sandbox_capability Sandbox capabilities: what the manager mints and the agent verifies. sandbox_egress What an AWS sandbox with egress: deny needs in the customer account, as concrete documents:
the operator role Lambda assumes to place the connector’s network interfaces, and the
AWS::Lambda::NetworkConnector those interfaces belong to. sandbox_image What a sandbox image must carry for the agent to serve, and the Dockerfile text carrying it. sandbox_setup_inputs The facts an AWS sandbox’s setup renders its scaffolding from. Setup applies them and the
runtime never re-reads them, so a change to any of them needs setup to run again. sync Sync protocol types for agent ↔ manager communication. vault_naming How each vault backend names a secret in the cloud’s own secret store. AgentStatus Status of a single agent in the dev server Ai Represents an AI Gateway resource that provides a unified interface to
managed AI inference services across cloud providers. AiAvailabilityObservation AiBuilder Use builder syntax to set the inputs and finish with build() . AiHeartbeatStatus AiModelAvailabilityObservation AiOutputs Outputs generated by a successfully provisioned AI Gateway resource. ArtifactRegistry Represents an artifact registry for storing container images and other build artifacts.
This is a high-level wrapper resource that provides a cloud-agnostic interface over
AWS ECR, GCP Artifact Registry, and Azure Container Registry. ArtifactRegistryBuilder Use builder syntax to set the inputs and finish with build() . ArtifactRegistryHeartbeatStatus ArtifactRegistryOutputs Outputs generated by a successfully provisioned ArtifactRegistry. AuroraPostgresHeartbeatData AwsBedrockAiHeartbeatData AwsClientConfig AWS client configuration AwsCodeBuildHeartbeatData AwsComputeClusterHeartbeatData AwsCustomCertificateConfig AwsDaemonHeartbeatData AwsDynamoDbKeySchemaElement AwsDynamoDbKvHeartbeatData AwsEcrArtifactRegistryHeartbeatData AwsEcrRepositoryHeartbeatData AwsEnvironmentInfo AWS-specific environment information AwsIamRoleServiceAccountHeartbeatData AwsImpersonationConfig Configuration for AWS role impersonation AwsKmsKeyHeartbeatData AwsLambdaWorkerHeartbeatData AwsManagementConfig AWS management configuration extracted from stack settings AwsMicrovmSandboxHeartbeatData AWS: the image a sandbox runs from, and the lifecycle state AWS reports for it. AwsOpenSearch An Amazon OpenSearch Serverless collection (next generation). AwsOpenSearchBuilder Use builder syntax to set the inputs and finish with build() . AwsOpenSearchCapacity Indexing and search capacity limits for an OpenSearch collection group. AwsOpenSearchCapacityRange Minimum and maximum OCU bounds for one OpenSearch compute component. AwsOpenSearchOutputs Outputs generated by a successfully provisioned AwsOpenSearch collection. AwsParameterStoreVaultHeartbeatData AwsRemoteStackManagementHeartbeatData AwsS3StorageHeartbeatData AwsSandboxEgressScaffolding The objects that keep an AWS deny sandbox’s sessions inside the VPC. Each id is recorded as
soon as the object exists and cleared once it is deleted. AwsServiceOverrides Service endpoint overrides for testing AWS services AwsSqsQueueHeartbeatData AwsVpcNetworkHeartbeatData AwsWebIdentityConfig Configuration for AWS Web Identity Token authentication AzureBlobStorageHeartbeatData AzureClientConfig Azure client configuration AzureComputeClusterHeartbeatData AzureContainerAppsBuildHeartbeatData AzureContainerAppsEnvironment Represents an Azure Container Apps Environment for hosting container applications. AzureContainerAppsEnvironmentBuilder Use builder syntax to set the inputs and finish with build() . AzureContainerAppsEnvironmentHeartbeatData AzureContainerAppsEnvironmentHeartbeatStatus AzureContainerAppsEnvironmentOutputs Outputs generated by a successfully provisioned Azure Container Apps Environment. AzureContainerAppsEnvironmentWorkloadProfile AzureContainerAppsWorkerHeartbeatData AzureContainerRegistryHeartbeatData AzureCustomCertificateConfig AzureDaemonHeartbeatData AzureEnvironmentInfo Azure-specific environment information AzureFlexibleServerPostgresHeartbeatData AzureFoundryAiHeartbeatData AzureImpersonationConfig Configuration for Azure managed identity impersonation AzureKeyVaultHeartbeatData AzureKeyVaultKeyHeartbeatData AzureManagedIdentityServiceAccountHeartbeatData AzureManagementConfig Azure management configuration extracted from stack settings AzureRemoteStackManagementHeartbeatData AzureResourceGroup Represents an Azure Resource Group that acts as a logical container for Azure resources. AzureResourceGroupBuilder Use builder syntax to set the inputs and finish with build() . AzureResourceGroupHeartbeatData AzureResourceGroupHeartbeatStatus AzureResourceGroupOutputs Outputs generated by a successfully provisioned Azure Resource Group. AzureResourceProviderActivationHeartbeatData AzureSandboxGroupHeartbeatData Azure: the sandbox group’s ARM state. The data plane has no list operation, so a sandbox count
is not available here. AzureServiceBusNamespace Represents an Azure Service Bus Namespace for hosting queues and topics. AzureServiceBusNamespaceBuilder Use builder syntax to set the inputs and finish with build() . AzureServiceBusNamespaceHeartbeatData AzureServiceBusNamespaceOutputs Outputs generated by a successfully provisioned Azure Service Bus Namespace. AzureServiceBusQueueHeartbeatData AzureServiceOverrides Service endpoint overrides for testing Azure services AzureStorageAccount Represents an Azure Storage Account for blob, file, table, and queue storage. AzureStorageAccountBuilder Use builder syntax to set the inputs and finish with build() . AzureStorageAccountEndpoints AzureStorageAccountHeartbeatData AzureStorageAccountOutputs Outputs generated by a successfully provisioned Azure Storage Account. AzureTableKvHeartbeatData AzureVnetNetworkHeartbeatData Build Represents a build resource that executes bash scripts to build code.
