cua-fleet
The Fleet (cloud sandboxes) crate: pools, claims, builds and claim secrets.
The Fleet (cloud sandboxes) crate: pools, claims, builds and claim secrets.
Public API of the cua-fleet crate (cua_fleet). Summaries and declarations only (cargo doc -p cua-fleet --open in libs/cua has the full comments); see Rust crates for stability.
Fleet for the cua SDK.
autopool: Automatic Fleet pools: Sandbox.create(image) on Fleet ...billing: Cua Cloud billing from an app: the account's billing ...builds: Remote image builds: Image layers (pip_install ...claim_secrets: Per-claim env tokens delivered by Fleet's claim Secrets.limits: The sandbox sizes the SDK asks Cua Cloud for.parity: Sandbox parity with the local runtimes: sidecars on ...pricing: Cua Cloud usage rates, read from Fleet.runtime: The Fleet runtime ↔ image pairing, validated in exactly ...spec: One sandbox model for pools and Sandbox.create.AcquireOpts#Per-acquire options.
pub struct AcquireOpts {
pub name: Option<String>,
pub warm: Option<bool>,
pub registry_credentials: Option<RegistryCredentials>,
pub max_pool_size: Option<u32>,
pub claim_ttl: Option<Duration>,
pub labels: BTreeMap<String, String>,
pub bind_deadline: Option<Duration>,
pub claim_token: Option<String>,
}AutoPoolConfig#Pool manager settings.
pub struct AutoPoolConfig {
pub warm: bool,
pub max_pool_size: u32,
pub claim_ttl: Duration,
pub heartbeat_every: Option<Duration>,
pub bind_deadline: Duration,
pub pool_ttl: Duration,
pub pool_ttl_renew_window: Duration,
pub idle_gc: Option<Duration>,
pub auto_gc_every: Duration,
pub home: PathBuf,
pub tenant: Option<String>,
pub clock: Clock,
}
impl AutoPoolConfig {
fn from_env() -> Self;
fn from_lookup(get: impl Fn(&str) -> Option<String>) -> Self;
fn with_state_dir(self, dir: &Path) -> Self;
}BillingCard#The saved card, as Fleet describes it (never its ...
pub struct BillingCard {
pub brand: String,
pub last4: String,
pub exp_month: u32,
pub exp_year: u32,
}BillingCredit#The account's Cua Cloud credit.
pub struct BillingCredit {
pub balance_usd_cents: i64,
pub signup_grant_usd_cents: i64,
pub signup_grant_unused: bool,
}BillingStatus#GET /api/billing/status.
pub struct BillingStatus {
pub billing_enabled: bool,
pub payment_method_present: bool,
pub card: Option<BillingCard>,
pub plan: String,
pub payg_available: bool,
pub credit: Option<BillingCredit>,
pub billing_url: Option<String>,
}
impl BillingStatus {
fn disabled() -> Self;
}BuildFile#A local file copied into the image.
pub struct BuildFile {
pub source: PathBuf,
pub destination: String,
}BuildSpec#What to build.
pub struct BuildSpec {
pub from: String,
pub layers: Vec<ImageLayer>,
pub env: BTreeMap<String, String>,
pub ports: Vec<u16>,
pub files: Vec<BuildFile>,
pub timeout: Option<Duration>,
}
impl BuildSpec {
fn is_empty(&self) -> bool;
fn validate(&self) -> Result<()>;
}BuiltImage#A built (or cached) image.
pub struct BuiltImage {
pub reference: String,
pub digest: String,
pub namespace: String,
pub name: String,
pub cached: bool,
}claim_secrets::EnvTokenProbe#The real probe: connects to the env service through ...
pub struct EnvTokenProbe;ClaimOptions#Claim options.
pub struct ClaimOptions {
pub name: Option<String>,
pub spec: Option<ClaimSpec>,
pub ttl_seconds_after_created: Option<u32>,
pub labels: Option<HashMap<String, String>>,
pub claim_token: Option<String>,
}ClaimSecretsWait#Probe settings of a FleetClient (tests shorten them).
