Documentation
¶
Index ¶
- Constants
- Variables
- func AddUserFile(ctx context.Context, file *types.UserFile) error
- func AppFileOptions() *syntax.FileOptions
- func ClearCleanup(thread *starlark.Thread, key string)
- func CreatePluginApi(f StarlarkFunction, opType PluginFunctionType) plugin.PluginFunc
- func CreatePluginApiName(...) plugin.PluginFunc
- func CreatePluginConstant(name string, value starlark.Value) plugin.PluginFunc
- func DeferCleanup(thread *starlark.Thread, key string, deferFunc apptype.DeferFunc, strict bool)
- func DeleteUserFile(ctx context.Context, id string) error
- func FetchPluginState(thread *starlark.Thread, key string) any
- func GetContext(thread *starlark.Thread) context.Context
- func GetUserFile(ctx context.Context, id string) (*types.UserFile, error)
- func InitFileStore(connectString string) error
- func NewFSPlugin(pluginContext *types.PluginContext) (any, error)
- func RegisterPlugin(name string, builder plugin.NewPluginFunc, funcs []plugin.PluginFunc)
- func RegisterSystemPlugin(name string, builder plugin.NewPluginFunc, funcs []plugin.PluginFunc)
- func SavePluginState(thread *starlark.Thread, key string, value any)
- func SystemPluginsAllowed(serverConfig *types.ServerConfig, userId string) bool
- type AccessType
- type App
- func (a *App) ActiveContainerName() (container.ContainerName, bool)
- func (a *App) Audit() (*types.ApproveResult, error)
- func (a *App) Close() error
- func (a *App) ExecuteContainerBuild(ctx context.Context, plan *BuildPlan) error
- func (a *App) Initialize(ctx context.Context, dryRun types.DryRun) error
- func (a *App) MaterializeSource() (string, error)
- func (a *App) PrepareContainerBuild(ctx context.Context) (*BuildPlan, error)
- func (a *App) Reload(ctx context.Context, force, immediate bool, dryRun types.DryRun, ...) (bool, error)
- func (a *App) ResetFS()
- func (a *App) ServeHTTP(w http.ResponseWriter, r *http.Request)
- type AppPlugins
- type BuildPlan
- type ByteWindow
- type ContainerHandler
- func (h *ContainerHandler) ActiveContainerName() (container.ContainerName, bool)
- func (h *ContainerHandler) Close() error
- func (h *ContainerHandler) DevReload(ctx context.Context, dryRun bool) error
- func (h *ContainerHandler) ExecuteBuild(ctx context.Context, plan *BuildPlan) error
- func (h *ContainerHandler) GetHealthUrl(appHealthUrl string) string
- func (h *ContainerHandler) GetProxyUrl() string
- func (h *ContainerHandler) IsImageSpec() bool
- func (h *ContainerHandler) PrepareBuild(ctx context.Context) (*BuildPlan, error)
- func (h *ContainerHandler) ProdReload(ctx context.Context, dryRun bool, verify bool) error
- func (h *ContainerHandler) Run(ctx context.Context, path string, cmdArgs []string, env []string) (*exec.Cmd, error)
- func (h *ContainerHandler) WaitForHealth(attempts int, containerName container.ContainerName, expectHash string) error
- type ContainerState
- type FileInfo
- type PluginFunctionType
- type PluginResponse
- func (r *PluginResponse) Attr(name string) (starlark.Value, error)
- func (r *PluginResponse) AttrNames() []string
- func (r *PluginResponse) Freeze()
- func (r *PluginResponse) Hash() (uint32, error)
- func (r *PluginResponse) String() string
- func (r *PluginResponse) Truth() starlark.Bool
- func (r *PluginResponse) Type() string
- func (r *PluginResponse) UnmarshalStarlarkType() (any, error)
- type ReloadOptions
- type SSEMessage
- type StarlarkFunction
- type Tracker
Constants ¶
const ( CONTAINERFILE = "Containerfile" DOCKERFILE = "Dockerfile" )
const ( DEFAULT_FILE_LIMIT = 10_000 MAX_FILE_LIMIT = 100_000 )
const (
VOL_PREFIX_SECRET = "cl_secret:"
)
Variables ¶
