Expand description
isb serve’s HTTP side: users, sessions and tokens, the audit log and
history, the MCP and REST server, fleet servers and the embedded web UI.
This is an internal crate of isb, which re-exports
every module here under its own name: depend on isb, not on this.
Modules§
- audit
- The audit log: who did what, where, through which door, and how it went.
- auth
- Identity for
isb serve: users, org memberships and roles, browser sessions, invitations, API tokens and password resets, in SQLite at<state>/isb.db. - history
- The history: everything that happened to what isb runs, kept so the current state can always be traced back.
- server
isb serve: the MCP server layer, with the tools supplied by the embedder.- servers
- Remote servers (P5.1, P5.2): a control plane places orgs on other hosts,
each running incus and
isb serve --agent, and forwards their calls over mutual TLS. Federation, not incus clustering: every server is a whole isb (controller, ingress, registry, builds, secrets) for the orgs on it. See docs/guides/servers.md. - web
- The web UI, embedded at build time (see
build.rs) and served byisb serveon its TCP listener.