pub struct ContextIsolation { /* private fields */ }Expand description
Context Isolation Manager
Manages sandboxed execution environments for agents with:
- Resource limit enforcement
- Tool permission management
- Sandbox lifecycle management
- Automatic cleanup of expired sandboxes
Implementations§
Source§impl ContextIsolation
impl ContextIsolation
Sourcepub fn create_sandbox(
&mut self,
context: AgentContext,
agent_id: Option<String>,
restrictions: Option<SandboxRestrictions>,
) -> SandboxedContext
pub fn create_sandbox( &mut self, context: AgentContext, agent_id: Option<String>, restrictions: Option<SandboxRestrictions>, ) -> SandboxedContext
Create a new sandbox for an agent context
Sourcepub fn create_sandbox_with_ttl(
&mut self,
context: AgentContext,
agent_id: Option<String>,
restrictions: Option<SandboxRestrictions>,
ttl: Duration,
) -> SandboxedContext
pub fn create_sandbox_with_ttl( &mut self, context: AgentContext, agent_id: Option<String>, restrictions: Option<SandboxRestrictions>, ttl: Duration, ) -> SandboxedContext
Create a sandbox with expiration
Sourcepub fn get_sandbox(&self, sandbox_id: &str) -> Option<&SandboxedContext>
pub fn get_sandbox(&self, sandbox_id: &str) -> Option<&SandboxedContext>
Get a sandbox by ID
Sourcepub fn get_sandbox_mut(
&mut self,
sandbox_id: &str,
) -> Option<&mut SandboxedContext>
pub fn get_sandbox_mut( &mut self, sandbox_id: &str, ) -> Option<&mut SandboxedContext>
Get a mutable sandbox by ID
Sourcepub fn get_isolated_context(&self, agent_id: &str) -> Option<&AgentContext>
pub fn get_isolated_context(&self, agent_id: &str) -> Option<&AgentContext>
Get the isolated context for an agent
Sourcepub fn get_sandbox_by_agent(&self, agent_id: &str) -> Option<&SandboxedContext>
pub fn get_sandbox_by_agent(&self, agent_id: &str) -> Option<&SandboxedContext>
Get sandbox by agent ID
Sourcepub fn get_sandbox_by_agent_mut(
&mut self,
agent_id: &str,
) -> Option<&mut SandboxedContext>
pub fn get_sandbox_by_agent_mut( &mut self, agent_id: &str, ) -> Option<&mut SandboxedContext>
Get mutable sandbox by agent ID
Sourcepub fn update_sandbox(
&mut self,
sandbox_id: &str,
updates: ContextUpdate,
) -> AgentContextResult<()>
pub fn update_sandbox( &mut self, sandbox_id: &str, updates: ContextUpdate, ) -> AgentContextResult<()>
Update a sandbox’s context
Sourcepub fn is_tool_allowed(&self, sandbox_id: &str, tool_name: &str) -> bool
pub fn is_tool_allowed(&self, sandbox_id: &str, tool_name: &str) -> bool
Check if a tool is allowed in a sandbox
Sourcepub fn suspend(&mut self, sandbox_id: &str) -> AgentContextResult<()>
pub fn suspend(&mut self, sandbox_id: &str) -> AgentContextResult<()>
Suspend a sandbox
Sourcepub fn resume(&mut self, sandbox_id: &str) -> AgentContextResult<()>
pub fn resume(&mut self, sandbox_id: &str) -> AgentContextResult<()>
Resume a suspended sandbox
Sourcepub fn terminate(&mut self, sandbox_id: &str) -> AgentContextResult<()>
pub fn terminate(&mut self, sandbox_id: &str) -> AgentContextResult<()>
Terminate a sandbox
Sourcepub fn cleanup_expired(&mut self) -> usize
pub fn cleanup_expired(&mut self) -> usize
Cleanup all expired sandboxes Returns the number of sandboxes cleaned up
Sourcepub fn list_sandbox_ids(&self) -> Vec<String>
