Skip to main content

Module spec

Module spec 

Source
Expand description

The one spec model shared by the library API, the CLI and the compose YAML.

Every struct denies unknown fields, so a typo is an error rather than a silently ignored setting. The JSON Schema (isb schema) is generated from these types.

Structs§

ComposeFile
A compose file: named volumes plus any number of services, each one sandbox. Mirrors docker compose wherever incus allows.
Dependency
Deploy
docker’s deploy:, for isb stack deploy.
DomainSpec
A hostname (and path) the ingress serves a service on.
Environment
A service’s environment: plain values, and variables whose value is a top-level secret (KEY: {secret: NAME}).
ExecDefaults
Defaults for exec into a sandbox. Per-call options override them.
ExecSpec
The exec: block of a service: exec defaults with no docker equivalent.
HealthProbe
A healthcheck resolved to argv and durations.
Healthcheck
docker compose’s healthcheck:. Durations are strings (30s, 1m30s).
IdmapMap
IdmapRaw
NamedVolumeSpec
A named custom storage volume.
PortBinding
Port binding builders.
PortSpec
An incus proxy device. Written as docker’s [HOST_IP:]PUBLISHED:TARGET[/PROTOCOL], its long form (PortMapping in the schema), or the incus form (ProxyPort).
ResourceLimits
Resources
RestartPolicy
SandboxSpec
Everything about one sandbox: a compose service.
SecretDef
Where a secret’s value comes from. Exactly one source.
SecretRef
A service’s use of a secret.
UpdateConfig
Volume
Mount builders: Volume::bind(host), Volume::named(name).
VolumeOptions
docker’s volume: block of a long-form mount.
VolumeSpec
A mount. Written as SOURCE:TARGET[:OPTIONS] or as the long form (VolumeMount in the schema); always serialized in the long form.

Enums§

DependCondition
What a dependency must reach before its dependents start.
FailureAction
IdmapMode
IdmapSpec
idmap handling.
InstanceType
Instance type.
MountType
What a mount’s source is.
OnChange
What a new version of a secret does to the stack services using it. Ordered weakest first: a service that uses a secret twice with different settings gets the stronger one.
PortBind
Which side listens.
ReadyCheck
A readiness check. “Running” alone is not ready: networking comes up a beat after the instance does.
RestartCondition
RestartMode
docker’s restart:.
SecretAs
How an environment secret reaches the app (KEY: {secret: NAME, as: ...}).
UpdateOrder

Constants§

DEFAULT_SECRET_REFRESH
How often isb serve checks a driver-backed secret by default.

Functions§

compose_schema
JSON Schema for the compose file format.