var ( CONTENT_TYPE_JSON = []string{"application/json"} CONTENT_TYPE_TEXT = []string{"text/plain"} CONTENT_TYPE_HTML = []string{"text/html; charset=utf-8"} SERVER_NAME = []string{"OpenRun"} // Boosted requests (HX-Request + HX-Boosted) get the full page while // non-boosted HTMX requests get the partial block, so both headers are // part of the cache key VARY_HEADER_VALUE = []string{"HX-Request", "HX-Boosted"} )
Functions ¶
func AppFileOptions ¶ added in v0.15.2
func AppFileOptions() *syntax.FileOptions
func ClearCleanup ¶
ClearCleanup clears a defer function from the thread local
func CreatePluginApi ¶
func CreatePluginApi(f StarlarkFunction, opType PluginFunctionType) plugin.PluginFunc
func CreatePluginApiName ¶
func CreatePluginApiName( f func(thread *starlark.Thread, fn *starlark.Builtin, args starlark.Tuple, kwargs []starlark.Tuple) (starlark.Value, error), opType PluginFunctionType, name string) plugin.PluginFunc
CreatePluginApiName creates a OpenRun plugin function
func CreatePluginConstant ¶
func CreatePluginConstant(name string, value starlark.Value) plugin.PluginFunc
func DeferCleanup ¶
DeferCleanup defers a close function to call when the API handler is done
func FetchPluginState ¶
FetchPluginState fetches a value from the thread local for the plugin
func InitFileStore ¶
func NewFSPlugin ¶
func NewFSPlugin(pluginContext *types.PluginContext) (any, error)
func RegisterPlugin ¶
func RegisterPlugin(name string, builder plugin.NewPluginFunc, funcs []plugin.PluginFunc)
RegisterPlugin registers a plugin with OpenRun
func RegisterSystemPlugin ¶ added in v0.18.7
func RegisterSystemPlugin(name string, builder plugin.NewPluginFunc, funcs []plugin.PluginFunc)
RegisterSystemPlugin registers a privileged system plugin that anonymous callers may not invoke unless security.unsafe_allow_system_plugins_anon is set
func SavePluginState ¶
SavePluginState saves a value in the thread local for the plugin
func SystemPluginsAllowed ¶ added in v0.18.7
func SystemPluginsAllowed(serverConfig *types.ServerConfig, userId string) bool
SystemPluginsAllowed reports whether userId may invoke the privileged system plugins (openrun_admin, build): an authenticated (non-anonymous) caller, or any caller when security.unsafe_allow_system_plugins_anon is set. Shared by the pluginHook gate and the openrun plugin's system_plugins_allowed report, so the two cannot drift
Types ¶
type AccessType ¶
type AccessType string
const ( UserAccess AccessType = "user" AppAccess AccessType = "app" )
type App ¶
type App struct {
*types.Logger
*types.AppEntry
Name string
CustomLayout bool
// App config that takes default values from toml config, overridden with app level metadata.
// It is important that this property is used instead of reading from app metadata config, so that toml
// config defaults are applied.
AppConfig types.AppConfig
AppRunPath string // path to the app run directory
// contains filtered or unexported fields
}
App is the main object that represents a OpenRun app. It is created when the app is loaded
func NewApp ¶
func NewApp(sourceFS *appfs.SourceFs, workFS *appfs.WorkFs, logger *types.Logger, appEntry *types.AppEntry, systemConfig *types.SystemConfig, plugins map[string]types.PluginSettings, appConfig types.AppConfig, notifyClose chan<- types.AppPathDomain, secretEvalFunc func([][]string, string, string) (string, error), auditInsert func(*types.AuditEvent) error, serverConfig *types.ServerConfig, rbacApi rbac.RBACAPI, bindings []*types.Binding) (*App, error)
func (*App) ActiveContainerName ¶ added in v0.17.3
func (a *App) ActiveContainerName() (container.ContainerName, bool)
ActiveContainerName returns the container from the last successful app reload.
