Skip to main content

SandboxSpec

Struct SandboxSpec 

Source
pub struct SandboxSpec {
Show 32 fields pub name: Option<String>, pub image: String, pub instance_type: InstanceType, pub storage: Option<String>, pub cpus: Option<String>, pub cpuset: Option<String>, pub memory: Option<String>, pub privileged: Option<bool>, pub idmap: Option<IdmapSpec>, pub profiles: Option<Vec<String>>, pub labels: BTreeMap<String, String>, pub env: Environment, pub volumes: Vec<VolumeSpec>, pub ports: Vec<PortSpec>, pub ready: Option<Vec<ReadyCheck>>, pub ready_timeout: Option<String>, pub user: Option<String>, pub working_dir: Option<String>, pub exec: ExecSpec, pub command: Option<Vec<String>>, pub entrypoint: Option<Vec<String>>, pub restart: Option<RestartMode>, pub healthcheck: Option<Healthcheck>, pub depends_on: BTreeMap<String, Dependency>, pub deploy: Option<Deploy>, pub domains: Vec<DomainSpec>, pub secrets: Vec<SecretRef>, pub egress: Option<EgressSpec>, pub raw_config: BTreeMap<String, String>, pub raw_devices: BTreeMap<String, BTreeMap<String, String>>, pub workspace_nesting: bool, pub stack_udp: bool,
}
Expand description

Everything about one sandbox: a compose service.

Fields§

§name: Option<String>

incus instance name: at most 63 characters of [a-z0-9-] (case-insensitive), starting with a letter. In a compose file it defaults to <project>-<service>.

§image: String

Image: a local alias or fingerprint (dev-base), or remote:alias for a well-known remote (images:debian/12, ubuntu:24.04). A local alias that does not exist is an error before anything is created.

§instance_type: InstanceType

container (default) or virtual-machine (vm). Fixed at creation.

A VM is a stronger boundary (its own kernel) at the cost of boot time and memory. Container-only settings are refused for a VM: privileged, and any explicit idmap (idmap: auto is a no-op there). Host paths are shared into a VM over virtiofs, where inotify from host edits is not delivered, so file watchers inside the VM need polling. Proxies into a VM must be host-bound, and incus runs them in NAT mode (nat: true, set automatically); bind: guest is not available for VMs.

§storage: Option<String>

Storage pool for the root disk. auto (default): incus-zfs if it exists, else default, else the first pool. Fixed at creation.

§cpus: Option<String>

Number of CPUs (limits.cpu), a whole number like 8.

§cpuset: Option<String>

CPUs to pin to (limits.cpu), e.g. 0-3 or 0,2. Excludes cpus.

§memory: Option<String>

Memory limit (limits.memory): docker units (512m, 8g, bytes) or incus ones (8GiB, 50%).

§privileged: Option<bool>

Run privileged (security.privileged). Omit to leave the incus default (unprivileged); false pins it explicitly.

§idmap: Option<IdmapSpec>

uid/gid mapping so a host user can write bind mounts. See IdmapSpec.

§profiles: Option<Vec<String>>

incus profiles to apply, in order. Default: [default]. Fixed at creation.

§labels: BTreeMap<String, String>

Labels, stored as user.<key> config keys: a map, or a list of KEY=VALUE. Used by isb ls --label and isb prune. isb never removes a label it was not told about.

§env: Environment

Instance environment (environment.<KEY>), seen by every exec: a map, or a list of KEY=VALUE. A plain value is instance config, readable by anyone who can read the instance. KEY: {secret: NAME} delivers the top-level secret NAME as the variable (docs/guides/secrets.md).

§volumes: Vec<VolumeSpec>

Mounts: SOURCE:TARGET[:OPTIONS] or the long form. A source starting with /, . or ~ is a host path; anything else is a named volume.

§ports: Vec<PortSpec>

Published ports ([HOST_IP:]PUBLISHED:TARGET[/PROTOCOL] or the long form), and incus proxies in either direction (listen/connect).

§ready: Option<Vec<ReadyCheck>>

Readiness checks, run in order after every start/ensure. Default: [running] for a container, [running, agent] for a VM.

§ready_timeout: Option<String>

Deadline for all readiness checks together, e.g. 90s. Default: 60s for a container, 300s for a VM.

§user: Option<String>

Guest user for command, isb exec and path_writable: a name (dev), uid, uid:gid or name:group. Default root.

§working_dir: Option<String>

Working directory for command and isb exec. Default: the user’s home.

§exec: ExecSpec

More exec defaults: an exec-only environment and the login shell.

§command: Option<Vec<String>>

The sandbox’s main command, run by a foreground isb up once the sandbox is ready, as user in working_dir. Its output is streamed, and up stops the sandbox when every command has exited. A list is argv; a string is split like a shell would split it, without running one. Never part of the instance, so changing it is not drift.

§entrypoint: Option<Vec<String>>

OCI images only: the entrypoint, run with command as its arguments. On an OCI image command alone replaces the whole command line, including the image’s own entrypoint.

§restart: Option<RestartMode>

no (default), always, on-failure or unless-stopped. Anything but no makes the service long-running: the instance starts with the host (boot.autostart), and command is supervised inside the guest (a systemd unit, or the instance itself for an OCI image) instead of being held open by isb up, so it survives isb exiting.

§healthcheck: Option<Healthcheck>

A recurring health test, as in docker compose. isb stack deploy routes traffic only to healthy replicas and replaces unhealthy ones; depends_on can wait for it.