Builds are designed to be stateless and can be triggered on-demand to compile,
test, or package application code. BuildBuilder Use builder syntax to set the inputs and finish with build() . BuildConfig Configuration for starting a build. BuildExecution Information about a build execution. BuildHeartbeatStatus BuildOutputs Outputs generated by a successfully provisioned Build. CapacityGroup Capacity group definition. CapacityGroupStatus Status of a single capacity group within a ComputeCluster. ComputeCapacityBlocker ComputeCapacityGroupStatus ComputeCapacityRecommendation ComputeChoiceRange Allowed range and default for a count selected by the installer. ComputeCluster ComputeCluster resource for running long-running container workloads. ComputeClusterBuilder Use builder syntax to set the inputs and finish with build() . ComputeClusterHeartbeatStatus ComputeClusterOutputs Outputs generated by a successfully provisioned ComputeCluster. ComputeDrainBlocker ComputeDrainProgress ComputeSettings Deployment-time compute choices for Alien-managed compute pools. Container Container resource for running long-running container workloads. ContainerAutoscaling Autoscaling configuration for stateless containers. ContainerBuilder Use builder syntax to set the inputs and finish with build() . ContainerGpuSpec GPU specification for a container. ContainerImageIdentity Image a running container reports. ContainerOutputs Outputs generated by a successfully provisioned Container. ContainerPort Container port configuration. ContainerSecurity Container process identity and filesystem security. ContainerTunnel A container port reachable from the control plane through the manager. CustomCertificateConfig Platform-specific certificate references for custom domains. CustomDomainConfig Custom domain configuration for a single resource. Daemon DaemonBuilder Use builder syntax to set the inputs and finish with build() . DaemonOutputs DaemonRuntime DaemonRuntimeMount DeployerSecretEnv An environment variable a workload reads from a vault-native deployer
secret when it starts. DeployerSecretLocation Where a deployer writes a vault-native secret. DeployerSecretLocationContext What a location needs beyond the vault binding. DeployerSecretReport The state of one deployer secret slot, reported with the deployment. DeployerSecretSlot A deployer secret input whose value lives in the customer’s secret store. DeploymentConfig Deployment configuration DeploymentConfigBuilder Use builder syntax to set the inputs and finish with build() . DeploymentState Deployment state DeploymentStateBuilder Use builder syntax to set the inputs and finish with build() . DeploymentStepResult Result of a deployment step DevResourceInfo Information about a deployed resource DevStatus Overall status of the dev server DomainMetadata Domain metadata for auto-managed public resources (no private keys). DomainSettings Domain configuration for the stack. EcrImageRepository The ECR repository a private image reference is pulled from. Email Email infrastructure for sending and receiving mail on customer-owned
domains. On AWS this is backed by SES: a shared configuration set, optional
inbound/event wiring, and one email identity (Easy DKIM) per seed domain. EmailBuilder Use builder syntax to set the inputs and finish with build() . EmailDkimToken A single DKIM CNAME record the operator must create in DNS. EmailDomainOutputs Per-domain DNS records the operator must create. EmailEvents Event configuration for an Email resource. EmailInbound Inbound-mail configuration for an Email resource. EmailOutputs Outputs generated by a successfully provisioned Email resource. EnvironmentVariable Environment variable for deployment EnvironmentVariablesSnapshot Snapshot of environment variables at a point in time ExternalAiHeartbeatData ExternalBindings Map from resource ID to external binding. FailureDomainSelection Failure-domain policy selected for a compute pool. GcpAgentPlatformEngine A Gemini Agent Platform reasoning engine: the durable parent that sandbox
environment templates and sandboxes hang under. One per sandbox, provisioned