pub struct ClaimSecretsWait {
pub budget: Duration,
pub every: Duration,
pub probe: Arc<dyn TokenProbe>,
}Error#Errors from this crate.
pub enum Error {
MissingCredentials,
InvalidArgument(String),
Sdk(SdkError),
AdmissionDenied { operation: String, status: u16, message: String },
CreditExhausted { message: String, billing_url: String },
UnknownService { sandbox: String, service: String, available: Vec<String> },
Timeout(String),
Env(Error),
Unsupported(String),
PoolSpecMismatch { pool: String, diffs: Vec<SpecDiff> },
ClaimSecretsNotDelivered { claim: String, runtime: String, waited: Duration, detail: String },
}
impl Error {
fn is_not_found(&self) -> bool;
}FleetClient#A Fleet client.
pub struct FleetClient { /* private fields */ }
impl FleetClient {
async fn get_pool_json(&self, name: &str) -> Result<Option<Value>>;
async fn patch_pool_json(&self, name: &str, patch: Value) -> Result<Value>;
async fn billing_status(&self) -> Result<BillingStatus>;
async fn build_image(&self, spec: &BuildSpec, creds: Option<&RegistryCredentials>, progress: Option<BuildProgress<'_>>) -> Result<BuiltImage>;
fn with_claim_secrets_wait(self, wait: ClaimSecretsWait) -> Self;
async fn delete_claim_secret(&self, ns: &str, claim: &str) -> Result<()>;
async fn await_claim_secrets(&self, sandbox: &BoundSandbox, token: &str, runtime: &RuntimeKind) -> Result<()>;
async fn put_registry_secret(&self, namespace: &str, name: &str, registry: &str, creds: &RegistryCredentials) -> Result<()>;
async fn delete_registry_secret(&self, namespace: &str, name: &str) -> Result<()>;
async fn apply_pool(&self, spec: &PoolSpec) -> Result<PoolHandle>; // Deprecated.
async fn get_pool(&self, name: &str) -> Result<PoolHandle>;
async fn pool_runtime(&self, pool: &Pool) -> Option<RuntimeKind>;
async fn pool_services(&self, pool: &Pool) -> Result<BTreeMap<String, u16>>;
async fn delete_pool(&self, handle: PoolHandle) -> Result<()>;
async fn set_pool_replicas(&self, handle: &mut PoolHandle, replicas: u32) -> Result<()>;
async fn wait_pool_ready(&self, handle: &PoolHandle, timeout: Duration) -> Result<Pool>;
async fn claim(&self, pool: &Pool, options: ClaimOptions) -> Result<(Claim, bool)>;
async fn wait_claim(&self, claim: &Claim) -> Result<BoundSandbox>;
async fn acquire(&self, pool: &Pool, options: ClaimOptions) -> Result<BoundSandbox>;
async fn attach_claim(&self, namespace: &str, name: &str) -> Result<BoundSandbox>;
async fn claim_image(&self, namespace: &str, name: &str) -> Result<Option<(String, RuntimeKind)>>;
async fn release(&self, namespace: &str, name: &str) -> Result<()>;
async fn keep_alive(&self, namespace: &str, name: &str, duration: Duration) -> Result<String>;
async fn list_claims(&self, namespace: &str) -> Result<Vec<Claim>>;
async fn find_claims(&self, name: &str) -> Result<Vec<Claim>>;
async fn usage_pricing(&self) -> Result<Option<UsagePricing>>;
async fn apply(&self, name: &str, spec: &SandboxSpec, options: &PoolOptions) -> Result<PoolHandle>;
async fn apply_with_credentials(&self, name: &str, spec: &SandboxSpec, options: &PoolOptions, credentials: Option<&RegistryCredentials>) -> Result<PoolHandle>;
async fn pool_template(&self, pool: &str) -> Result<(SandboxSpec, RuntimeKind, Value)>;
async fn export_pool(&self, pool: &str) -> Result<(SandboxSpec, PoolOptions, RuntimeKind)>;
async fn check_pool_spec(&self, pool: &str, requested: &SandboxSpec) -> Result<()>;
