Skip to main content

DockerBackend

Struct DockerBackend 

Source
pub struct DockerBackend { /* private fields */ }
Expand description

The remote-Docker compute backend: a connected Engine API client.

Implementations§

Source§

impl DockerBackend

Source

pub fn connect() -> Result<Self, BackendError>

Connect to the Docker daemon configured by the environment (DOCKER_HOST + TLS/SSH vars, or the platform default socket).

Source

pub fn with_client(docker: Docker) -> Self

Wrap an already-connected client (for tests / custom transports).

Source

pub fn with_endpoint(self, endpoint: DockerEndpoint) -> Self

Select how a launched workload’s endpoint is reported (see DockerEndpoint).

Source

pub fn with_writable_root_allowed(self, allowed: bool) -> Self

Allow a spec’s writable_root to relax the read-only root here (single-tenant posture). Off by default, so the multi-tenant guard keeps the hardened root.

Source

pub fn with_cap_add_allowed(self, allowed: bool) -> Self

Allow a spec’s cap_add to add capabilities back on top of the dropped-ALL default here (single-tenant posture). Off by default, so the multi-tenant guard keeps every capability dropped.

Source

pub fn with_volume_mode(self, mode: DockerVolumeMode) -> Self

Select how persistent volumes are backed (see DockerVolumeMode).

Source

pub fn with_data_dir(self, data_dir: impl Into<PathBuf>) -> Self

Set the node data directory used for Bind-mode volume host paths.

Source

pub async fn reachable(&self) -> bool

Whether the daemon answers a ping — used to decide whether to register this backend (a connected client doesn’t imply a reachable daemon).

Trait Implementations§

Source§

impl ComputeBackend for DockerBackend

Source§

fn exec<'life0, 'life1, 'life2, 'life3, 'async_trait>( &'life0 self, handle: &'life1 InstanceHandle, argv: &'life2 [String], stdin: Option<&'life3 [u8]>, ) -> Pin<Box<dyn Future<Output = Result<ExecOutput, BackendError>> + Send + 'async_trait>>
where Self: 'async_trait, 'life0: 'async_trait, 'life1: 'async_trait, 'life2: 'async_trait, 'life3: 'async_trait,

Run a one-shot command inside the running container via the Engine exec API and buffer its output. argv is the command + args (no shell); stdin, when present, is written to the command’s standard input and the stream is then half-closed so the command sees EOF. stdout/stderr are captured to completion, and the command’s exit status is read back from inspect_exec after the output stream ends.

The container name is the one encoded in the handle (falling back to the deterministic boatramp-<workload>-<replica>, mirroring health/stop).

Source§

fn id(&self) -> &'static str

Stable backend id ("vmm" / "container" / "cloudflare" / "docker").
Source§

fn capabilities(&self) -> Capabilities

What this backend can do here (used by the scheduler + policy gate).
Source§

fn materialize<'life0, 'life1, 'async_trait>( &'life0 self, spec: &'life1 ComputeSpec, ) -> Pin<Box<dyn Future<Output = Result<Artifact, BackendError>> + Send + 'async_trait>>
where Self: 'async_trait, 'life0: 'async_trait, 'life1: 'async_trait,

Stage spec’s artifact into whatever this backend boots from. Idempotent + content-addressed (cache/dedup by spec id).
Source§

fn launch<'life0, 'life1, 'async_trait>( &'life0 self, req: &'life1 LaunchRequest, ) -> Pin<Box<dyn Future<Output = Result<Instance, BackendError>> + Send + 'async_trait>>
where Self: 'async_trait, 'life0: 'async_trait, 'life1: 'async_trait,

Launch one replica; returns its handle + routable endpoint.
Source§

fn stop<'life0, 'life1, 'async_trait>( &'life0 self, handle: &'life1 InstanceHandle, ) -> Pin<Box<dyn Future<Output = Result<(), BackendError>> + Send + 'async_trait>>
where Self: 'async_trait, 'life0: 'async_trait, 'life1: 'async_trait,

Stop + clean up a replica (idempotent; safe on a half-launched instance).
Source§

fn health<'life0, 'life1, 'async_trait>( &'life0 self, handle: &'life1 InstanceHandle, ) -> Pin<Box<dyn Future<Output = Result<Health, BackendError>> + Send + 'async_trait>>
where Self: 'async_trait, 'life0: 'async_trait, 'life1: 'async_trait,

