1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
//! Kubernetes transports for Claude Code CLI.
//!
//! Two providers are available:
//!
//! * [`K8sEphemeralProvider`] - creates a new pod for each invocation, reads logs,
//! then deletes the pod. Simple and isolated but has startup overhead.
//! [`K8sEphemeralProvider::sandboxed`] adds a hardened pod (non-root,
//! read-only root filesystem, secrets from Kubernetes Secrets, managed
//! settings presets, egress profile label, Claude profile ConfigMaps in
//! [`profile`]), cleanup of a previous attempt's pods on retry and of a
//! run's pods before it executes again, and an orphan reaper ([`reap_orphans`]).
//! [`K8sEphemeralProvider::auth_proxy`] routes Claude traffic through an
//! `ironflow-auth-proxy`: the pod gets an opaque per-step token instead of
//! the Claude credential.
//! * [`K8sPersistentProvider`] - reuses a long-running worker pod and executes
//! commands via the Kubernetes exec API. Lower latency but shared state between
//! invocations.
//!
//! Shared types ([`K8sResources`], [`PodHardening`], [`SandboxSettings`]) and
//! helpers live in the [`common`] submodule; the orphan reaping decisions
//! ([`reap_reason`], [`configmap_expired`]) in [`reaper`].
pub use ;
pub use K8sEphemeralProvider;
pub use K8sPersistentProvider;
pub use ;
pub use ;