async fn apply_pool_template(&self, pool: &str, requested: &SandboxSpec, credentials: Option<&RegistryCredentials>) -> Result<()>;
fn from_env() -> Result<Self>;
fn connect(config: FleetConfig) -> Result<Self>;
fn connect_with_http_client(config: FleetConfig, http: Arc<dyn HttpClient>) -> Result<Self>;
fn connect_with_token_provider(config: FleetConfig, provider: Arc<dyn AccessTokenProvider>, http: Option<Arc<dyn HttpClient>>) -> Result<Self>;
fn sdk(&self) -> Arc<CyclopsClient>;
fn config(&self) -> &FleetConfig;
async fn access_token(&self, force_refresh: bool) -> Result<String>;
fn service_url(&self, sandbox: &BoundSandbox, service: &str) -> Result<String>;
async fn service_request(&self, sandbox: &BoundSandbox, service: &str, path: &str, method: &str, body: Option<Vec<u8>>, timeout: Option<Duration>) -> Result<HttpResponse>;
async fn service_request_with_headers(&self, sandbox: &BoundSandbox, service: &str, path: &str, method: &str, headers: &[(String, String)], body: Option<Vec<u8>>, timeout: Option<Duration>) -> Result<HttpResponse>;
fn env_connect_options(&self, sandbox: &BoundSandbox, service: &str, env_token: Option<String>) -> Result<ConnectOptions>;
async fn spacesd(&self, sandbox: &BoundSandbox, service: &str, env_token: Option<String>) -> Result<SpacesdClient>;
async fn list_images(&self, namespace: &str) -> Result<Vec<Value>>;
async fn get_image(&self, namespace: &str, name: &str) -> Result<Value>;
async fn create_image(&self, namespace: &str, manifest: Value) -> Result<Value>;
async fn delete_image(&self, namespace: &str, name: &str) -> Result<()>;
async fn upload_image_file(&self, namespace: &str, name: &str, contents: Vec<u8>) -> Result<ImageUploadInstruction>;
async fn create_signed_service_url(&self, sandbox: &BoundSandbox, service: &str, label: Option<String>, expires_in: Duration) -> Result<SignedServiceUrl>;
async fn list_signed_service_urls(&self, sandbox: &BoundSandbox) -> Result<Vec<SignedServiceUrl>>;
async fn revoke_signed_service_url(&self, url: SignedServiceUrl) -> Result<()>;
}FleetConfig#How to reach and authenticate to Fleet.
pub struct FleetConfig {
pub base_url: String,
pub token_url: String,
pub client_id: Option<String>,
pub client_secret: Option<String>,
pub fleet_token: Option<String>,
pub pool_poll_interval_ms: u64,
pub pool_poll_limit: u32,
pub claim_poll_interval_ms: u64,
pub claim_poll_limit: u32,
}
impl FleetConfig {
fn from_env() -> Self;
fn from_lookup(get: impl Fn(&str) -> Option<String>) -> Self;
fn has_auth(&self) -> bool;
}FleetImage#An image resolved for Fleet: the reference to put in ...
pub struct FleetImage {
pub image: String,
pub runtime: RuntimeKind,
pub resolved: Option<ResolvedImage>,
}GcReport#What PoolManager::gc did.
pub struct GcReport {
pub deleted_pools: Vec<String>,
pub deleted_namespaces: Vec<String>,
pub deleted_claims: Vec<String>,
pub kept: Vec<String>,
pub errors: Vec<String>,
}ImageEvidence#What is known about an image before choosing its ...
pub enum ImageEvidence {
Known(ImageVariant),
Unsupported(String),
Unavailable(String),
}ImageInspector#Reads an image's manifest for resolve_runtime.
pub trait ImageInspector: Send + Sync {
async fn inspect(&self, image: &str) -> ImageEvidence;
}ImageResolver#Resolves an image tag to a digest-pinned reference ...
pub trait ImageResolver: Send + Sync {
async fn resolve(&self, image: &str) -> Option<String>;
}ImageVariant#What a Fleet image is, read from its manifest.
