Expand description
§isb: declarative incus sandboxes
A library, a CLI and a compose-style YAML format for incus containers (and
VMs) used as sandboxes. isb talks to incusd over its unix socket, never through
the incus binary, so every request has a deadline and every stall is reported
as the step that stalled.
use isb::{Client, Sandbox, SandboxSpec, Volume, PortBinding, ReadyCheck};
let client = Client::new();
let spec = SandboxSpec::new("dev-web", "dev-base")
.cpus(8)
.memory("8GiB")
.label("app", "web")
.volume("/home/dev/src", Volume::bind("./src").device("src"))
.volume("/home/dev/.cache", Volume::named("dev-cache").owner("dev"))
.port(PortBinding::host("tcp:127.0.0.1:5173", "tcp:127.0.0.1:5173"))
.ready(vec![ReadyCheck::Running, ReadyCheck::DefaultRoute]);
// Creates it if missing; otherwise changes only what differs.
let sb = Sandbox::connect_or_create(&client, &spec)?;
let out = sb.exec(["uname", "-a"])?;
println!("{}", out.stdout_text());The spec model (spec) is shared by the library, the CLI flags and the
YAML, and plan turns a spec plus the instance’s actual state into the
minimal set of changes. A device that is already correct is never touched.
Modules§
- app
- Applications: the Dokploy-style object over stacks.
- audit
- The audit log: who did what, where, through which door, and how it went.
- auth
- Identity for
isb serve: users, org memberships and roles, browser sessions, invitations, API tokens and password resets, in SQLite at<state>/isb.db. - backup
- Database backups to S3-compatible storage, and restores from them.
- balance
- An L4 (TCP) load balancer for published ports.
- build
- Builds: turn a source tree into an OCI image in the org’s registry.
- client
- A small, synchronous incusd REST client over the local unix socket.
- compose
- Loading compose files:
-f a.yaml -f b.yaml, interpolation, defaults. - cron
- Cron schedules: the five-field form (
minute hour day-of-month month day-of-week) and the@hourly-style aliases, evaluated in UTC or a fixed offset from it. - daemon
isb serve: the stack controller behind an MCP server.- discovery
- Service discovery: stable DNS names for a stack’s services inside an org.
- egress
- Per-sandbox egress policy: an allowlist of
host[:port]a sandbox may reach, and secrets that never enter the guest. - egress_
proxy - isb’s per-sandbox egress proxy: hostname allowlists, and secrets that never enter the guest.
- error
- exec
- Running commands in a sandbox over the incus exec websocket API.
- foreground
- Foreground
isb up: run each sandbox’scommand, stream its output, and stop the sandboxes when it is over. - history
- The history: everything that happened to what isb runs, kept so the current state can always be traced back.
- idmap
- Deciding whether a sandbox needs
raw.idmap. - image_
check - Does a remote image exist? Asked before an app or a stack service names one, so a typo is refused up front instead of deployed into a replica that fails to pull, and asked again at each deploy, where its answer is also the digest the image is pinned to.
- ingress
- Ingress: public hostnames for stack services (docs/guides/domains.md).
- interp
- Compose-style variable interpolation.
- jobs
- Scheduled jobs: a command run on a cron schedule against an app or a stack service of an org.
- lock
- Per-sandbox lock, so two concurrent
up/ensurecalls do not both create. - machine
isb machine: incus runs only on Linux, so on macOS isb manages a Lima VM that runs it, the waypodman machinedoes.- metrics
- Live numbers for dashboards: the host’s CPU, memory and storage, and every instance’s status, address, CPU, memory and disk, each with a short history for sparklines.
- metrics_
history - Metrics history: the sampler’s per-instance CPU, memory, network and disk numbers, kept for a month in downsampling tiers, per org, across daemon restarts.
- monitor
- Uptime monitors: what users see of an org’s apps, checked from outside the app every interval, with history, incidents and notifications.
- net
- Outbound connections held to an address policy (notifications, and whatever else dials an address an org member chose).
- notify
- Notifications: per-org channels (webhook, Slack, Discord, Telegram,
email) told about events of chosen kinds (
deploy.*,health.*,backup.*,job.*,cert.*,monitor.*; seecrate::stack::controller::Event). - org
- Orgs: the trust boundary. An org is an incus project; its people and agents fully administer what is in it, and nothing crosses orgs.
- owner
- A named volume’s mount point: its owner and mode, set from the host.
- plan
- Resolve a spec into desired incus state, and diff it against actual state.
