Expand description
isb serve: the stack controller behind an MCP server.
Two doors, one set of tools:
- the unix socket, for the local CLI (
isb stack ...), trusted as the daemon’s own user; - loopback HTTP at
/mcp, for remote agents through a cloudflared tunnel and Cloudflare Access, held topolicy::RemotePolicy.
The tools manage stacks (long-running, replicated, load-balanced
services), apps over them (crate::app), plain sandboxes (an isolated
machine for an agent), and each org’s secrets (crate::secrets).
Modules§
- apps
- The app tools (
project_*,environment_*,app_*) and the public webhook route, overcrate::app::Apps. - audit
- The daemon’s side of the audit log (
crate::audit): which calls are recorded and what of them is kept, the tool classes that viewers and token scopes are judged by, theaudit_listandaudit_verifytools, the live tail (GET /api/v1/audit/stream) and webhook deliveries. - builds
- The
build_*andregistry_*tools: builds run in the daemon (it alone pushes to the local registry), and their logs are read back in pieces, so a CLI or an agent follows a build that outlives any one request. - data
- The data tools: databases (
database_*, over apps with a database source), backups and restores (backup_*), and scheduled jobs (job_*). Every one acts in the org it names, so the authorizer’s org check covers them; destinations on this host need a trusted caller. - policy
- What a remote caller may ask for.
- previews
- The preview tools (
preview_*), overcrate::app::Apps. Settings are the app’spreviewsfield (app_update). - secrets
- The
secret_*tools: the org’s secret store over MCP and the unix socket. Values travel base64 in arguments and results. - superadmin
- Who is a superadmin (
crate::auth::superadmin) on this daemon: a superadmin token, a tailnet identity on--superadmin-tailnet, a verified Cloudflare Access identity on--superadmin-access, either kind of identity added toisb.dbwithisb superadmin add(read per request, so no restart), or, in a debug build, any credential-less loopback request underISB_DEV_SUPERADMIN(crate::auth::dev). Nothing else grants it. One gate serves the tool endpoints (through the authn hook) and the identity endpoints (/api/v1/auth/*). - templates
- The template tools (
template_*): the catalog, and deploying a template into a project environment as apps (crate::template). - volumes
- The volume tools (
volume_*): an org’s named volumes, their snapshots (now and on a schedule, with the pre-snapshot hook) and staged restores. Volume backups arebackup_*with avolume(docs/guides/volumes.md). - workspaces
- Workspaces in the daemon (docs/concepts/workspaces.md): the
workspace_*tools, the workspace’s token and its delivery into the machine, the per-org MCP listener on the org’s bridge, live sessions, and the sandbox reaper.
Structs§
- Serve
Config - How
isb serveruns.
Constants§
- LABEL_
OWNER - Marks an instance a remote caller created with
sandbox_create.
Functions§
- default_
state_ dir - Default state directory, exported for the CLI.
- local_
deploy_ args - Resolve the paths the local CLI sends with a deploy: the project’s own
directory, so relative binds and
file:secrets work as withisb up. - serve
- Run the daemon until SIGINT/SIGTERM. Apps keep running when it stops.
- wait_
settled - Poll until every service is converged, or one is paused or failing (its
message says why), or
timeout.