pub enum ImageVariant {
ContainerDisk,
Rootfs,
Other,
}
impl ImageVariant {
fn as_str(self) -> &'static str;
fn parse(value: &str) -> Result<Self>;
fn runtime(self) -> Option<RuntimeKind>;
}ManagedClaim#A claim on a managed pool.
pub struct ManagedClaim {
pub pool: String,
pub claim: String,
pub sandbox: BoundSandbox,
pub created_pool: bool,
pub reattached: bool,
pub bind_time: Duration,
pub claim_ttl: Duration,
}
impl ManagedClaim {
fn set_release_on_drop(&mut self, release: bool);
fn extend_until(&self, until: i64);
fn heartbeat_active(&self) -> bool;
async fn release(self) -> Result<()>;
fn detach(self) -> BoundSandbox;
}ManagedPoolInfo#A managed pool as PoolManager::list reports it.
pub struct ManagedPoolInfo {
pub name: String,
pub managed: bool,
pub spec_hash: Option<String>,
pub image: Option<String>,
pub replicas: u32,
pub ready_replicas: Option<u32>,
pub max_pool_size: Option<u32>,
pub claims: u32,
pub bound_claims: u32,
pub last_used: Option<i64>,
pub created: Option<i64>,
pub expires_at: Option<i64>,
pub terminating: bool,
}PoolHandle#A reconciled pool plus the template it owns (when ...
pub struct PoolHandle {
pub pool: Pool,
pub template: Option<Template>,
pub runtime: Option<RuntimeKind>,
pub claim_ttl: Option<Duration>,
}
impl PoolHandle {
fn name(&self) -> &str;
}PoolManager#The auto pool manager.
pub struct PoolManager { /* private fields */ }
impl PoolManager {
fn new(fleet: FleetClient, cfg: AutoPoolConfig) -> Self;
fn with_resolver(self, resolver: Arc<dyn ImageResolver>) -> Self;
fn fleet(&self) -> &FleetClient;
fn config(&self) -> &AutoPoolConfig;
async fn tenant(&self) -> Result<String>;
async fn resolve_key(&self, key: PoolSpecKey) -> PoolSpecKey;
async fn acquire(&self, key: PoolSpecKey, opts: AcquireOpts) -> Result<ManagedClaim>;
fn adopt(&self, sandbox: BoundSandbox, claim_ttl: Option<Duration>) -> ManagedClaim;
async fn ensure_pool(&self, key: &PoolSpecKey, hash: &str, opts: &AcquireOpts) -> Result<(Pool, bool)>;
async fn list(&self) -> Result<Vec<ManagedPoolInfo>>;
async fn gc(&self, idle_after: Duration) -> Result<GcReport>;
async fn gc_pools(&self, idle_after: Duration, only: &[String]) -> Result<GcReport>;
async fn gc_if_due(&self) -> Option<GcReport>;
}PoolOptions#How a pool keeps capacity for a SandboxSpec.
pub struct PoolOptions {
pub runtime: Option<RuntimeKind>,
pub replicas: Option<u32>,
pub warm: Option<bool>,
pub min_pool_size: Option<u32>,
pub max_pool_size: Option<u32>,
pub idle_ttl: Option<Duration>,
pub ttl_policy: Option<TtlPolicy>,
pub pool_ttl: Option<Duration>,
pub claim_ttl: Option<Duration>,
}
impl PoolOptions {
fn autoscaled(&self) -> bool;
fn autoscaling(&self) -> Option<WarmPoolAutoscaling>;
fn validate(&self) -> Result<()>;
fn spec_replicas(&self) -> u32;
fn lifecycle_patch(&self) -> Map<String, Value>;
fn from_pool_json(pool: &Value, runtime: Option<RuntimeKind>) -> Self;
}PoolSpec#Everything needed to reconcile a pool and its template ...
