Skip to main content

Module org

Module org 

Source
Expand description

Orgs: the trust boundary. An org is an incus project; its people and agents fully administer what is in it, and nothing crosses orgs.

Any org x is the incus project isb-x, the default org included (isb-default, which ensure_default creates when the daemon starts). incus’ own default project is never an org: it holds the plain sandboxes isb create and isb up make without --org.

Modules§

disk
Root disk sizes under an org’s disk limit (limits.disk).
nesting
The Docker exception (docs/concepts/security.md#the-docker-exception): an org setting, allow_nesting, that lets the org’s workspace and nothing else run with security.nesting, so Docker works inside it.

Structs§

Budget
One limit of an org: the limit, what its instances are allocated against it (summed over every instance, stopped ones included), and what is left. Bytes for memory and disk.
Egress
An egress exception: a private destination an org may reach despite the default deny. Written CIDR[:PORTS[/PROTO]]: 10.1.2.0/24 (everything there), 100.79.171.47:1080 (one TCP port), 10.1.2.3:53/udp, 10.1.2.3:8000-8100,9000/tcp. A bare address is a /32.
OrgId
A validated org name: [a-z][a-z0-9-]{0,30}, not ending in -.
OrgInfo
An org as it exists in incus.
OrgOptions
Limits for an org as a whole (the incus project’s limits) and the defaults each instance gets when its spec sets none.

Enums§

Limit
One of an org’s limits, which isb org update can lift again.
Names
Where an org stands on service names.

Constants§

DEFAULT_ORG
DEFAULT_ORG_PROJECT
The incus project of the default org.
DEFAULT_ROOT_SIZE
The root disk size isb gives an instance it creates in an org with limits.disk when its spec sets none (incus refuses an instance without one there); see super::disk.
INGRESS_CADDY
How an org’s domains reach it: Caddy’s public listeners (default) or the org’s own Cloudflare Tunnel.
INGRESS_CLOUDFLARE_TUNNEL

Functions§

allow_home
Let the org’s restricted project bind path (and what is under it) as a workspace home, and record it so that the org’s later updates keep it.
allowed_udp
The UDP ports org may publish, as a platform admin listed them. An org that does not exist here may publish none.
bridge_name
The bridge for an org: isbbr + 8 hex digits of the name’s hash, inside the kernel’s 15-character limit on interface names.
check_domain_suffix
Check an allowlist entry: a domain suffix (example.com), or *.example.com to allow wildcard hosts under it too.
check_egress
Exceptions for different networks must not overlap: a port-limited one would otherwise cut into the other. The same network may repeat (its ports add up).
check_exists
Ok when org exists here, else the same “org X not found” as get, without reading the rest of it. For a tool to check before it acts, so an unknown org is refused up front instead of failing halfway on an incus error about a missing project.
check_proxies
Refuse proxy devices in an org project’s instance, except a stack replica’s UDP ports, which only the stack controller makes (crate::spec::SandboxSpec::stack_udp, which no spec, compose file or tool argument can set): host-bound, NAT mode, UDP into the instance’s own address. The project allows proxy devices once the org has UDP ports, so this is what keeps every other proxy (a guest reaching a host socket, a TCP port opened beside the balancer) out of it. Projects outside isb’s orgs (incus’ own default) are the host’s.
check_udp_port
Check one entry: IP:PORT ([V6]:PORT), a specific, non-loopback address and a port above 0: the port is taken on that address only, and DNAT on loopback would never see a packet from outside.
client
The client to use for an org: its project.
ensure
Create an org, or bring an existing one in line with opts. The project’s disk paths are opts.bind_roots plus the host-folder workspace homes recorded on it (allow_home), so rewriting the bind roots never drops a home.
ensure_all_service_names
Turn service names on for every org whose bridge lacks them and whose host can have them now. Returns how many orgs are still without names (the host has no directory for them yet). Orgs that cannot be read are reported and left as they are.
ensure_default
Make sure the default org exists: create isb-default with default settings when it is missing. An existing one keeps its settings, except that its service names are turned on when the host can have them now, whatever order isb serve install and isb host setup ran in. Returns whether it created the org. Idempotent.
ensure_service_names
Bring one existing org’s service names in line: when the host has the hosts directory now (isb host setup ran after the org was made), make the org’s directory and point its bridge at it.
format_bytes
Bytes as incus sizes are written: 3.5GiB, 512MiB.
get
One org.
list
Every org: the default one first, then isb’s projects by name.
names
The names of every org, by name, from one read: what exists, for callers that need no more (whoami, the metrics history).
of_project
The org an incus project (as /1.0/projects?recursion=1 lists it) is, if it is one: an isb- name AND isb’s marker naming the same org. A project that only looks like one (a test’s isb-test-own-1, another tool’s) is not.
remove
Delete an org: its project (with force, everything in it), its network and its ACL. Refuses a non-empty org without force.