pub fn list_sandbox_ids(&self) -> Vec<String>
Get all sandbox IDs
Sourcepub fn list_sandboxes_by_state(
&self,
state: SandboxState,
) -> Vec<&SandboxedContext>
pub fn list_sandboxes_by_state( &self, state: SandboxState, ) -> Vec<&SandboxedContext>
Get all sandboxes in a specific state
Sourcepub fn sandbox_count(&self) -> usize
pub fn sandbox_count(&self) -> usize
Get sandbox count
Sourcepub fn active_sandbox_count(&self) -> usize
pub fn active_sandbox_count(&self) -> usize
Get active sandbox count
Trait Implementations§
Source§impl Debug for ContextIsolation
impl Debug for ContextIsolation
Source§impl Default for ContextIsolation
impl Default for ContextIsolation
Source§fn default() -> ContextIsolation
fn default() -> ContextIsolation
Returns the “default value” for a type. Read more
Auto Trait Implementations§
impl Freeze for ContextIsolation
impl RefUnwindSafe for ContextIsolation
impl Send for ContextIsolation
impl Sync for ContextIsolation
impl Unpin for ContextIsolation
impl UnsafeUnpin for ContextIsolation
impl UnwindSafe for ContextIsolation
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more
Source§impl<T> FutureExt for T
impl<T> FutureExt for T
Source§fn with_context(self, otel_cx: Context) -> WithContext<Self>
fn with_context(self, otel_cx: Context) -> WithContext<Self>
Source§fn with_current_context(self) -> WithContext<Self>
fn with_current_context(self) -> WithContext<Self>
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self>
fn instrument(self, span: Span) -> Instrumented<Self>
Source§fn in_current_span(self) -> Instrumented<Self>
fn in_current_span(self) -> Instrumented<Self>
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
Converts
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
Converts
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§impl<T> IntoRequest<T> for T
impl<T> IntoRequest<T> for T
Source§fn into_request(self) -> Request<T>
fn into_request(self) -> Request<T>
Wrap the input message
T in a tonic::RequestCreates a shared type from an unshared type.
Source§impl<T> Pipe for Twhere
T: ?Sized,
impl<T> Pipe for Twhere
T: ?Sized,
Source§fn pipe<R>(self, func: impl FnOnce(Self) -> R) -> Rwhere
Self: Sized,
fn pipe<R>(self, func: impl FnOnce(Self) -> R) -> Rwhere
Self: Sized,
Pipes by value. This is generally the method you want to use. Read more
Source§fn pipe_ref<'a, R>(&'a self, func: impl FnOnce(&'a Self) -> R) -> Rwhere
R: 'a,
fn pipe_ref<'a, R>(&'a self, func: impl FnOnce(&'a Self) -> R) -> Rwhere
R: 'a,
Borrows
self and passes that borrow into the pipe function. Read moreSource§fn pipe_ref_mut<'a, R>(&'a mut self, func: impl FnOnce(&'a mut Self) -> R) -> Rwhere
R: 'a,
fn pipe_ref_mut<'a, R>(&'a mut self, func: impl FnOnce(&'a mut Self) -> R) -> Rwhere
R: 'a,
Mutably borrows
self and passes that borrow into the pipe function. Read moreSource§fn pipe_borrow<'a, B, R>(&'a self, func: impl FnOnce(&'a B) -> R) -> R
fn pipe_borrow<'a, B, R>(&'a self, func: impl FnOnce(&'a B) -> R) -> R
Source§fn pipe_borrow_mut<'a, B, R>(
&'a mut self,
func: impl FnOnce(&'a mut B) -> R,
) -> R
fn pipe_borrow_mut<'a, B, R>( &'a mut self, func: impl FnOnce(&'a mut B) -> R, ) -> R
Source§fn pipe_as_ref<'a, U, R>(&'a self, func: impl FnOnce(&'a U) -> R) -> R