pub struct PoolSpec {
pub name: String,
pub image: String,
pub runtime: RuntimeKind,
pub replicas: u32,
pub cpu: Option<u32>,
pub memory_mb: Option<u32>,
pub services: BTreeMap<String, u16>,
pub readiness_tcp_port: Option<u16>,
pub readiness: Option<ReadinessProbe>,
pub efi: bool,
pub command: Option<Vec<String>>,
pub args: Option<Vec<String>>,
pub env: BTreeMap<String, String>,
pub process_mode: Option<ProcessMode>,
pub autoscaling: Option<WarmPoolAutoscaling>,
pub ttl_seconds_after_created: Option<u32>,
pub idle_ttl_seconds: Option<u32>,
pub ttl_policy: Option<TtlPolicy>,
pub claim_secrets: bool,
pub sidecars: Vec<Sidecar>,
pub image_pull_secret: Option<String>,
pub registry_credentials: Option<RegistryCredentials>,
}
impl PoolSpec {
fn new(name: impl Into<String>, image: impl Into<String>) -> Self;
fn parts(&self) -> (SandboxSpec, PoolOptions);
fn from_parts(name: impl Into<String>, spec: &SandboxSpec, options: &PoolOptions) -> Self;
fn uses_parity(&self) -> bool;
fn validate_parity(&self) -> Result<()>;
fn template_json(&self) -> Result<Value>;
fn claim_secrets(self, enabled: bool) -> Self;
fn runtime(self, runtime: RuntimeKind) -> Self;
fn services<I, S>(self, services: I) -> Self where I: IntoIterator<Item = (S, u16)>, S: Into<String>;
fn readiness_tcp(self, port: u16) -> Self;
fn pool_request(&self) -> CreatePoolRequest;
fn template_request(&self) -> Result<CreateTemplateRequest>;
}PoolSpecKey#What makes two sandboxes interchangeable: they may ...
pub struct PoolSpecKey {
pub image: String,
pub runtime: RuntimeKind,
pub efi: bool,
pub cpu: Option<u32>,
pub memory_mb: Option<u32>,
pub services: BTreeMap<String, u16>,
pub readiness_tcp_port: Option<u16>,
pub command: Option<Vec<String>>,
pub env: BTreeMap<String, String>,
pub sidecars: Vec<Sidecar>,
pub pull_secret: Option<String>,
pub claim_secrets: bool,
}
impl PoolSpecKey {
fn new(image: impl Into<String>) -> Self;
fn runtime(self, runtime: RuntimeKind) -> Self;
fn resources(self, cpu: Option<u32>, memory_mb: Option<u32>) -> Self;
fn services<I, S>(self, services: I) -> Self where I: IntoIterator<Item = (S, u16)>, S: Into<String>;
fn canonical(&self) -> String;
fn spec_hash(&self) -> String;
fn sandbox_spec(&self) -> SandboxSpec;
fn pool_options(&self, initial: u32, max: u32, ttl: Duration) -> PoolOptions;
fn pool_spec(&self, name: &str, initial: u32, max: u32, ttl: Duration) -> PoolSpec;
}ProcessMode#How a sandbox runs command / args / env ...
pub enum ProcessMode {
Legacy,
Run,
}
impl ProcessMode {
fn as_str(&self) -> &'static str;
fn parse(s: &str) -> Result<Self>;
}ReadinessProbe#A readiness probe on a guest port ( ...
pub enum ReadinessProbe {
Tcp { port: u16 },
Http { port: u16, path: String },
}
impl ReadinessProbe {
fn port(&self) -> u16;
}runtime::RegistryInspector#The default ImageInspector: cua_image::resolve ...
pub struct RegistryInspector { /* private fields */ }SandboxSpec#What a sandbox runs.
pub struct SandboxSpec {
pub image: String,
pub command: Option<Vec<String>>,
pub args: Option<Vec<String>>,
pub env: BTreeMap<String, String>,
pub services: BTreeMap<String, u16>,
pub readiness: Option<ReadinessProbe>,
pub cpu: Option<u32>,
pub memory_mb: Option<u32>,
pub efi: bool,
pub sidecars: Vec<Sidecar>,
pub registry_secret: Option<String>,
pub process_mode: Option<ProcessMode>,
pub claim_secrets: bool,
}
impl SandboxSpec {
fn new(image: impl Into<String>) -> Self;
fn effective_process_mode(&self) -> Option<ProcessMode>;
fn validate(&self, runtime: &RuntimeKind) -> Result<()>;
fn typed_template(&self, runtime: &RuntimeKind) -> Result<OSGymSandboxTemplateSpec>;
fn template_json(&self, name: &str, runtime: &RuntimeKind) -> Result<Value>;
fn from_template_json(template: &Value) -> Self;
fn diff(&self, current: &SandboxSpec, image_matches: bool) -> Vec<SpecDiff>;
fn overlay(&self, current: &SandboxSpec) -> SandboxSpec;
}Sidecar#An extra container next to a sandbox.