§depends_on: BTreeMap<String, Dependency>

Services to bring up first: a list, or a map to {condition: service_started | service_healthy}.

§deploy: Option<Deploy>

Replicas, rolling updates and restart policy for isb stack deploy.

§domains: Vec<DomainSpec>

Public hostnames isb serve’s ingress routes to this service’s replicas (docs/guides/domains.md). Only stacks use them; isb up ignores them.

§secrets: Vec<SecretRef>

Secrets (top-level secrets:) to write under /run/secrets in the guest: names, or {source, target, uid, gid, mode}.

§egress: Option<EgressSpec>

Which hostnames the sandbox may reach, and secrets that never enter it (docs/guides/egress.md). none denies all network; a list of host[:port] (port 443 by default; *.example.com for subdomains) denies everything else, public and private; {allow, secrets} adds secrets the guest sees only as placeholders, put on the wire towards their approved hosts. Omitted: open egress, as before. Needs isb serve running for its proxy.

§raw_config: BTreeMap<String, String>

Extra instance config keys, set verbatim (escape hatch).

§raw_devices: BTreeMap<String, BTreeMap<String, String>>

Extra devices, set verbatim (escape hatch). Keys are device names.

§workspace_nesting: bool

Nesting keys allowed: only the daemon sets it, for a workspace (crate::org::nesting).

§stack_udp: bool

UDP proxy devices allowed: only the stack controller sets it, for a replica’s published UDP ports (crate::org::check_proxies).

Implementations§

Source§

impl SandboxSpec

Source

pub fn new(name: impl Into<String>, image: impl Into<String>) -> Self

Source

pub fn cpus(self, cpus: impl ToString) -> Self

Source

pub fn cpuset(self, set: impl Into<String>) -> Self

Source

pub fn memory(self, m: impl Into<String>) -> Self

Source

pub fn storage(self, pool: impl Into<String>) -> Self

Source

pub fn idmap(self, idmap: IdmapSpec) -> Self

Source

pub fn privileged(self, p: bool) -> Self

Source

pub fn label(self, k: impl Into<String>, v: impl Into<String>) -> Self

Source

pub fn env(self, k: impl Into<String>, v: impl Into<String>) -> Self

Source

pub fn egress(self, e: EgressSpec) -> Self

Restrict the sandbox’s network: see crate::egress::EgressSpec.

Source

pub fn volume(self, guest_path: impl Into<String>, vol: VolumeSpec) -> Self

Mount vol at guest_path.

Source

pub fn port(self, p: PortSpec) -> Self

Source

pub fn ready(self, checks: Vec<ReadyCheck>) -> Self

Source

pub fn ready_timeout(self, t: impl Into<String>) -> Self

Source

pub fn user(self, u: impl Into<String>) -> Self

Source

pub fn working_dir(self, c: impl Into<String>) -> Self

Source

pub fn raw_config(self, k: impl Into<String>, v: impl Into<String>) -> Self

Source

pub fn raw_device( self, name: impl Into<String>, props: BTreeMap<String, String>, ) -> Self

Source§

impl SandboxSpec

Source

pub fn exec_defaults(&self) -> ExecDefaults

The exec defaults this spec implies: user, working_dir and exec.

Source§

impl SandboxSpec

Source

pub fn secret_keys(&self) -> BTreeSet<&str>

Every top-level secret the service uses, as a file or a variable.

Source

pub fn long_running(&self) -> bool

restart is set to something that keeps the service running.

Source

pub fn replicas(&self) -> u32

deploy.replicas, default 1.

Source

pub fn health_probe(&self) -> Result<Option<HealthProbe>, String>

The health probe, if any.

Trait Implementations§

Source§

impl Clone for SandboxSpec

Source§

fn clone(&self) -> Self

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for SandboxSpec

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Default for SandboxSpec

Source§

fn default() -> Self

Returns the “default value” for a type. Read more
Source§

impl<'de> Deserialize<'de> for SandboxSpec

Source§

fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>
where __D: Deserializer<'de>,

Deserialize this value from the given Serde deserializer. Read more
Source§

impl JsonSchema for SandboxSpec

Source§

fn schema_name() -> Cow<'static, str>

The name of the generated JSON Schema. Read more
Source§

fn schema_id() -> Cow<'static, str>

Returns a string that uniquely identifies the schema produced by this type. Read more
Source§

fn json_schema(generator: &mut SchemaGenerator) -> Schema

Generates a JSON Schema for this type. Read more
Source§

fn inline_schema() -> bool

Whether JSON Schemas generated for this type should be included directly in parent schemas, rather than being re-used where possible using the $ref keyword. Read more
Source§

impl PartialEq for SandboxSpec

Source§

fn eq(&self, other: &Self) -> bool

Equality operator ==. Read more
1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Inequality operator !=. Read more
Source§

impl Serialize for SandboxSpec

Source§

fn serialize<__S>(&self, __serializer: __S) -> Result<__S::Ok, __S::Error>
where __S: Serializer,

Serialize this value into the given Serde serializer. Read more
Source§

impl StructuralPartialEq for SandboxSpec

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> AnyEq for T
where T: Any + PartialEq,

Source§

fn equals(&self, other: &(dyn Any + 'static)) -> bool

Source§

fn as_any(&self) -> &(dyn Any + 'static)

Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> DeserializeOwned for T
where T: for<'de> Deserialize<'de>,

Source§

impl<T> DynClone for T
where T: Clone,

Source§

fn __clone_box(&self, _: Private) -> *mut ()

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V