func (*App) ExecuteContainerBuild ¶ added in v0.18.4
ExecuteContainerBuild builds the image described by the plan returned from PrepareContainerBuild. It touches no DB state, so no transaction is needed.
func (*App) MaterializeSource ¶ added in v0.18.7
MaterializeSource writes the app's current source files to a new temp directory (delegating to the source FS; supported for non-dev apps whose source is in the metadata file store). The caller owns the directory
func (*App) PrepareContainerBuild ¶ added in v0.18.4
PrepareContainerBuild computes the build plan for the app's container image: image name, whether a build is needed, and (when it is) a temp source dir extracted from the app's source FS. All DB reads happen here, so the caller can close the transaction backing the source FS before ExecuteContainerBuild. Returns nil for apps with no image to build (no container, image-spec, dev).
type AppPlugins ¶
func NewAppPlugins ¶
func NewAppPlugins(app *App, pluginConfig map[string]types.PluginSettings, appAccounts []types.AccountLink) *AppPlugins
func (*AppPlugins) GetPlugin ¶
func (p *AppPlugins) GetPlugin(pluginInfo *plugin.PluginInfo, accountName string) (any, error)
type BuildPlan ¶ added in v0.18.4
type BuildPlan struct {
ImageName container.ImageName
SourceDir string // temp source dir, already extracted; set only when NeedsBuild
NeedsBuild bool
}
BuildPlan captures the state needed to build an app image after the DB transaction backing the app's source FS has been closed. PrepareBuild does all source reads (image identity hash and temp source dir extraction); ExecuteBuild only runs the container build and touches no DB state.
type ByteWindow ¶ added in v0.15.5
type ByteWindow struct {
// contains filtered or unexported fields
}
func NewByteWindow ¶ added in v0.15.5
func NewByteWindow(windowSeconds int, attrs ...attribute.KeyValue) *ByteWindow
func (*ByteWindow) Totals ¶ added in v0.15.5
func (bw *ByteWindow) Totals() (sent, recv uint64)
type ContainerHandler ¶ added in v0.15.20
type ContainerHandler struct {
*types.Logger
GenImageName container.ImageName // generated image name
// contains filtered or unexported fields
}
func NewContainerHandler ¶ added in v0.15.20
func NewContainerHandler(logger *types.Logger, app *App, containerFile string, serverConfig *types.ServerConfig, configPort int32, lifetime, scheme, health, buildDir string, sourceFS appfs.ReadableFS, paramMap map[string]string, containerConfig types.Container, stripAppPath bool, containerVolumes []string, secretsAllowed [][]string, cargs map[string]any, bindings []*types.Binding) (*ContainerHandler, error)
func (*ContainerHandler) ActiveContainerName ¶ added in v0.17.3
func (h *ContainerHandler) ActiveContainerName() (container.ContainerName, bool)
ActiveContainerName returns the last container this handler successfully started or reused.
func (*ContainerHandler) Close ¶ added in v0.15.20
func (h *ContainerHandler) Close() error
func (*ContainerHandler) DevReload ¶ added in v0.15.20
func (h *ContainerHandler) DevReload(ctx context.Context, dryRun bool) error
func (*ContainerHandler) ExecuteBuild ¶ added in v0.18.4
func (h *ContainerHandler) ExecuteBuild(ctx context.Context, plan *BuildPlan) error
ExecuteBuild builds the image described by a plan from PrepareBuild. It reads only from the plan's temp source dir, never the DB, so callers can (and should) close their DB transaction before invoking it.
func (*ContainerHandler) GetHealthUrl ¶ added in v0.15.20
func (h *ContainerHandler) GetHealthUrl(appHealthUrl string) string
func (*ContainerHandler) GetProxyUrl ¶ added in v0.15.20
func (h *ContainerHandler) GetProxyUrl() string
func (*ContainerHandler) IsImageSpec ¶ added in v0.17.3
func (h *ContainerHandler) IsImageSpec() bool
IsImageSpec reports whether this container handler was configured with an upstream image reference (i.e. `--spec image` / `container.source = "image:..."`). Such apps need ProdReload to run on every admin reload so that RefreshImage can resolve the current digest and recreate the container when the upstream tag has moved; build-spec apps only need ProdReload on Initialize since their image identity is captured by the source-content hash.