pub struct Sidecar {
pub name: String,
pub image: String,
pub command: Option<Vec<String>>,
pub env: BTreeMap<String, String>,
pub ports: Vec<u16>,
pub args: Option<Vec<String>>,
pub cpu: Option<String>,
pub memory: Option<String>,
}
impl Sidecar {
fn new(image: impl Into<String>) -> Self;
}SpecDiff#One field where a pool's template differs from the ...
pub struct SpecDiff {
pub field: String,
pub pool: String,
pub requested: String,
}TokenProbe#Asks a bound sandbox whether its driver has the claim's ...
pub trait TokenProbe: Send + Sync {
async fn probe(&self, fleet: &FleetClient, sandbox: &BoundSandbox, token: &str) -> TokenState;
}TokenState#What one token probe saw.
pub enum TokenState {
Delivered,
Awaiting(String),
Unknown(String),
}TtlPolicy#What expiry of the pool TTL or idle TTL deletes ...
pub enum TtlPolicy {
Retain,
Cascade,
}
impl TtlPolicy {
fn as_str(&self) -> &'static str;
fn parse(s: &str) -> Result<Self>;
}UsagePricing#Cua Cloud rates in USD.
pub struct UsagePricing {
pub vcpu_hour_usd: f64,
pub memory_gib_hour_usd: f64,
}
impl UsagePricing {
fn from_config(config: &Value) -> Option<Self>;
fn hourly_usd(&self, cpus: u32, memory_mib: u32) -> f64;
}/// A canonical alias (`linux`, `ubuntu` ...
pub fn canonical_alias(name: &str, env: &dyn Fn(&str) -> Option<String>) -> Option<(String, String)>
/// The canonical image for `os` (`linux` ...
pub fn canonical_image(os: &str) -> String
/// Checks a cloud sandbox size against ...
pub fn check_cloud_size(cpu: Option<u32>, memory_mb: Option<u32>) -> Result<()>
/// Checks a pool size field (`what` ...
pub fn check_pool_size(what: &str, n: u32) -> Result<()>
/// Refuses `RESERVED_SERVICE_NAMES` in ...
pub fn check_reserved_service_names<'a>(services: impl IntoIterator<Item = &'a String>, has_sidecars: bool) -> Result<()>
/// Validates the runtime/image pairing ...
pub fn check_runtime(runtime: Option<RuntimeKind>, image: &str, evidence: &ImageEvidence) -> Result<RuntimeKind>
/// Forgets cached rates (sign-out, tests).
pub fn clear_pricing_cache()
/// redis for docker. ...
pub fn default_sidecar_name(image: &str) -> String
/// Refuses a runtime this SDK does not ...
pub fn ensure_runtime_offered(runtime: &RuntimeKind) -> Result<()>
/// Name of an ephemeral pool: cua-eph-<12 ...
pub fn ephemeral_pool_name() -> String
/// The readable diff of a ...
pub fn format_diffs(diffs: &[SpecDiff]) -> String
/// Reads what `image` is through the ...
pub async fn inspect_image(image: &str) -> ImageEvidence
/// Whether `image` is one of the canonical ...
pub fn is_canonical_image(image: &str) -> bool
/// Parses a runtime name to create or ...
pub fn parse_runtime(value: &str) -> Result<Option<RuntimeKind>>
/// The deterministic Secret name for ...
pub fn registry_secret_name(registry: &str, username: &str) -> String
/// The error for a remote image build ...
