Expand description
isb’s foundation: the incus client, the sandbox spec and planner, compose projects, stacks, orgs, the local registry and ingress.
This is an internal crate of isb, which re-exports
every module here under its own name: depend on isb, not on this.
Re-exports§
pub use client::Client;pub use client::Timeouts;pub use compose::LoadOptions;pub use compose::Project;pub use error::Error;pub use error::Result;pub use exec::ExecController;pub use exec::ExecEvent;pub use exec::ExecOptions;pub use exec::ExecOutput;pub use exec::ExecStream;pub use exec::Stdin;pub use plan::Action;pub use plan::DiffOptions;pub use plan::SandboxPlan;pub use sandbox::ApplyReport;pub use sandbox::EnsureOptions;pub use sandbox::LabelFilter;pub use sandbox::Sandbox;pub use sandbox::SandboxInfo;pub use spec::ComposeFile;pub use spec::ExecDefaults;pub use spec::IdmapMap;pub use spec::IdmapMode;pub use spec::IdmapRaw;pub use spec::IdmapSpec;pub use spec::InstanceType;pub use spec::NamedVolumeSpec;pub use spec::PortBind;pub use spec::PortBinding;pub use spec::PortSpec;pub use spec::ReadyCheck;pub use spec::SandboxSpec;pub use spec::Volume;pub use spec::VolumeSpec;
Modules§
- balance
- An L4 (TCP) load balancer for published ports.
- client
- A small, synchronous incusd REST client over the local unix socket.
- compose
- Loading compose files:
-f a.yaml -f b.yaml, interpolation, defaults. - cron
- Cron schedules: the five-field form (
minute hour day-of-month month day-of-week) and the@hourly-style aliases, evaluated in UTC or a fixed offset from it. - discovery
- Service discovery: stable DNS names for a stack’s services inside an org.
- egress
- Per-sandbox egress policy: an allowlist of
host[:port]a sandbox may reach, and secrets that never enter the guest. - error
- exec
- Running commands in a sandbox over the incus exec websocket API.
- foreground
- Foreground
isb up: run each sandbox’scommand, stream its output, and stop the sandboxes when it is over. - idmap
- Deciding whether a sandbox needs
raw.idmap. - ingress
- Ingress: public hostnames for stack services (docs/guides/domains.md).
- interp
- Compose-style variable interpolation.
- lock
- Per-sandbox lock, so two concurrent
up/ensurecalls do not both create. - machine
isb machine: incus runs only on Linux, so on macOS isb manages a Lima VM that runs it, the waypodman machinedoes.- metrics
- Live numbers for dashboards: the host’s CPU, memory and storage, and every instance’s status, address, CPU, memory and disk, each with a short history for sparklines.
- metrics_
history - Metrics history: the sampler’s per-instance CPU, memory, network and disk numbers, kept for a month in downsampling tiers, per org, across daemon restarts.
- net
- Outbound connections held to an address policy (notifications, and whatever else dials an address an org member chose).
- org
- Orgs: the trust boundary. An org is an incus project; its people and agents fully administer what is in it, and nothing crosses orgs.
- plan
- Resolve a spec into desired incus state, and diff it against actual state.
- registry
- The local OCI registry: where builds push and incus pulls.
- rpc
isb rpc: the protocol the language SDKs speak.- sandbox
- The sandbox API and the apply engine.
- secrets
- Secrets: named values per org, behind pluggable drivers.
- self_
update isb update: replace the running isb with a release from GitHub.- serve_
client - Calling
isb servetools from the CLI over its unix socket. - shorthand
- Command-line shorthands for mounts, ports, labels and readiness checks.
- spec
- The one spec model shared by the library API, the CLI and the compose YAML.
- stack
- Stacks: a compose file deployed to the
isb servedaemon, which keeps it running the way docker swarm keeps a stack running, on one host. - supervise
- Long-running services: the app is supervised inside the guest, never held
open by an isb process, so it outlives
isb up, a daemon restart or an isb upgrade. - volume
- Named custom storage volumes.
Functions§
- parse_
duration - Parse
90,90s,5m,1h,90d,1500msinto a duration.