Liveness/readiness of a running replica.
Source§

fn reserve_in_use<'life0, 'life1, 'async_trait>( &'life0 self, _replicas: &'life1 [(String, String, u32, Ipv4Addr)], ) -> Pin<Box<dyn Future<Output = ()> + Send + 'async_trait>>
where 'life0: 'async_trait, 'life1: 'async_trait, Self: 'async_trait,

Adopt the guest IPs already assigned to persisted/running replicas of this backend, so a fresh-on-boot IP pool reflects addresses in use before it hands out any new one. Called once at node startup with every known replica as (project, workload, replica, endpoint_ip); the backend reserves the ones it owns (those in its own subnet), skipping the rest, and remembers each replica’s address — keyed by (project, workload, replica) so two projects’ same-named workloads never share a slot — so a relaunch reclaims the same endpoint (stable) rather than a fresh one. Without this a backend that rebuilds its pool each process start (the native container backend) could re-hand a live address to a different workload — the container-IP collision. Backends that don’t own a per-node IP pool (docker / cloudflare delegate addressing) default to a no-op, so they are unaffected.
Source§

fn gc_ip_pool<'life0, 'life1, 'async_trait>( &'life0 self, _parked: &'life1 [(String, String, u32)], ) -> Pin<Box<dyn Future<Output = ()> + Send + 'async_trait>>
where 'life0: 'async_trait, 'life1: 'async_trait, Self: 'async_trait,

Reconcile the IP pool against reality (A2): reclaim addresses this backend still holds for replicas whose container is actually gone. Adoption reserves the IP of every persisted replica at boot; a replica whose container has since crashed (or whose state was removed out-of-band) would otherwise keep its IP reserved for the life of the process, slowly leaking the pool. This is called periodically with parked — the (project, workload, replica) keys that are intentionally down (scale-to-zero Zero) and MUST keep their IP for the wake — so the backend releases only the addresses it holds for a key that is neither live (no running container) nor parked. Backends without a per-node IP pool default to a no-op. Conservative by construction: a key is reclaimed only when the backend is sure the container is gone.
Source§

fn snapshot<'life0, 'life1, 'async_trait>( &'life0 self, _handle: &'life1 InstanceHandle, ) -> Pin<Box<dyn Future<Output = Result<Option<Snapshot>, BackendError>> + Send + 'async_trait>>
where 'life0: 'async_trait, 'life1: 'async_trait, Self: 'async_trait,

Snapshot a replica for scale-to-zero (backends that support it).
Source§

fn restore<'life0, 'life1, 'async_trait>( &'life0 self, _snapshot: &'life1 Snapshot, ) -> Pin<Box<dyn Future<Output = Result<Instance, BackendError>> + Send + 'async_trait>>
where 'life0: 'async_trait, 'life1: 'async_trait, Self: 'async_trait,

Restore a snapshotted replica.
Source§

fn list_volumes<'life0, 'async_trait>( &'life0 self, ) -> Pin<Box<dyn Future<Output = Result<Vec<VolumeInfo>, BackendError>> + Send + 'async_trait>>
where 'life0: 'async_trait, Self: 'async_trait,

List this backend’s persistent volumes (the host-side backing for a spec’s VolumeRefs). Only the backends that own an on-node volume directory implement it (the native container backend, under <data_dir>/compute/volumes/<name>); the rest return the empty default, so a listing across a mixed fleet simply omits them. Backs the operator GET /api/compute/volumes volume-reclamation surface.
Source§

fn remove_volume<'life0, 'life1, 'async_trait>( &'life0 self, _name: &'life1 str, ) -> Pin<Box<dyn Future<Output = Result<bool, BackendError>> + Send + 'async_trait>>
where 'life0: 'async_trait, 'life1: 'async_trait, Self: 'async_trait,

Remove the backing for persistent volume name, returning whether it existed. Only the backends that own an on-node volume directory implement it (native container); the rest return BackendError::Unsupported. The caller (the node volume capability) refuses to remove a volume still referenced by a registered workload’s spec unless forced — see ComputeVolumes. Backs DELETE /api/compute/volumes/{name}.

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more