docker

package
v0.2.2 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 3, 2026 License: Apache-2.0 Imports: 11 Imported by: 0

Documentation

Overview

Package docker is the container capability: the Docker Engine reached over its API socket, granted to the code that runs containers.

It wraps the upstream Docker Engine SDK client (github.com/moby/moby/client) rather than the docker CLI run through ipc/proc. The SDK is already the client CSF's local simulations consume, it is typed end to end (no parsing of CLI output), and it gives the owner of a container its whole lifecycle — create, wait, start, kill, logs, remove — as separate calls, which is what cleanup on cancellation needs. Talking to the Engine socket is a kernel I/O crossing, so the client is constructed here, under ipc, and nowhere else.

A binary constructs one ContainerHost and passes it to whatever runs containers. Consumers that need only part of the Engine API declare their own narrow interface, which ContainerHost satisfies; ContainerHost.RunSandboxed is the bounded, isolated run-to-completion that sandboxed evaluation and the node executor are built on.

Index

Constants

View Source
const (
	// DefaultOutputBytes bounds each captured output stream of a sandboxed run.
	DefaultOutputBytes = 1 << 20
	// DefaultPidsLimit bounds the processes a sandboxed container may create.
	DefaultPidsLimit = 256
	// RemoveTimeout bounds the cleanup that removes a finished or canceled
	// sandbox, which runs even after the caller's context has ended.
	RemoveTimeout = 30 * time.Second
)

Variables

View Source
var (
	// ErrImageRequired is returned for a sandbox spec without an image.
	ErrImageRequired = errors.New("ipc/docker: sandbox image is required")
	// ErrInvalidOption is returned by NewContainerHost for a nil, empty or
	// conflicting option.
	ErrInvalidOption = errors.New("ipc/docker: invalid container host option")
)

Functions

This section is empty.

Types

type ContainerHost

type ContainerHost struct {
	IContainerAPI
	// contains filtered or unexported fields
}

ContainerHost is the Docker Engine granted as a capability. Its Engine API methods are promoted from the client it wraps, so it satisfies a consumer's narrow interface directly.

func NewContainerHost

func NewContainerHost(options ...ContainerHostOption) (*ContainerHost, error)

NewContainerHost connects the container capability. Construction does not contact the Engine; the first call does.

func (*ContainerHost) RunSandboxed

func (host *ContainerHost) RunSandboxed(ctx context.Context, spec SandboxSpec) (result SandboxResult, err error)

RunSandboxed creates the container, starts it, waits for it to exit and collects its output, then removes it. The container is removed on every path — success, failure, and cancellation, which kills it first — so a sandbox never outlives the call. A nonzero exit returns the result together with an *ExitError.

type ContainerHostOption

type ContainerHostOption func(settings *containerHostSettings) error

ContainerHostOption configures a ContainerHost.

func WithContainerAPI

func WithContainerAPI(api IContainerAPI) ContainerHostOption

WithContainerAPI supplies an already-constructed Engine client, which the host then owns and closes.

func WithDockerHost

func WithDockerHost(host string) ContainerHostOption

WithDockerHost names the Engine endpoint, such as unix:///var/run/docker.sock. The default is the SDK's platform default; the environment is never read.

func WithOutputBytes

func WithOutputBytes(limit int64) ContainerHostOption

WithOutputBytes bounds each captured output stream of a sandboxed run.

type ExitError

type ExitError struct {
	ContainerID string
	Code        int64
}

ExitError reports a sandbox whose command exited unsuccessfully.

func (*ExitError) Error

func (exitError *ExitError) Error() string

Error names the container and its status.

type IContainerAPI

type IContainerAPI interface {
	ContainerCreate(ctx context.Context, options client.ContainerCreateOptions) (client.ContainerCreateResult, error)
	ContainerInspect(ctx context.Context, id string, options client.ContainerInspectOptions) (client.ContainerInspectResult, error)
	ContainerStart(ctx context.Context, id string, options client.ContainerStartOptions) (client.ContainerStartResult, error)
	ContainerStop(ctx context.Context, id string, options client.ContainerStopOptions) (client.ContainerStopResult, error)
	ContainerKill(ctx context.Context, id string, options client.ContainerKillOptions) (client.ContainerKillResult, error)
	ContainerWait(ctx context.Context, id string, options client.ContainerWaitOptions) client.ContainerWaitResult
	ContainerRemove(ctx context.Context, id string, options client.ContainerRemoveOptions) (client.ContainerRemoveResult, error)
	ContainerLogs(ctx context.Context, id string, options client.ContainerLogsOptions) (client.ContainerLogsResult, error)
	ContainerList(ctx context.Context, options client.ContainerListOptions) (client.ContainerListResult, error)
	ImageList(ctx context.Context, options client.ImageListOptions) (client.ImageListResult, error)
	ImagePrune(ctx context.Context, options client.ImagePruneOptions) (client.ImagePruneResult, error)
	BuildCachePrune(ctx context.Context, options client.BuildCachePruneOptions) (client.BuildCachePruneResult, error)
	DiskUsage(ctx context.Context, options client.DiskUsageOptions) (client.DiskUsageResult, error)
	Close() error
}

IContainerAPI is the part of the Docker Engine API client this capability uses and hands on. *client.Client satisfies it; a test substitutes a double.

type Mount

type Mount struct {
	Source   string
	Target   string
	ReadOnly bool
}

Mount is one host path visible inside a sandbox.

type SandboxResult

type SandboxResult struct {
	ContainerID     string
	ExitCode        int64
	Stdout          []byte
	Stderr          []byte
	StdoutTruncated bool
	StderrTruncated bool
}

SandboxResult is what a finished sandbox left behind.

type SandboxSpec

type SandboxSpec struct {
	Image            string
	Command          []string
	Environment      []string
	WorkingDirectory string
	User             string
	Mounts           []Mount
	Labels           map[string]string
	// Network is a Docker network mode; empty means no network at all.
	Network string
	// MemoryBytes and NanoCPUs are resource limits; zero means unlimited.
	MemoryBytes int64
	NanoCPUs    int64
	// PidsLimit bounds process creation; zero means [DefaultPidsLimit].
	PidsLimit int64
	// WritableRoot leaves the root filesystem writable.
	WritableRoot bool
}

SandboxSpec is one isolated run to completion. Unset limits fall back to the sandbox defaults: no network, every capability dropped, no privilege escalation, a read-only root filesystem with a small /tmp, an init process, and DefaultPidsLimit.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL