brokerclient

package
v0.9.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 22, 2026 License: MIT Imports: 20 Imported by: 0

Documentation

Overview

Package brokerclient reaches openbloxd over a Unix socket or a mutual-TLS network connection.

Its Client satisfies sandbox.Backend and its handle satisfies sandbox.Sandbox, so a caller swaps one constructor and stops needing Docker socket access.

Index

Constants

View Source
const DefaultPreviewTTL = 10 * time.Minute

DefaultPreviewTTL applies when Expose is asked for no particular lifetime. It mirrors pkg/docker's default rather than importing it: brokerclient depends on nothing that needs a Docker socket, and docker.DefaultPreviewTTL is the one constant in that package that isn't.

Variables

This section is empty.

Functions

func WithProfile

func WithProfile(name string) sandbox.CreateOption

WithProfile selects which of the daemon's configured profiles to create under. It is the only policy choice a caller has, and the daemon rejects a name it does not know.

Types

type Client

type Client struct {
	// contains filtered or unexported fields
}

Client reaches openbloxd over a Unix socket or a mutual-TLS network connection. It satisfies sandbox.Backend so it can stand in for a Docker-backed one without the caller changing any other code.

func New

func New(socketPath string, opts ...Option) (*Client, error)

New returns a Client that dials openbloxd at socketPath.

func NewRemote added in v0.7.0

func NewRemote(address string, files TLSFiles, opts ...Option) (*Client, error)

NewRemote returns a Client that dials openbloxd over the network.

The credential is a positional argument rather than an Option because it is not optional: openbloxd requires a client certificate, and a Client built without one could only ever fail at the handshake.

func (*Client) Close

func (c *Client) Close() error

Close releases the client's own resources. It does not touch any sandbox, which is openbloxd's to manage and outlives this process either way.

func (*Client) Create

func (c *Client) Create(ctx context.Context, name string, opts ...sandbox.CreateOption) (sandbox.Sandbox, error)

Create returns a running sandbox for name, creating it if absent.

Every CreateOption that would set host policy — runtime, egress, image, user, resources, lifetime — is daemon configuration now, chosen by profile. Passing one here is rejected rather than ignored: see policyFields.

func (*Client) Destroy

func (c *Client) Destroy(ctx context.Context, name string) error

Destroy removes a sandbox. Destroying an absent sandbox is not an error.

func (*Client) DialPort

func (c *Client) DialPort(ctx context.Context, name string, port int) (net.Conn, error)

DialPort opens a byte stream to a port inside a sandbox.

The connection is dialled outside the pooled client on purpose: the response is a hijacked stream that never completes, and handing it back to the pool would corrupt whatever request reused it.

func (*Client) List

func (c *Client) List(ctx context.Context) ([]sandbox.Info, error)

List returns every sandbox openbloxd manages.

func (*Client) Open

func (c *Client) Open(ctx context.Context, name string) (sandbox.Sandbox, error)

Open returns an existing sandbox, or ErrNotFound.

func (*Client) PreviewHandler

func (c *Client) PreviewHandler() *preview.Handler

PreviewHandler returns the HTTP handler that serves this client's previews, or nil if WithPreviews was not passed. Mount it at preview.RoutePrefix — mirrors docker.Backend.PreviewHandler.

openblox does not run a server. Which address it listens on, behind what TLS, and who can reach it are deployment decisions.

The handler is built once, here, rather than by the caller: Revoke needs to reach the exact instance serving traffic, and a caller-constructed handler (built separately from client and signer) would be a different instance with its own, never-consulted revocation state.

func (*Client) Profiles

func (c *Client) Profiles(ctx context.Context) ([]brokerapi.ProfileInfo, error)

Profiles returns every profile's name and lifetime bounds.

It exists for a caller running its own idle reaper: that reaper's TTL must stay ordered behind the daemon's, or it can end up holding a cached handle that already points at a sandbox openbloxd destroyed. Read the profile's bounds here rather than assuming the caller's own configured timeout is still authoritative — it stopped being so the moment lifetime became daemon policy.

type Option

type Option func(*Client) error

Option configures a Client.

func WithPreviews

func WithPreviews(key []byte, baseURL string) Option

WithPreviews enables Expose, signing credentials with key and serving them under baseURL — the same option the Docker backend takes.

Minting a preview touches Docker nowhere: it signs a name, a port and an expiry. So it happens here, and the signing key lives in the one process that also verifies it. The daemon holds no key.

This also builds the Handler that PreviewHandler returns, exactly as docker.WithPreviews builds one onto the Backend. Revoke calls into that same instance, which is why the Handler is built here rather than left for a caller to construct separately: a caller-built preview.NewHandler(c, signer) would be a different object with its own revocation state that Revoke could never reach.

type TLSFiles added in v0.7.0

type TLSFiles struct {
	CertFile string
	KeyFile  string
	CAFile   string

	// ServerName overrides the name verified against the daemon's
	// certificate. Leave it empty and it is derived from the dial address,
	// which is what you want unless you dial by IP and the certificate names
	// a host.
	ServerName string
}

TLSFiles is the client's half of the mTLS credential openbloxd verifies.

It takes file paths rather than a *tls.Config deliberately. Exposing a *tls.Config would mean accepting InsecureSkipVerify and then refusing it at runtime; taking paths makes an unverified client inexpressible instead. If in-memory certificates are ever needed, that is an Option.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL