Documentation
¶
Overview ¶
Package config loads and validates sim's TOML configuration.
The TOML document is decoded directly into the typed structs below, which are pre-filled with sim's defaults: BurntSushi only overwrites keys that are present, so absent keys need no presence tracking. `[systemd.limits]` uses pointers because "absent" (do not pass -p MemoryMax=...) differs from a zero value.
Wrong-type values are rejected by the decoder; everything else (port range, enum membership, env-name syntax, positive ints, non-empty strings) is checked in validate(), which reports the same messages the Python implementation did.
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
Types ¶
type Config ¶
type Config struct {
Path string `toml:"-"`
Network Network `toml:"network"`
Podman Podman `toml:"podman"`
Systemd Systemd `toml:"systemd"`
Env Env `toml:"env"`
Sandbox Sandbox `toml:"sandbox"`
}
Config is the validated configuration.
type Limits ¶
type Limits struct {
MemoryMax *string `toml:"memory_max"`
MemoryHigh *string `toml:"memory_high"`
MemorySwapMax *string `toml:"memory_swap_max"`
CPUQuota *string `toml:"cpu_quota"`
TasksMax *int `toml:"tasks_max"`
}
Limits mirrors [systemd.limits]. A nil field means the key was absent.
type Network ¶
type Network struct {
Public bool `toml:"public"`
// LocalPorts are host ports spliced into the sandbox by pasta (-T/-U).
// An empty list passes "none", so no host port is reachable.
LocalPorts []int `toml:"local_ports"`
// AllowCIDRs are egress destinations that stay reachable when Public is
// false (the corporate-only / "private" mode). Normalized to masked
// prefixes by validate; empty with Public false means loopback only.
AllowCIDRs []string `toml:"allow_cidrs"`
ResolvConf string `toml:"resolv_conf"`
}
Network mirrors [network].
type Podman ¶
type Podman struct {
Enabled bool `toml:"enabled"`
Images []string `toml:"images"`
ChownShadow bool `toml:"chown_shadow"`
}
Podman mirrors [podman].
type Sandbox ¶
type Sandbox struct {
VirtualHome string `toml:"virtual_home"`
Binds []string `toml:"binds"`
CwdGitMode string `toml:"cwd_git_mode"`
SetupScripts []string `toml:"setup_scripts"`
}
Sandbox mirrors [sandbox].