Expand description
Orgs: the trust boundary. An org is an incus project; its people and agents fully administer what is in it, and nothing crosses orgs.
Any org x is the incus project isb-x, the default org included
(isb-default, which ensure_default creates when the daemon
starts). incus’ own default project is never an org: it holds the
plain sandboxes isb create and isb up make without --org.
Modules§
- disk
- Root disk sizes under an org’s disk limit (
limits.disk). - nesting
- The Docker exception (docs/concepts/security.md#the-docker-exception):
an org setting,
allow_nesting, that lets the org’s workspace and nothing else run withsecurity.nesting, so Docker works inside it.
Structs§
- Budget
- One limit of an org: the limit, what its instances are allocated against it (summed over every instance, stopped ones included), and what is left. Bytes for memory and disk.
- Egress
- An egress exception: a private destination an org may reach despite the
default deny. Written
CIDR[:PORTS[/PROTO]]:10.1.2.0/24(everything there),100.79.171.47:1080(one TCP port),10.1.2.3:53/udp,10.1.2.3:8000-8100,9000/tcp. A bare address is a /32. - OrgId
- A validated org name:
[a-z][a-z0-9-]{0,30}, not ending in-. - OrgInfo
- An org as it exists in incus.
- OrgOptions
- Limits for an org as a whole (the incus project’s limits) and the defaults each instance gets when its spec sets none.
Enums§
- Limit
- One of an org’s limits, which
isb org updatecan lift again. - Names
- Where an org stands on service names.
Constants§
- DEFAULT_
ORG - DEFAULT_
ORG_ PROJECT - The incus project of the default org.
- DEFAULT_
ROOT_ SIZE - The root disk size isb gives an instance it creates in an org with
limits.diskwhen its spec sets none (incus refuses an instance without one there); seesuper::disk. - INGRESS_
CADDY - How an org’s domains reach it: Caddy’s public listeners (default) or the org’s own Cloudflare Tunnel.
- INGRESS_
CLOUDFLARE_ TUNNEL
Functions§
- allow_
home - Let the org’s restricted project bind
path(and what is under it) as a workspace home, and record it so that the org’s later updates keep it. - allowed_
udp - The UDP ports
orgmay publish, as a platform admin listed them. An org that does not exist here may publish none. - bridge_
name - The bridge for an org:
isbbr+ 8 hex digits of the name’s hash, inside the kernel’s 15-character limit on interface names. - check_
domain_ suffix - Check an allowlist entry: a domain suffix (
example.com), or*.example.comto allow wildcard hosts under it too. - check_
egress - Exceptions for different networks must not overlap: a port-limited one would otherwise cut into the other. The same network may repeat (its ports add up).
- check_
exists Okwhenorgexists here, else the same “org X not found” asget, without reading the rest of it. For a tool to check before it acts, so an unknown org is refused up front instead of failing halfway on an incus error about a missing project.- check_
proxies - Refuse proxy devices in an org project’s instance, except a stack
replica’s UDP ports, which only the stack controller makes
(
crate::spec::SandboxSpec::stack_udp, which no spec, compose file or tool argument can set): host-bound, NAT mode, UDP into the instance’s own address. The project allows proxy devices once the org has UDP ports, so this is what keeps every other proxy (a guest reaching a host socket, a TCP port opened beside the balancer) out of it. Projects outside isb’s orgs (incus’ owndefault) are the host’s. - check_
udp_ port - Check one entry:
IP:PORT([V6]:PORT), a specific, non-loopback address and a port above 0: the port is taken on that address only, and DNAT on loopback would never see a packet from outside. - client
- The client to use for an org: its project.
- ensure
- Create an org, or bring an existing one in line with
opts. The project’s disk paths areopts.bind_rootsplus the host-folder workspace homes recorded on it (allow_home), so rewriting the bind roots never drops a home. - ensure_
all_ service_ names - Turn service names on for every org whose bridge lacks them and whose host can have them now. Returns how many orgs are still without names (the host has no directory for them yet). Orgs that cannot be read are reported and left as they are.
- ensure_
default - Make sure the default org exists: create
isb-defaultwith default settings when it is missing. An existing one keeps its settings, except that its service names are turned on when the host can have them now, whatever orderisb serve installandisb host setupran in. Returns whether it created the org. Idempotent. - ensure_
service_ names - Bring one existing org’s service names in line: when the host has the
hosts directory now (
isb host setupran after the org was made), make the org’s directory and point its bridge at it. - format_
bytes - Bytes as incus sizes are written:
3.5GiB,512MiB. - get
- One org.
- list
- Every org: the default one first, then isb’s projects by name.
- names
- The names of every org, by name, from one read: what exists, for callers that need no more (whoami, the metrics history).
- of_
project - The org an incus project (as
/1.0/projects?recursion=1lists it) is, if it is one: anisb-name AND isb’s marker naming the same org. A project that only looks like one (a test’sisb-test-own-1, another tool’s) is not. - remove
- Delete an org: its project (with
force, everything in it), its network and its ACL. Refuses a non-empty org withoutforce.