appspec

package
v0.16.2 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 29, 2026 License: Apache-2.0 Imports: 10 Imported by: 0

Documentation

Overview

Package appspec builds the sandbox spec that runs an app's code.

It exists because there were two of these. The deployment launcher had the real one, and the exec proxy had a copy carrying the comment "adapted from controllers/deployment/launcher.go" -- which had since drifted: it dropped per-service env, ignored disks entirely, hardcoded the container command to /bin/sh, and labeled every sandbox `service: web` whatever the app declared. Anyone using `miren app run` got that second, worse spec.

The fork happened because the original was a method that reached into the launcher's entity client, so there was no way to call it from elsewhere. So the one thing this package deliberately does not do is talk to the store: callers resolve what they need and pass it in.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func Build

func Build(log *slog.Logger, opts Options) (*compute_v1alpha.SandboxSpec, error)

Build assembles the sandbox spec.

log may be nil; it is only used to report config that had to be ignored.

func IsSystemEnvVar

func IsSystemEnvVar(key string) bool

IsSystemEnvVar reports whether a key is managed by the platform and must not be taken from user config.

Types

type Options

type Options struct {
	// AppID is the app the sandbox belongs to; it becomes the log entity.
	AppID entity.Id
	// AppName is the app's metadata name, used for MIREN_APP. Callers resolve
	// it -- fetching it here is what made the original impossible to reuse.
	AppName string

	Version *core_v1alpha.AppVersion
	Config  *core_v1alpha.ConfigSpec

	// Service names the entry in Config.Services to draw ports, env, disks,
	// and the command from. Empty means none of that applies, which is the
	// case for a task run.
	Service string

	// Task names the entry in Config.Tasks to draw env from. A run has no
	// service, so without this the env a task declares is stored at build time
	// and read back nowhere -- which silently drops the credentials a task was
	// declared to carry.
	Task string

	Image string

	// Command overrides the service's command. The config entrypoint is still
	// prepended, so callers pass the command as written in app.toml.
	Command string

	// SkipPorts suppresses port configuration entirely.
	//
	// Runs must set this, and not only to avoid a stray listener: the sandbox
	// controller waits for declared ports to bind and kills the sandbox when
	// they don't. A migration would be executed and then reported as a failed
	// startup. Suppressing ports also drops PORT, which follows from there
	// being no port rather than needing its own switch.
	SkipPorts bool

	// SkipDisks suppresses disk volumes and mounts.
	//
	// Runs set this. Miren disks are single-writer, enforced by requiring the
	// attaching service to be fixed at one instance; a run alongside the
	// service that holds the lease would either block or race it. RFD-97 cut
	// per-task disks for exactly that reason.
	SkipDisks bool

	// Stdin makes the container attachable: containerd wires up a stdin FIFO
	// when the task is created and cannot add one afterwards.
	Stdin bool
	// Tty allocates a pty, which also merges stderr into stdout.
	Tty bool

	// LogAttrs replaces the default log labels. Whatever is set here lands
	// verbatim on the container's log entries, which is how a run's output
	// becomes findable without any change to the log pipeline.
	LogAttrs types.Labels

	// RestartPolicy set to never stops the sandbox controller rebooting the
	// container if it vanishes. Runs must set it: rebooting re-executes the
	// command.
	RestartPolicy compute_v1alpha.SandboxSpecRestartPolicy

	// ExtraEnv is appended after config env but before the system-managed
	// variables, so it cannot shadow PORT or ADMIN_TOKEN.
	ExtraEnv []string

	// ShutdownTimeout overrides the service's graceful-shutdown window.
	ShutdownTimeout string
}

Options describes one sandbox to build.

Every zero value reproduces what the deployment launcher did before this package existed, so a service pool passes only the first group of fields. The rest exist for task runs, which want the same image, env, and app identity but none of the machinery that assumes a long-running server.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL