pub enum ExecSubstrate {
Native,
Container,
MicroVm,
}Expand description
The execution substrate a workload runs on, ordered by the isolation it
provides — Native < Container < MicroVm.
The ordering is the type’s whole reason to exist, and it is the one kamaji’s
Backend enum documents widest-first: a native workload is fork+exec’d on
the host with no boundary at all, a container gets namespaces and a cgroup
on the host’s kernel, and a microVM gets its own kernel behind hardware
virtualization. Ord is derived, so declaration order below is the
security ordering — do not reorder these variants, and insert a new one at
the position its isolation actually places it.
This is the same three-way distinction crate::admission::GrantRuntime
carries; that type stays separate because a grant names a substrate it
admits (an unordered label in a signed document) while this one answers
“is what I got at least as strong as what I need”. GrantRuntime::of_spec
delegates here so the two cannot disagree about how a spec reads.
Variants§
Native
fork+exec on the host’s own userland. Host kernel, no namespaces, no
image — WorkloadSpec::wants_native_exec.
Container
A container backend: host kernel, namespaces + cgroup, OCI rootfs. The
default when NATIVE_EXEC_ANNOTATION is absent or unrecognised.
MicroVm
A KVM guest with its own kernel — WorkloadSpec::wants_microvm.
Implementations§
Source§impl ExecSubstrate
impl ExecSubstrate
Sourcepub fn annotation_value(self) -> Option<&'static str>
pub fn annotation_value(self) -> Option<&'static str>
The annotation value that selects this substrate, or None for
Self::Container (which is selected by saying nothing).
Trait Implementations§
Source§impl Clone for ExecSubstrate
impl Clone for ExecSubstrate
impl Copy for ExecSubstrate
Source§impl Debug for ExecSubstrate
impl Debug for ExecSubstrate
impl Eq for ExecSubstrate
Source§impl Hash for ExecSubstrate
impl Hash for ExecSubstrate
Source§impl Ord for ExecSubstrate
impl Ord for ExecSubstrate
1.21.0 (const: unstable) · Source§fn max(self, other: Self) -> Selfwhere
Self: Sized,
fn max(self, other: Self) -> Selfwhere
Self: Sized,
1.21.0 (const: unstable) · Source§fn min(self, other: Self) -> Selfwhere
Self: Sized,
fn min(self, other: Self) -> Selfwhere
Self: Sized,
Source§impl PartialEq for ExecSubstrate
impl PartialEq for ExecSubstrate
Source§impl PartialOrd for ExecSubstrate
impl PartialOrd for ExecSubstrate
impl StructuralPartialEq for ExecSubstrate
Auto Trait Implementations§
impl Freeze for ExecSubstrate
impl RefUnwindSafe for ExecSubstrate
impl Send for ExecSubstrate
impl Sync for ExecSubstrate
impl Unpin for ExecSubstrate
impl UnsafeUnpin for ExecSubstrate
impl UnwindSafe for ExecSubstrate
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
Source§impl<Q, K> Comparable<K> for Q
impl<Q, K> Comparable<K> for Q
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§fn equivalent(&self, key: &K) -> bool
fn equivalent(&self, key: &K) -> bool
key and return true if they are equal.