func (*ContainerHandler) PrepareBuild ¶ added in v0.18.4
func (h *ContainerHandler) PrepareBuild(ctx context.Context) (*BuildPlan, error)
PrepareBuild mirrors the image-build portion of ProdReload without any container side effects. The image name is content-hashed, so a later ProdReload for the same source finds the built image via its ImageExists check and skips the build. Returns nil for apps with no image to build (dev apps build through DevReload, image-spec apps pull rather than build).
func (*ContainerHandler) ProdReload ¶ added in v0.15.20
ProdReload reloads the prod container. verify indicates the caller wants the update to be verified and rollback-capable; for in-place managers this makes a snapshot failure fatal (we refuse to mutate the live Deployment when we cannot capture the state needed to roll it back), rather than proceeding with an irreversible update.
func (*ContainerHandler) WaitForHealth ¶ added in v0.15.20
func (h *ContainerHandler) WaitForHealth(attempts int, containerName container.ContainerName, expectHash string) error
type ContainerState ¶
type ContainerState string
const ( ContainerStateUnknown ContainerState = "unknown" ContainerStateRunning ContainerState = "running" ContainerStateIdleShutdown ContainerState = "idle_shutdown" ContainerStateHealthFailure ContainerState = "health_failure" )
type PluginFunctionType ¶
type PluginFunctionType int
const ( READ PluginFunctionType = iota WRITE READ_WRITE )
type PluginResponse ¶
type PluginResponse struct {
// contains filtered or unexported fields
}
PluginResponse is a starlark.Value that represents the response to a plugin request
func NewErrorCodeResponse ¶
func NewErrorCodeResponse(errorCode int, err error, value any) *PluginResponse
func NewErrorResponse ¶
func NewErrorResponse(err error, thread *starlark.Thread) *PluginResponse
func NewResponse ¶
func NewResponse(value any) *PluginResponse
func NewStreamResponse ¶
func NewStreamResponse(value any) *PluginResponse
func (*PluginResponse) AttrNames ¶
func (r *PluginResponse) AttrNames() []string
func (*PluginResponse) Freeze ¶
func (r *PluginResponse) Freeze()
func (*PluginResponse) Hash ¶
func (r *PluginResponse) Hash() (uint32, error)
func (*PluginResponse) String ¶
func (r *PluginResponse) String() string
func (*PluginResponse) Truth ¶
func (r *PluginResponse) Truth() starlark.Bool
func (*PluginResponse) Type ¶
func (r *PluginResponse) Type() string
func (*PluginResponse) UnmarshalStarlarkType ¶
func (r *PluginResponse) UnmarshalStarlarkType() (any, error)
type ReloadOptions ¶ added in v0.18.3
type ReloadOptions struct {
// ReloadContainer, when true, (re)loads the prod container (rebuild/restart
// as needed). It is true for reload and initialize operations; only the
// metadata-only paths leave it false. Image-spec apps always reload.
ReloadContainer bool
// Verify indicates the caller wants a verified, rollback-capable update.
// For in-place container managers (Kubernetes) this makes a missing
// rollback snapshot a fatal error rather than proceeding with an
// irreversible in-place update.
Verify bool
// SkipContainer skips the prod container reload entirely, including for
// image-spec apps (which ReloadContainer=false alone does not skip). Used
// by the image pre-build pass, which needs the app fully configured but
// must not touch containers.
SkipContainer bool
}
ReloadOptions controls how App.Reload handles the prod container.
type SSEMessage ¶
type SSEMessage struct {
// contains filtered or unexported fields
}
type StarlarkFunction ¶
type Tracker ¶ added in v0.15.5
type Tracker struct {
// contains filtered or unexported fields
}
Tracker is a reverse proxy with byte count tracking
func NewTracker ¶ added in v0.15.5
func (*Tracker) GetRollingTotals ¶ added in v0.15.5
Accessor to read the rolling totals.