once and addressed by the server-assigned id its controller records. GcpAgentPlatformEngineBuilder Use builder syntax to set the inputs and finish with build() . GcpAgentPlatformSandboxHeartbeatData GCP: the Agent Platform template sandboxes are cut from, and the engine it hangs under. GcpArtifactRegistryHeartbeatData GcpClientConfig GCP client configuration GcpCloudBuildHeartbeatData GcpCloudKmsKeyHeartbeatData GcpCloudRunWorkerHeartbeatData GcpCloudSqlPostgresHeartbeatData GcpCloudStorageHeartbeatData GcpComputeClusterHeartbeatData GcpCustomCertificateConfig GcpDaemonHeartbeatData GcpEnvironmentInfo GCP-specific environment information GcpFirestoreKvHeartbeatData GcpImpersonationConfig Configuration for GCP service account impersonation GcpManagementConfig GCP management configuration extracted from stack settings GcpPubSubQueueHeartbeatData GcpRemoteStackManagementHeartbeatData GcpSecretManagerVaultHeartbeatData GcpServiceAccountHeartbeatData GcpServiceOverrides Service endpoint overrides for testing GCP services GcpServiceUsageActivationHeartbeatData GcpVertexAiHeartbeatData GcpVpcNetworkHeartbeatData GpuSpec GPU specification for a capacity group. HealthCheck HTTP health check configuration. HeartbeatCollectionIssue HorizonAwsMachineImages AWS Horizon machine image catalog. HorizonAzureMachineImage Azure Horizon machine image entry. HorizonAzureMachineImages Azure Horizon machine image catalog. HorizonClusterConfig Configuration for a single container worker cluster. HorizonConfig Horizon control-plane configuration for container orchestration. HorizonContainerHeartbeatData HorizonGcpMachineImage GCP Horizon machine image entry. HorizonGcpMachineImages GCP Horizon machine image catalog. HorizonMachineBaseImage Base image metadata for the Horizon machine image. HorizonMachineImage Horizon machine image catalog. HorizondArtifact Download artifact for one horizond release platform. IdConfig Configuration for ID generation Key A customer-managed encryption key. KeyBuilder Use builder syntax to set the inputs and finish with build() . KeyHeartbeatStatus KeyOutputs Outputs generated by a successfully provisioned Key. KubernetesBuildHeartbeatData KubernetesCloudReference Optional provider-specific identity for a cloud-backed Kubernetes cluster. KubernetesCluster Runtime substrate for Kubernetes deployments. KubernetesClusterBuilder Use builder syntax to set the inputs and finish with build() . KubernetesClusterHeartbeatData KubernetesClusterNodeStatus KubernetesClusterOutputs Outputs produced once the Kubernetes substrate is ready for workloads. KubernetesClusterSettings Kubernetes cluster setup settings. KubernetesContainerHeartbeatData KubernetesCustomCertificateConfig KubernetesDaemonHeartbeatData KubernetesEventInvolvedObject KubernetesEventSnapshot KubernetesEventSource KubernetesGatewayRouteProfile Shared Gateway API route profile values. KubernetesHttpProbe HTTP probe used by Kubernetes for workload liveness or readiness. KubernetesIngressRouteProfile Shared Ingress route profile values. KubernetesNodeConditionStatus KubernetesNodeResources KubernetesNodeUsage KubernetesOwnerReference KubernetesPodRuntimeUnitStatus KubernetesSandboxHeartbeatData Kubernetes: pods carrying the sandbox label, in the deployment’s namespace. KubernetesSecretMount Mounts an existing, setup-owned Kubernetes Secret into a Container pod.
The Secret must exist in the deployment namespace before the workload starts. KubernetesSecretVaultHeartbeatData KubernetesSettings Kubernetes runtime substrate configuration. KubernetesTlsSecretRef Namespace-scoped Kubernetes TLS Secret reference. KubernetesWorkerHeartbeatData KubernetesWorkloadCondition KubernetesWorkloadStatus Kv Represents a key-value storage resource that provides a minimal, platform-agnostic API
compatible across DynamoDB, Firestore, Redis, and Azure Table Storage. KvBuilder Use builder syntax to set the inputs and finish with build() . KvHeartbeatStatus KvOutputs Outputs generated by a successfully provisioned KV store. LifecycleRule Defines a rule for managing the lifecycle of objects within a storage bucket. LoadBalancerEndpoint Load balancer endpoint information for DNS management.