fn pipe_as_ref<'a, U, R>(&'a self, func: impl FnOnce(&'a U) -> R) -> R
Borrows
self, then passes self.as_ref() into the pipe function.Source§fn pipe_as_mut<'a, U, R>(&'a mut self, func: impl FnOnce(&'a mut U) -> R) -> R
fn pipe_as_mut<'a, U, R>(&'a mut self, func: impl FnOnce(&'a mut U) -> R) -> R
Mutably borrows
self, then passes self.as_mut() into the pipe
function.Source§fn pipe_deref<'a, T, R>(&'a self, func: impl FnOnce(&'a T) -> R) -> R
fn pipe_deref<'a, T, R>(&'a self, func: impl FnOnce(&'a T) -> R) -> R
Borrows
self, then passes self.deref() into the pipe function.Source§impl<T> Pointable for T
impl<T> Pointable for T
Source§impl<T> PolicyExt for Twhere
T: ?Sized,
impl<T> PolicyExt for Twhere
T: ?Sized,
Source§impl<T> Tap for T
impl<T> Tap for T
Source§fn tap_borrow<B>(self, func: impl FnOnce(&B)) -> Self
fn tap_borrow<B>(self, func: impl FnOnce(&B)) -> Self
Immutable access to the
Borrow<B> of a value. Read moreSource§fn tap_borrow_mut<B>(self, func: impl FnOnce(&mut B)) -> Self
fn tap_borrow_mut<B>(self, func: impl FnOnce(&mut B)) -> Self
Mutable access to the
BorrowMut<B> of a value. Read moreSource§fn tap_ref<R>(self, func: impl FnOnce(&R)) -> Self
fn tap_ref<R>(self, func: impl FnOnce(&R)) -> Self
Immutable access to the
AsRef<R> view of a value. Read moreSource§fn tap_ref_mut<R>(self, func: impl FnOnce(&mut R)) -> Self
fn tap_ref_mut<R>(self, func: impl FnOnce(&mut R)) -> Self
Mutable access to the
AsMut<R> view of a value. Read moreSource§fn tap_deref<T>(self, func: impl FnOnce(&T)) -> Self
fn tap_deref<T>(self, func: impl FnOnce(&T)) -> Self
Immutable access to the
Deref::Target of a value. Read moreSource§fn tap_deref_mut<T>(self, func: impl FnOnce(&mut T)) -> Self
fn tap_deref_mut<T>(self, func: impl FnOnce(&mut T)) -> Self
Mutable access to the
Deref::Target of a value. Read moreSource§fn tap_dbg(self, func: impl FnOnce(&Self)) -> Self
fn tap_dbg(self, func: impl FnOnce(&Self)) -> Self
Calls
.tap() only in debug builds, and is erased in release builds.Source§fn tap_mut_dbg(self, func: impl FnOnce(&mut Self)) -> Self
fn tap_mut_dbg(self, func: impl FnOnce(&mut Self)) -> Self
Calls
.tap_mut() only in debug builds, and is erased in release
builds.Source§fn tap_borrow_dbg<B>(self, func: impl FnOnce(&B)) -> Self
fn tap_borrow_dbg<B>(self, func: impl FnOnce(&B)) -> Self
Calls
.tap_borrow() only in debug builds, and is erased in release
builds.Source§fn tap_borrow_mut_dbg<B>(self, func: impl FnOnce(&mut B)) -> Self
fn tap_borrow_mut_dbg<B>(self, func: impl FnOnce(&mut B)) -> Self
Calls
.tap_borrow_mut() only in debug builds, and is erased in release
builds.Source§fn tap_ref_dbg<R>(self, func: impl FnOnce(&R)) -> Self
fn tap_ref_dbg<R>(self, func: impl FnOnce(&R)) -> Self
Calls
.tap_ref() only in debug builds, and is erased in release
builds.Source§fn tap_ref_mut_dbg<R>(self, func: impl FnOnce(&mut R)) -> Self
fn tap_ref_mut_dbg<R>(self, func: impl FnOnce(&mut R)) -> Self
Calls
.tap_ref_mut() only in debug builds, and is erased in release
builds.Source§fn tap_deref_dbg<T>(self, func: impl FnOnce(&T)) -> Self
fn tap_deref_dbg<T>(self, func: impl FnOnce(&T)) -> Self
Calls
.tap_deref() only in debug builds, and is erased in release
builds.