Expand description
Workspaces in the daemon (docs/concepts/workspaces.md): the workspace_* tools,
the workspace’s token and its delivery into the machine, the per-org MCP
listener on the org’s bridge, live sessions, and the sandbox reaper.
- The workspace is an incus container in the org’s project, named
after the workspace, with a managed volume
<org>_<name>_homemounted at the workspace user’s home. Rebuilding replaces the container from its image and mounts the same home again. - Its token (
isb_ws_...) is minted at create, kept as a SHA-256 for authentication and, encrypted to the daemon’s age key, as the token itself so it can be delivered again after a restart. It is never returned by a tool, written to a log, or put on a command line: it reaches the machine through incus’ file API as/run/isb/token(0400, the workspace user’s). Deleting the workspace revokes it. - The bridge listener: for each org with a workspace, the daemon
serves the org-bound MCP and REST surface (
/orgs/<org>/...only) on the org bridge’s gateway address, port 8481 by default. Only peers in the org’s own subnet are answered, and only with a bearer token (the workspace’s, or an org API token); the authorizer pins the org. - The reaper deletes sandboxes past their expiry or idle timeout, only those isb gave deadlines, never a workspace or a replica, and records each in the history.
Structs§
- Preview
Base --preview-domain:[http(s)://]DOMAIN[:PORT].- Previews
- The previews: where each host goes, open links, sessions.
- Session
Guard - Live sessions on an instance (web terminals now; SSH through the daemon later), counted while their guard lives.
- Sessions
- Live sessions a workspace has, as far as isb can tell.
- Workspaces
- The daemon’s workspaces.
Constants§
- DEFAULT_
PORT - The bridge listener’s port when
--workspace-mcp-portis not given. - SANDBOX_
ROOT_ SIZE - A sandbox’s root disk size when it gives none in an org with a disk quota.
Functions§
- copy_
on_ write - Whether snapshots on this driver share blocks with the volume (cheap),
rather than copying it whole (
dir). - pool_
driver - A storage pool’s driver (
zfs,btrfs,lvm,dir, …). - project_
has_ disk_ limit - Whether the org’s project has a disk quota (
limits.disk).