Skip to main content

Module sandbox_image

Module sandbox_image 

Source
Expand description

What a sandbox image must carry for the agent to serve, and the Dockerfile text carrying it.

Two kinds of image exist and neither is built the way the other is. AWS renders one per deployment onto a customer-supplied base image; GCP builds static images in CI. Nothing at build time reads the other side, and a value that disagrees is invisible until a session fails: an agent listening on a port no caller dials, or an exec into a uid the image never created.

So the values live here once and both kinds render the block that carries them from this module. The same holds for the default sandbox base both kinds start from: its toolchain is listed here once, and a probe reads that list rather than restating it. The Dockerfiles and the tool list are committed as generated text because CI builds them with docker build and probes them from a shell, neither of which can call a Rust function.

Structs§

SandboxImage
The values an image must carry for the agent to run in it.
SandboxImageCommand
Root-owned metadata copied from the base image at bundle creation, never from an exec caller.
SandboxTool
A tool the default sandbox base ships, and the command that shows it runs.

Enums§

Authorization
How the agent decides a caller may be served.
Isolation
How an image ends, and the isolation that ending permits.

Constants§

AGENT_MODE
Mode of the agent binary, owned by 0:0 so the exec uid cannot rewrite its supervisor.
AGENT_PATH
Path the agent binary is installed at inside every sandbox image.
AGENT_PORT
Port the agent serves unless the platform pins another.
AWS_MICROVM
The Lambda MicroVM image, rendered per deployment onto a customer base image.
DEFAULT_SANDBOX_BASE_IMAGE
The image every default sandbox builds on, by index digest so both architectures are pinned.
DEFAULT_SANDBOX_TOOLS
The toolchain of the default sandbox base, and the one list its probes read.
DEFAULT_SANDBOX_UV_IMAGE
The image uv and uvx are copied out of, by index digest.
EXEC_USER
Name of the exec identity’s passwd and group entries.
GCP_AGENT_LOG_FILTER
RUST_LOG for a GCP image, which the agent needs set before it logs anything.
GCP_AGENT_PLATFORM
The GCP Agent Platform image, built once in CI and run with nothing layered on top.
IMAGE_COMMAND_PATH
Installed outside the command-writable session directory.
SESSION_ROOT_MODE
Mode of the session root, which the exec uid owns.

Functions§

contract_env
The ENV block carrying the agent’s configuration contract.
entrypoint
EXPOSE, the image’s ending, and the ENTRYPOINT.
gcp_agent_platform_env
Every variable a GCP Agent Platform image sets: the contract, then RUST_LOG.
identity_setup
The RUN step creating the exec identity and the session root it owns.