- registry
- The local OCI registry: where builds push and incus pulls.
- rpc
isb rpc: the protocol the language SDKs speak.- s3
- A small S3 client for backups: AWS Signature Version 4 over ring and ureq, no SDK.
- sandbox
- The sandbox API and the apply engine.
- secrets
- Secrets: named values per org, behind pluggable drivers.
- self_
update isb update: replace the running isb with a release from GitHub.- server
isb serve: the MCP server layer, with the tools supplied by the embedder.- servers
- Remote servers (P5.1, P5.2): a control plane places orgs on other hosts,
each running incus and
isb serve --agent, and forwards their calls over mutual TLS. Federation, not incus clustering: every server is a whole isb (controller, ingress, registry, builds, secrets) for the orgs on it. See docs/guides/servers.md. - sftp
- Just enough SFTP (version 3) to stat, chown and chmod a path inside an
instance through incus’
/1.0/instances/NAME/sftp. - shorthand
- Command-line shorthands for mounts, ports, labels and readiness checks.
- spec
- The one spec model shared by the library API, the CLI and the compose YAML.
- stack
- Stacks: a compose file deployed to the
isb servedaemon, which keeps it running the way docker swarm keeps a stack running, on one host. - supervise
- Long-running services: the app is supervised inside the guest, never held
open by an isb process, so it outlives
isb up, a daemon restart or an isb upgrade. - template
- Templates: one-click apps.
- tui
isb tui: a terminal dashboard for stacks and sandboxes.- volume
- Named custom storage volumes.
- volume_
backup - Snapshots, backups and staged restores of an org’s named volumes: an
app’s
<app>_<NAME>, a database’s data, a workspace’s home. Generic over “a custom volume in the org’s incus project”;crate::volumeis the raw incus helper underneath. - web
- The web UI, embedded at build time (see
build.rs) and served byisb serveon its TCP listener. - workspace
- Workspaces (docs/concepts/workspaces.md): an org’s long-lived machine, where its people and agents work, and the rules for the short-lived sandboxes beside it.
Structs§
- Apply
Report - What
applydid. - Client
- Connection to incusd.
- Compose
File - A compose file: named volumes plus any number of services, each one sandbox. Mirrors docker compose wherever incus allows.
- Diff
Options - Options for
diff. - Ensure
Options - Options for ensure / up.
- Exec
Controller - A cloneable handle for driving a running command (stdin, signals, window size) from other threads while one thread reads its output.
- Exec
Defaults - Defaults for exec into a sandbox. Per-call options override them.
- Exec
Options - Per-call exec options. Unset fields fall back to the sandbox’s exec defaults.
- Exec
Output - Captured result of
crate::Sandbox::exec. - Exec
Stream - A running command. Iterate it for output;
ExecStream::waitfor the exit code. - Idmap
Map - Idmap
Raw - Label
Filter key(present) orkey=value(equal).- Load
Options - How to load.
- Named
Volume Spec - A named custom storage volume.
- Port
Binding - Port binding builders.
- Port
Spec - An incus proxy device. Written as docker’s
[HOST_IP:]PUBLISHED:TARGET[/PROTOCOL], its long form (PortMappingin the schema), or the incus form (ProxyPort). - Project
- A loaded, interpolated, merged compose project.
- Sandbox
- A handle on one sandbox.
- Sandbox
Info - A summary of an instance, as listed.
- Sandbox
Plan - The plan for one sandbox.
- Sandbox
Spec - Everything about one sandbox: a compose service.
- Timeouts
- Deadlines used by the client. Every request has one; there is no unbounded wait
anywhere except the output of
exec, which by design has no default timeout. - Volume
- Mount builders:
Volume::bind(host),Volume::named(name). - Volume
Spec - A mount. Written as
SOURCE:TARGET[:OPTIONS]or as the long form (VolumeMountin the schema); always serialized in the long form.
Enums§
- Action
- One step of a plan.
- Error
- Everything isb can fail with.
- Exec
Event - A chunk of output, in the order it was produced per stream.
- Idmap
Mode - Idmap
Spec - idmap handling.
- Instance
Type - Instance type.
- Port
Bind - Which side listens.
- Ready
Check - A readiness check. “Running” alone is not ready: networking comes up a beat after the instance does.
- Stdin
- Where the command’s stdin comes from.
Functions§
- parse_
duration - Parse
90,90s,5m,1h,90d,1500msinto a duration.