Skip to main content

Module workspaces

Module workspaces 

Source
Expand description

Workspaces in the daemon (docs/concepts/workspaces.md): the workspace_* tools, the workspace’s token and its delivery into the machine, the per-org MCP listener on the org’s bridge, live sessions, and the sandbox reaper.

  • The workspace is an incus container in the org’s project, named after the workspace, with a managed volume <org>_<name>_home mounted at the workspace user’s home. Rebuilding replaces the container from its image and mounts the same home again.
  • Its token (isb_ws_...) is minted at create, kept as a SHA-256 for authentication and, encrypted to the daemon’s age key, as the token itself so it can be delivered again after a restart. It is never returned by a tool, written to a log, or put on a command line: it reaches the machine through incus’ file API as /run/isb/token (0400, the workspace user’s). Deleting the workspace revokes it.
  • The bridge listener: for each org with a workspace, the daemon serves the org-bound MCP and REST surface (/orgs/<org>/... only) on the org bridge’s gateway address, port 8481 by default. Only peers in the org’s own subnet are answered, and only with a bearer token (the workspace’s, or an org API token); the authorizer pins the org.
  • The reaper deletes sandboxes past their expiry or idle timeout, only those isb gave deadlines, never a workspace or a replica, and records each in the history.

Structs§

PreviewBase
--preview-domain: [http(s)://]DOMAIN[:PORT].
Previews
The previews: where each host goes, open links, sessions.
SessionGuard
Live sessions on an instance (web terminals now; SSH through the daemon later), counted while their guard lives.
Sessions
Live sessions a workspace has, as far as isb can tell.
Workspaces
The daemon’s workspaces.

Constants§

DEFAULT_PORT
The bridge listener’s port when --workspace-mcp-port is not given.
SANDBOX_ROOT_SIZE
A sandbox’s root disk size when it gives none in an org with a disk quota.

Functions§

copy_on_write
Whether snapshots on this driver share blocks with the volume (cheap), rather than copying it whole (dir).
pool_driver
A storage pool’s driver (zfs, btrfs, lvm, dir, …).
project_has_disk_limit
Whether the org’s project has a disk quota (limits.disk).