This is optional metadata used by the DNS controller to create domain mappings. LocalArtifactRegistryHeartbeatData LocalComputeClusterHeartbeatData LocalContainerHeartbeatData LocalDaemonHeartbeatData LocalEnvironmentInfo Local platform environment information LocalKvHeartbeatData LocalPostgresHeartbeatData LocalQueueHeartbeatData LocalRuntimeEventSnapshot LocalRuntimeEventSubject LocalRuntimeUnitStatus LocalSandboxHeartbeatData Local: containers Docker still holds for this sandbox. LocalServiceAccountHeartbeatData LocalStorageHeartbeatData LocalVaultHeartbeatData LocalWorkerHeartbeatData MachineProfile Machine resource profile for a capacity group. MachinesComputeClusterHeartbeatData MachinesComputeMachineStatus MachinesDaemonHeartbeatData ManagedDomainInfo Certificate and DNS metadata for a managed hostname. ManagedRuntimeEventInvolvedObject ManagedRuntimeEventSnapshot ManagedRuntimeEventSource ManagedRuntimeUnitStatus MetricSample MicrovmTier One of the five sizes a Lambda MicroVM can be built at. MonitoringConfig Configuration for monitoring and observability. NamedResourceDetail Network Represents cloud-agnostic networking infrastructure (VPC, VNet, subnets, etc.). NetworkBuilder Use builder syntax to set the inputs and finish with build() . NetworkHeartbeatStatus NetworkOutputs Outputs generated by a successfully provisioned Network. ObservedCounts ObservedInventoryBatch ObservedResourceSample OtlpConfig OTLP log export configuration for a deployment. PersistentStorage Persistent storage configuration for stateful containers. Postgres A managed PostgreSQL database. The target platform decides the backend
(AWS Aurora Serverless v2, GCP Cloud SQL, Azure Flexible Server, or an
embedded native process on Local); the database is never publicly reachable. PostgresBuilder Use builder syntax to set the inputs and finish with build() . PostgresHeartbeatStatus PostgresOutputs Outputs generated by a successfully provisioned Postgres database. ProviderFleetStatus PublicEndpoint Public endpoint configuration for port-backed workload resources. PublicEndpointOutput Runtime-resolved public endpoint metadata. Queue Represents a message queue resource with minimal, portable semantics.
Queue integrates with platform-native services (AWS SQS, GCP Pub/Sub, Azure Service Bus). QueueBuilder Use builder syntax to set the inputs and finish with build() . QueueHeartbeatStatus QueueOutputs Outputs generated by a successfully provisioned Queue. RawHeartbeatSnippet ReadinessProbe Configuration for HTTP-based readiness probe.
This probe is executed after worker provisioning/update to verify the worker is ready to serve traffic.
Only works with workers that have Public ingress. RegistryAccess The cross-account read a manager opened on Alien’s registry for one deployment. ReleaseInfo Release metadata RemoteBindingGrant RemoteBindings Setup-owned identity used to issue short-lived application credentials for
explicitly published resources. RemoteBindingsBuilder Use builder syntax to set the inputs and finish with build() . RemoteBindingsOutputs RemoteStackManagement Represents cross-account management access configuration for a stack deployed
on AWS, GCP, or Azure platforms. This resource sets up the necessary IAM/RBAC
configuration to allow another cloud account to manage the stack. RemoteStackManagementBuilder Use builder syntax to set the inputs and finish with build() . RemoteStackManagementHeartbeatStatus RemoteStackManagementOutputs Resource outputs for RemoteStackManagement.
Different platforms will provide different outputs based on their implementation. ReplicaStatus Status of a single container replica. Resource ResourceDomainInfo Certificate and DNS metadata for a public resource. ResourceEntry ResourceHeartbeat ResourceOutputs New Resource outputs wrapper that can hold any ResourceOutputsDefinition.
This replaces the old ResourceOutputs enum to enable runtime extensibility. ResourceOwnershipPolicy ResourceRef Reference to a resource by its stable id and resource type. ResourceSpec Resource specification with min/desired values. ResourceType Type alias for resource type identifiers RuntimeMetadata Runtime metadata for deployment Sandbox An isolated environment for running untrusted code, created at runtime. SandboxBuilder Use builder syntax to set the inputs and finish with build() . SandboxCapabilities What a platform’s sandbox backend can actually do. SandboxHeartbeatStatus SandboxLifecyclePolicy How long a sandbox may live and when it is paused. SandboxLimits Hard ceilings enforced on a sandbox. SandboxOutputs Outputs generated by a successfully provisioned Sandbox parent. SandboxPrivilegedSupervisor Opt-in supervisor-owned network enforcement. Caller requests cannot change this identity. ServiceAccount Represents a non-human identity that can be assumed by compute services
such as Lambda, Cloud Run, ECS, Container Apps, etc. ServiceAccountBuilder Use builder syntax to set the inputs and finish with build() . ServiceAccountHeartbeatStatus ServiceAccountOutputs Outputs generated by a successfully provisioned ServiceAccount. ServiceActivation Represents a service activation that can be enabled on cloud platforms.
For GCP: enables project services (e.g., iam.googleapis.com, compute.googleapis.com).
