pub struct SpawnOverrides {
pub provider: SpawnOverride<AgentId>,
pub mode: SpawnOverride<SessionMode>,
pub terminal_size: SpawnOverride<TerminalSize>,
pub prompt: SpawnOverride<SpawnPrompt>,
pub bundle_id: SpawnOverride<SpawnBundleId>,
pub context_id: SpawnOverride<SpawnContextId>,
pub environment_profile_id: SpawnOverride<SpawnEnvironmentProfileId>,
pub approval_level: Option<ApprovalLevel>,
pub network_allowlist: Option<SpawnNetworkAllowlistId>,
pub browser_profile_id: Option<SpawnBrowserProfileId>,
}Expand description
Spawn-time overrides for an accepted SpawnSpec.
Station-profile axes (design ledger): environment_profile_id covers
providerHome bindings; workspace target covers cwd;
approval_level is the partial sandbox axis; optional
network_allowlist + browser_profile_id are the network /
dig2browser browserProfile axes (ids only). See hatchery-websession-docs
plan station-network-and-browser-profile-knobs-2026-10-02.md and research
station-profile-and-os-sandbox-matrix-2026-10-02.md. Secrets stay on
the node; C2 carries ids/receipts only (C2 → node → drivers). Resolve
echoes registered network allowlist ids onto env-profile receipts (empty-
default catalog refuse); dig2browser station IPC bind / reachability
refuse waits on a cheap g4a-local probe (stubbed on node).
Fields§
§provider: SpawnOverride<AgentId>§mode: SpawnOverride<SessionMode>§terminal_size: SpawnOverride<TerminalSize>§prompt: SpawnOverride<SpawnPrompt>§bundle_id: SpawnOverride<SpawnBundleId>§context_id: SpawnOverride<SpawnContextId>§environment_profile_id: SpawnOverride<SpawnEnvironmentProfileId>§approval_level: Option<ApprovalLevel>A plain Option, not a SpawnOverride<ApprovalLevel> like every
field above it: those all have a corresponding field on
SpawnProfileDefaults to inherit from, so Inherit names a real
third state distinct from “cleared” or “set”. A spawn profile
declares no approval level of its own, so there is nothing to
inherit – None already means exactly what Inherit would, “use
the axis default” (ApprovalLevel::FullAuto), so this stays a
two-state Option rather than adding a SpawnOverride variant that
can never resolve against a profile field that does not exist.
network_allowlist: Option<SpawnNetworkAllowlistId>Optional station network allowlist policy id (node-local catalog).
Opaque id only — never credentials. Plan:
station-network-and-browser-profile-knobs-2026-10-02.md §2.1 / §4.
Resolve echoes this onto ResolvedEnvironmentProfileReceipt when the
id is registered in the node-local catalog (empty by default). Empty /
whitespace ids refuse at type construction; unknown ids refuse with
UnknownNetworkAllowlist. Dig2browser bind is separate (browser_profile_id).
browser_profile_id: Option<SpawnBrowserProfileId>Optional dig2browser station browserProfile id (profiles_root).
Id only — never cookie/OAuth/proxy material on C2. Plan:
station-network-and-browser-profile-knobs-2026-10-02.md §2.2 / §4.
Resolve echoes this onto ResolvedEnvironmentProfileReceipt. Station
IPC reachability refuse waits on a cheap g4a-local probe (stubbed).