pub struct RemotePolicy {
pub allow_privileged: bool,
pub allow_raw: bool,
pub bind_roots: Vec<PathBuf>,
pub publish_addresses: Vec<String>,
pub any_instance: bool,
}Expand description
The operator’s limits for remote callers.
Fields§
§allow_privileged: bool§allow_raw: boolraw_config, raw_devices, incus_profiles, idmap maps, guest-bound ports.
bind_roots: Vec<PathBuf>Host directories bind mounts may come from.
publish_addresses: Vec<String>Host addresses a published port may listen on, besides loopback.
any_instance: boolExec into, remove and read logs of any instance, not only the ones
isb serve manages.
Implementations§
Source§impl RemotePolicy
impl RemotePolicy
Sourcepub fn check_file(&self, file: &ComposeFile, base: &Path) -> Result<()>
pub fn check_file(&self, file: &ComposeFile, base: &Path) -> Result<()>
Check a whole compose file. base is where its relative paths resolve.
Sourcepub fn check_spec(&self, spec: &SandboxSpec, base: &Path) -> Result<()>
pub fn check_spec(&self, spec: &SandboxSpec, base: &Path) -> Result<()>
Check one sandbox spec.
Sourcepub fn check_base_dir(&self, dir: &Path) -> Result<()>
pub fn check_base_dir(&self, dir: &Path) -> Result<()>
A base directory a remote caller asked for must be inside a bind root.
Trait Implementations§
Source§impl Clone for RemotePolicy
impl Clone for RemotePolicy
Source§impl Debug for RemotePolicy
impl Debug for RemotePolicy
Auto Trait Implementations§
impl Freeze for RemotePolicy
impl RefUnwindSafe for RemotePolicy
impl Send for RemotePolicy
impl Sync for RemotePolicy
impl Unpin for RemotePolicy
impl UnsafeUnpin for RemotePolicy
impl UnwindSafe for RemotePolicy
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more