For Azure: registers resource providers (e.g., Microsoft.DocumentDB, Microsoft.Storage). ServiceActivationBuilder Use builder syntax to set the inputs and finish with build() . ServiceActivationHeartbeatStatus ServiceActivationOutputs Outputs generated by a successfully activated service. SetupUpdateAuthorization One-shot authority for a setup re-import to replace setup-owned resources. Stack A bag of resources, unaware of any cloud. StackBuilder Use builder syntax to set the inputs and finish with build() . StackInputDefinition Stack input definition serialized into a release stack. StackInputEnvironmentMapping How a resolved stack input is injected into runtime environment variables. StackInputGenerate Asks Alien to generate a secret input’s value. StackInputValidation Portable stack input validation constraints. StackResourceState Represents the state of a single resource within the stack for a specific platform. StackResourceStateBuilder Use builder syntax to set the inputs and finish with build() . StackSettings User-customizable deployment settings specified at deploy time. StackState Represents the collective state of all resources in a stack, including platform and pending actions. Storage Represents an object storage bucket. StorageBuilder Use builder syntax to set the inputs and finish with build() . StorageHeartbeatStatus StorageOutputs Outputs generated by a successfully provisioned Storage bucket. TestEnvironmentInfo Test platform environment information (mock) TypeGateability Per-lifecycle gateability of one resource type, derived from the ownership
table and the gate refusals. Serialized into the generated manifest the
TypeScript SDK’s surface test consumes. Vault Represents a secure vault for storing secrets.
This resource provides a platform-agnostic interface over cloud-native secret management services: VaultBuilder Use builder syntax to set the inputs and finish with build() . VaultHeartbeatStatus VaultOutputs Outputs generated by a successfully provisioned Vault. VolumeBackups Scheduled snapshots of a persistent volume. VolumeBackupsStatus Whether a container’s snapshot schedule is in place. VolumeOutput A replica’s persistent volume and its latest completed snapshot. VolumeRestoreOutput A completed volume restore. VolumeRestoreRequest Replace one replica’s persistent volume with a new volume made from a snapshot. Worker Represents a serverless worker that executes code in response to triggers or direct invocations.
Workers are the primary compute resource in serverless applications, designed to be stateless and ephemeral. WorkerBuilder Use builder syntax to set the inputs and finish with build() . WorkerOutputs Outputs generated by a successfully provisioned Worker. WorkerPublicEndpoint Public endpoint configuration for Worker resources. WorkloadHeartbeatStatus WorkloadReplicaStatus AiAccessTest AiAvailabilityBlocker AiAvailabilitySource Provider control plane used to observe model availability without invoking
a model, spending customer quota, or accepting provider terms. AiHeartbeatData AiModelAvailability ApplicationLogLevel A recognized application-provided log level. ArtifactRegistryHeartbeatData AwsCredentials Supported AWS authentication methods AwsOpenSearchCollectionType Workload type for an OpenSearch Serverless collection. AzureCredentials Represents Azure authentication credentials AzureSandboxImage What an Azure sandbox starts from. BinaryTarget Target OS and architecture for compiled binaries. BuildHeartbeatData BuildHost Operating system and architecture of the machine running a build. BuildStatus Status of a build execution. BundleUri A bundle URI split around its region token, or carried whole when it has none. CapacityGroupScalePolicy Source-declared scale policy for a capacity group. CargoBuildStrategy Build strategy for cross-compilation. CertificateStatus Certificate status in the certificate lifecycle ClientConfig Configuration for different cloud platform clients ComputeBackend Compute backend for Container and Worker resources. ComputeCapacityBlockerCategory ComputeClusterHeartbeatData ComputeDrainProgressStatus ComputeKind A compute resource kind that receives injected environment variables. ComputePoolSelection User-selected deployment settings for one compute pool. ComputeType Compute type for build resources. ContainerCode Specifies the source of the container’s executable code. ContainerHeartbeatData ContainerSecurityProfile Security profile shared by container runtimes. ContainerStatus Container status in the managed container backend. DaemonCode DaemonHeartbeatData DeployerSecretStatus Whether a deployer secret slot holds a usable value. Alien learns this from
metadata only and never reads the value. DeployerSecretStore The secret store a deployer writes a vault-native secret into. DeploymentModel Deployment model: how updates are delivered to the remote environment. DeploymentStatus Deployment status in the deployment lifecycle. DevStatusState Overall dev server status DnsRecordStatus DNS record status in the DNS lifecycle EcrImageRegion Where a private ECR image’s region comes from. EndpointAccess Reachability of the deployment’s public endpoints, fixed at setup. EnvironmentInfo Platform-specific environment information EnvironmentVariableType Type of environment variable ErrorData Core error data exposed by the alien-core crate. ExposeProtocol Protocol for public workload endpoints. ExternalBinding Represents a binding to pre-existing infrastructure. GateInputIssue Why a gate input failed render-time validation; the caller owns the
