pub struct Execute {
pub bypass_local_limit: bool,
pub shell: ExecuteShell,
pub script: Option<String>,
pub script_file: Option<String>,
pub script_object: Option<String>,
pub timeout: String,
pub run_as: RunAs,
pub cwd: Option<String>,
}Fields§
§bypass_local_limit: boolCritical jobs can bypass the PC limit and consume no slot.
shell: ExecuteShell§script: Option<String>Inline script body. Mutually exclusive with script_file
and script_object; exactly one of the three must be set
(enforced by Execute::validate_script_source at the
write-side parse boundaries — kanade job create and
POST /api/jobs).
Empty string is treated as unset so operators can swap
to a script_file: / script_object: alternative just by
commenting out the body, without having to also drop the
script: key entirely.
script_file: Option<String>Repo-local file path resolved by the operator-side CLI at
kanade job create time. The CLI reads the file, slots its
contents into script, and clears this field before
POSTing — so the backend / agents never see script_file
in stored manifests. SPEC §2.4.1.
The resolver shipped with #210: kanade job create /
kanade job validate inline this field end-to-end. Because
resolution is CLI-side (it needs the operator’s filesystem),
POST /api/jobs rejects a manifest that still carries it
(#918) — a stored script_file job would 400 at every exec.
Inline the script or use script_object when writing through
the API / SPA editor.
script_object: Option<String>Object Store reference (<name>/<version>) into the
scripts bucket (OBJECT_SCRIPTS). Agents fetch the body
at Execute time via /api/script-objects/{name}/{version}
and cache it locally. SPEC §2.4.1.
Fully wired (#210/#211): the backend resolves the digest at
exec submission (api::exec::resolve_script_source), the agent
fetches + sha-verifies + caches the body (script_cache), and
kanade script CRUDs the store. Unlike script_file: (inlined
CLI-side, git-managed), this keeps the body in versioned,
digest-pinned object storage — the ops-managed counterpart.
timeout: Stringhumantime duration string (e.g. “30s”, “10m”). Script-intrinsic — represents how long this script reasonably takes to run.
run_as: RunAsToken + session combination the agent uses to launch the
script (v0.21). Default = RunAs::System (Session 0,
LocalSystem privileges, no GUI; root on macOS) — matches
pre-v0.21 behavior. user / system_gui run in the logged-in
console user’s session on Windows and macOS, and fail when
nobody is logged in; Linux agents skip them.
cwd: Option<String>Working directory for the spawned child (v0.21.1). When
unset, the child inherits the agent’s cwd — on Windows that
means %SystemRoot%\System32 for the prod service, which is
almost never what operators actually want (a macOS run_as: user job starts in the user’s home instead: the daemon’s own
cwd is its 0700 data dir). Use an absolute path; relative paths
are passed through to the OS verbatim. The agent expands a
leading ~ to the home of the identity the job runs as (the
user for run_as: user), and on Windows %FOO% from that
identity’s environment — so %PROGRAMDATA% works for run_as: system, ~\src / %USERPROFILE% for run_as: user. A macOS
agent expands only ~.
Implementations§
Source§impl Execute
impl Execute
Sourcepub fn validate_script_source(&self) -> Result<(), String>
pub fn validate_script_source(&self) -> Result<(), String>
Enforce that exactly one of script / script_file /
script_object is set. Called at the write-side parse
boundaries (CLI kanade job create + backend
POST /api/jobs) so ambiguous YAML is rejected before it
reaches the JOBS KV. Read paths (projector, agent
scheduler, list endpoints) skip this check — they only ever
see what the write path already validated.
Trait Implementations§
Source§impl<'de> Deserialize<'de> for Execute
impl<'de> Deserialize<'de> for Execute
Source§fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
Source§impl JsonSchema for Execute
impl JsonSchema for Execute
Source§fn schema_id() -> Cow<'static, str>
fn schema_id() -> Cow<'static, str>
Source§fn json_schema(generator: &mut SchemaGenerator) -> Schema
fn json_schema(generator: &mut SchemaGenerator) -> Schema
Source§fn inline_schema() -> bool
fn inline_schema() -> bool
$ref keyword. Read more