backend-specific error message. GateRefusal Why a resource cannot carry an .enabled() gate. GcpCredentials Authentication options for talking to GCP APIs. HeartbeatBackend HeartbeatCollectionIssueReason HeartbeatIssueSeverity HeartbeatsMode How heartbeat health checks are handled. HorizonMachineArchitecture Horizon machine image architecture. HorizonWorkloadSchedulingMode HttpMethod HTTP method for readiness probe requests. IdType Defines different ID types with their configuration ImpersonationConfig Cloud-agnostic impersonation configuration InitialSetupAuthority Actor that owns structural work during the initial setup phase. KeyFingerprint Stable identity of a provider key family. KeyHeartbeatData KubernetesCertificateMode Certificate publication or reference mode for Kubernetes public endpoints. KubernetesClientConfig Configuration mode for Kubernetes access KubernetesClusterOwnership Ownership model for the Kubernetes cluster. KubernetesClusterProvider Kubernetes provider backing the runtime substrate. KubernetesExposureSettings Kubernetes public HTTPS exposure mode. KubernetesHeartbeatMode How Alien should heartbeat this Kubernetes substrate. KubernetesRouteProfile Kubernetes route API selected for public endpoints. KubernetesRouteProviderOptions Provider-specific route options required by supported managed profiles. KubernetesWorkloadKind KvHeartbeatData LocalRuntimeUnitKind ManagementConfig Management configuration for different cloud platforms. MetricUnit NetworkHeartbeatData NetworkSettings Network configuration for the stack. ObservedHealth Platform Represents the target cloud platform. PostgresBackend Cloud backend for a Postgres resource. Only Aurora Serverless v2 ships in v1;
the enum reserves the slot so provisioned RDS is an additive variant later. PostgresHeartbeatData ProviderLifecycleState PublicEndpointTargetSettings DNS target mode for public endpoints. QueueHeartbeatData RawHeartbeatSnippetFormat RemoteStackManagementHeartbeatData ResourceHeartbeatData ResourceLifecycle Describes the lifecycle of a resource within a stack, determining how it’s managed and deployed. ResourceStatus Represents the high-level status of a resource during its lifecycle. SandboxCapability Names a single sandbox capability, so an unsupported call can report which one it needed. SandboxCode Specifies where the sandbox’s root filesystem comes from. SandboxEgress Outbound network policy for a sandbox. SandboxHeartbeatData Content-free telemetry about what a sandbox resource is running. SecretDelivery The mechanism by which Secret-typed env vars are delivered to a workload. ServiceAccountHeartbeatData ServiceActivationHeartbeatData SetupEmission When a resource type contributes anything to the setup artifact. SetupScaffolding Cloud objects a direct setup created so a runtime-owned resource can run. SourceBinaryType Types of source binaries used for package building StackInputDefaultValue Stack input default value. StackInputEnvironmentVariableType Environment variable handling for a stack input mapping. StackInputKind Primitive stack input kind. StackInputProvider Who can provide a stack input value. StackRef Reference to a stack for management permissions StackStatus Represents the overall status of a stack based on its resource states. StorageHeartbeatData TelemetryMode How telemetry (logs, metrics, traces) is handled. ToolchainConfig Configuration for different programming language toolchains.
Each toolchain provides type-safe build configuration and auto-detection capabilities. UpdatesMode How updates are delivered to the deployment. VaultHeartbeatData VolumeBackupsState State of a container’s snapshot schedule. WorkerCode Specifies the source of the worker’s executable code.
This can be a pre-built container image or source code that the system will build. WorkerHeartbeatData WorkerTrigger Defines what triggers a worker execution. ALIEN_MANAGED_BY_TAG_KEY ALIEN_MANAGED_BY_TAG_VALUE ALIEN_RESOURCE_TAG_KEY ALIEN_STACK_TAG_KEY ALIEN_SYSTEM_RESOURCE_ATTRIBUTE Resource-attribute key marking OTLP telemetry as Alien system-component
output (infrastructure daemons and internal runtimes) rather than user
workload. Log consumers — the CLI log viewer and the dashboard — hide
telemetry carrying this attribute by default. The value is the string
"true". ALPHABET_LOWERCASE ALPHABET_MIXED_CASE APEX_HOST_LABEL Host label that places a generated public endpoint at the deployment base hostname. AZURE_DISK_IMAGE_LABEL Label key the controller writes on every disk image it builds, and the provider finds it by. BUNDLE_REGION_TOKEN The one token a sandbox bundle URI may carry, replaced with the deploying region. CURRENT_DEPLOYMENT_PROTOCOL_VERSION Deployment protocol version this binary writes.
Bump when making incompatible changes to DeploymentState semantics. DEFAULT_ALIEN_LABEL_DOMAIN DEPLOYER_SECRET_KEY_PREFIX Prefix of every vault key that holds a deployer secret, so these keys
never collide with the env-var-named keys Alien syncs itself. DEPLOYER_SECRET_VALUE_PLACEHOLDER Placeholder for the secret value in the CLI commands Alien shows. DEPLOYMENT_PROTOCOL_VERSION Backwards-compatible alias for older call sites. ENV_ALIEN_DEPLOYER_SECRETS Env var that carries a natively projected workload’s
DeployerSecretEnv list to its hosting controller, which resolves each
entry before the process starts (a secretKeyRef on Kubernetes, a vault
read on the local platform). It holds names only, never values. MANIFEST_TYPES The built-in user resource types listed in the generated manifest. The SDK
builder surface is asserted against exactly this set. MAX_WORKER_TIMEOUT_SECONDS Longest Worker execution supported by every Commands delivery path. MIN_SUPPORTED_DEPLOYMENT_PROTOCOL_VERSION Oldest deployment protocol version this binary can read. POSTGRES_DATABASE_NAME The fixed inner database (and admin user) name for cloud Postgres backends.
AWS rejects hyphens in DatabaseName, and the cluster/instance/server name already
carries the resource id, so the inner database is a fixed label rather than the id.
Every cloud emitter and controller derives its database name from this single constant
so a frozen import always binds to a database that exists. (Local names its database
after the resource id and does not use this.) RESOURCE_PREFIX_ERROR_MESSAGE SECRETS_VAULT_ID Reserved id of the deployment secrets vault. STACK_INPUT_GENERATE_MAX_LENGTH Longest value Alien generates for a secret input. STACK_INPUT_GENERATE_MIN_LENGTH Shortest value Alien generates for a secret input. VERSION VOLUME_BACKUP_INTERVAL_HOURS Hours between snapshots that every cloud’s native snapshot scheduler supports. VOLUME_BACKUP_MAX_RETENTION_DAYS Longest a snapshot may be kept. Azure Disk Backup keeps operational snapshots
for at most a year; the same limit applies everywhere for portability. VOLUME_BACKUP_MAX_SNAPSHOTS Most snapshots a volume may hold at once. Azure Disk Backup keeps at most 450
scheduled snapshots per disk; the same limit applies everywhere so a stack is
portable across clouds. ResourceDefinition Trait that defines the interface for all resource types in the Alien system.
This trait enables extensibility by allowing new resource types to be registered
and managed alongside built-in resources. ResourceLinks A resource definition that owns resource links. ResourceOutputsDefinition Trait that defines the interface for all resource output types in the Alien system.
This trait enables extensibility by allowing new resource output types to be registered
and managed alongside built-in resource outputs. azure_disk_image_label The label value naming the disk image built from reference: a digest, since a label value
may not carry a reference’s /, : and @. branded_standard_resource_tags branded_tag_key classify_azure_sandbox_image Classifies a declared code.image for Azure, or None when it is neither kind. A bare
[A-Za-z0-9._-]+ is checked first and always a catalog name; anything else must carry /,
: or @ and parse as an OCI reference. declined_live_resources The ids of the gated live resources whose input resolves false. default_branded_standard_resource_tags deployer_secret_environment The environment variables workloads read from vault-native deployer
secrets, each with the resources its mapping targets (None = all). deployer_secret_location Where the deployer writes the value for vault_key of the secrets vault
described by binding. deployer_secret_slots The vault-native deployer secret slots of a deployment on platform. deployer_secret_value_refusal Why a setup path refuses a value for the deployer secret name (its label
or id), with what to do instead. deployer_secret_vault_key The secrets vault key for a deployer secret input: input- plus the input
id in lowercase kebab case (databasePassword → input-database-password). find_boolean_gate_input Finds the boolean deployer input a gate references, for render-time
re-validation. The compile-time preflight enforces the same two rules;
generators repeat them so a caller that renders without preflights cannot
ship a template whose gate variable is undeclared or non-boolean. frozen_gate_of The gate input of a setup-created gated resource, None for anything else. frozen_gated Every gated resource setup creates, as (resource_id, input_id). gate_refusal Whether a resource may carry an .enabled() gate at all. None means
gateable. Lifecycle legality is not decided here — a lifecycle the type
does not allow is refused by the lifecycle rules regardless of gating. gate_resolves_true The deployer’s answer for a live gate: the provided value, else the
input’s declared boolean default. The error is the reason, for the caller to wrap. gate_value_as_bool A gate value from the wire: JSON booleans stay booleans, and the
CloudFormation parameter strings “true”/“false” coerce — CloudFormation
has no boolean parameter type, so its registration payloads deliver gate
answers as strings. Anything else is None, refused loudly by callers. generate_id_example Generate a deterministic ID example for a given type id_error_message Generate an error message for invalid IDs id_regex_pattern Generate a regex pattern for validating IDs of a specific type is_deployer_secret_input Whether the deployer may provide this secret input. is_valid_resource_prefix kubernetes_build_service_account_name Canonical Kubernetes ServiceAccount for build jobs. kubernetes_compute_architecture Architecture shared by source images built for this Kubernetes stack.
Unspecified pools and Workers inherit this build constraint, so their Pods
cannot land on incompatible nodes in a cluster with mixed architectures. kubernetes_compute_node_selector Match Pod placement to the architecture used by the stack’s source images.
This does not associate Workers with a compute pool or reserve node capacity. kubernetes_container_pool Resolve placement, inferring a single declared cluster and its general or
sole pool. Legacy stacks without a declaration keep default scheduling. kubernetes_daemon_pool Resolve a daemon’s pool without changing its per-node DaemonSet behavior. kubernetes_dynamic_pool Resolve the one pool admitted for release-independent containers. kubernetes_manager_service_account_name Canonical Kubernetes ServiceAccount for the Alien agent/manager pod. kubernetes_resource_name Canonical Kubernetes workload name for stack resources. kubernetes_service_account_name Canonical Kubernetes ServiceAccount for a permission profile. links_of The links a resource owns, empty when it owns none. live_gate_of The gate input of a runtime-created gated resource, None for anything
else. The mirror of frozen_gate_of — which side of the setup boundary a
gated resource falls on is decided in exactly these two places. live_gate_resolves_true A live gate’s answer: the provided value, else the answer recorded when
the deployment was created (frozen dominance — a live resource sharing a
frozen-gating input follows the fixed answer, not the declared default),
else the declared default. live_gated Every gated resource the runtime creates, as (resource_id, input_id). millicores A CPU quantity in millicores. new_id Generate a new ID for the specified type ownership_policy_for_resource_type parse_application_log_level Reads an unambiguous severity from a structured application log. parse_application_log_message Extracts a readable message only from recognized structured stdout formats.
The caller can keep the original line as log.record.original when this
succeeds. Unknown JSON stays untouched rather than guessing a message key. parse_bundle_uri Reads a sandbox bundle URI, refusing anything an image build would only reject later. parse_ecr_image_repository Reads privateBaseImage as the one repository a build role may pull from. parse_public_endpoint_assignment Parse a public endpoint assignment in <resource-id>.<endpoint-name>=<absolute-url> form. permission_profile_from_service_account_id ServiceAccount resource IDs are generated as {permission_profile}-sa. public_url_host Return the host part of an already-validated public URL. public_url_port Return the effective port of an already-validated public URL. quantity_mib A memory or disk quantity in whole MiB, rounded down. remove_declined_resources Take declined gated resources out of stack with every link, ordering edge and grant naming
them. The deployment strips and the preflight runner’s digest projection share it, so the
installed stack and the target they compare are stripped the same way. resolve_stack_input_environment_variables Environment variables produced by stack inputs that declare env
mappings, from the deployment’s input values (or each input’s default). resource_links The link-owning view of a resource, or None when it owns no links. resource_links_mut Mutable counterpart of resource_links . restricts_network_mode Whether the artifact being rendered restricts which network modes it accepts. setup_resource_tags The tags the template setups put on what they create for a resource, with the stack name
replaced by the resource prefix. A direct setup creating the same objects uses these. stable_bundle_key_prefix The prefix a rebuild’s new key still sits under: everything above the file name and the
version segment beneath it. None when nothing sits there, meaning no prefix can be granted
without also granting objects a rebuild never reads. Shared so both emitters agree on it. stack_needs_named_subnets_at_setup Whether any setup-owned resource forces setup to name subnets. standard_resource_tags surviving_frozen_gate_answers Frozen-gate answers read off a stack whose Frozen declines were already stripped: a surviving
gated setup-created resource reads as yes, even when its gate was never answered. So a strip
built on it never drops what the real strip keeps: a digest can miss a match, never fake one. targets_resource Whether an environment variable with these target_resources reaches
resource_id: every resource when unset, else an exact id or a prefix*
pattern. Env delivery and the permissions that follow from it (such as
reading a deployer secret) share this one rule. type_gateability Gateability of one built-in user resource type, keyed for the manifest. validate_binding_type Validates that an external binding type matches the resource type. validate_endpoint_host_label Validates a single DNS label used in generated endpoint hostnames. validate_endpoint_name Validates a public endpoint name within a resource. validate_kubernetes_compute Validate logical pools without querying or provisioning Kubernetes nodes. validate_public_endpoint_url Validate one externally supplied endpoint URL. validate_public_endpoint_urls Validate endpoint URL overrides keyed by resource ID and endpoint name. GateAnswers Answers for inputs gating Frozen resources, keyed by input id. PublicEndpointDomainInfo Certificate and DNS metadata for a public endpoint. PublicEndpointUrls Public endpoint URL overrides keyed by resource ID, then endpoint name. Result alien_event A procedural macro that wraps a function with an AlienEvent scope.