pub fn remote_builds_unsupported(what: &str) -> Error
/// The one Fleet image rule: resolve ...
pub async fn resolve_fleet_image(runtime: Option<RuntimeKind>, image: &str) -> Result<FleetImage>
/// `resolve_fleet_image` reading a private ...
pub async fn resolve_fleet_image_with(runtime: Option<RuntimeKind>, image: &str, creds: Option<&RegistryCredentials>) -> Result<FleetImage>
/// `resolve_fleet_image`, returning only ...
pub async fn resolve_runtime(runtime: Option<RuntimeKind>, image: &str) -> Result<RuntimeKind>
/// The fallback runtime for an image whose ...
pub fn runtime_from_reference(image: &str) -> RuntimeKind
/// The wire spelling of a runtime (`macos` ...
pub fn runtime_name(runtime: &RuntimeKind) -> &'static str
/// `Error::is_not_found` for a bare ...
pub fn sdk_error_is_not_found(e: &SdkError) -> bool
/// Replaces the process-wide ...
pub fn set_image_inspector(inspector: Option<Arc<dyn ImageInspector>>)
/// A `fleets_pool` resource block (the ...
pub fn terraform_pool_block(name: &str, spec: &SandboxSpec, options: &PoolOptions, runtime: &RuntimeKind) -> String
/// Checks sidecars the way Fleet's ...
pub fn validate_sidecars(sidecars: &[Sidecar], reserved: &[u16]) -> Result<()>
// mod autopool
/// The base pool name for a tenant and ...
pub fn auto_pool_name(tenant: &str, spec_hash: &str) -> String
/// Every candidate name, in probe order ...
pub fn candidate_names(tenant: &str, spec_hash: &str) -> Vec<String>
/// Default home: `$CUA_HOME`, else ...
pub fn default_cua_home() -> PathBuf
/// The tenant a bearer belongs to: the JWT ...
pub fn tenant_from_token(token: &str) -> String
// mod builds
/// The content-addressed Image name for a ...
pub fn build_name(recipe: &ImageRecipe) -> String
/// The build namespace for a tenant ...
pub fn build_namespace(tenant: &str) -> String
/// The recipe a build of `spec` on `base` ...
pub fn build_recipe(spec: &BuildSpec, base: &str, files: Vec<ImageFile>, from_pull_secret: Option<String>) -> ImageRecipe
/// A local build's content-addressed ...
pub fn local_build_file(f: &BuildFile) -> Result<ImageFile>
// mod claim_secrets
/// The Opaque Secret the SDK writes for ...
pub fn claim_secret_body(namespace: &str, claim: &str, token: &str) -> Value
/// A fresh env token: 64 hex characters ...
pub fn generate_claim_token() -> String
/// Checks a claim token with cua-spacesd's ...
pub fn validate_claim_token(token: &str) -> Result<()>
// mod parity
/// The Secret body #7887's admission ...
pub fn registry_secret_body(namespace: &str, name: &str, registry: &str, creds: &RegistryCredentials) -> Result<Value>
/// `vmTemplate.sidecars[]` entries ...
pub fn sidecars_json(sidecars: &[Sidecar]) -> Value
// mod runtime
/// Classifies already-fetched documents ...
pub fn classify_manifest(index: Option<&ImageIndex>, manifest: Option<&ImageManifest>, config: Option<&Value>) -> Result<ImageVariant>
/// `classify_manifest` over raw JSON ...
pub fn classify_manifest_json(manifest: &str, config: Option<&str>) -> Result<ImageVariant>
/// The tag of an image reference, or ...
pub fn image_tag(image: &str) -> Option<&str>
// mod spec
/// `4096Mi`, `4Gi`, `512M`, `4G` → MiB.
pub fn parse_memory_mib(q: &str) -> Option<u32>/// The everyday vCPU range of a cloud ...
pub const CLOUD_DEFAULT_RANGE_CPUS: RangeInclusive<u32> = _;
/// The everyday memory range of a cloud ...
pub const CLOUD_DEFAULT_RANGE_MEMORY_MB: RangeInclusive<u32> = _;
/// Default Fleet API endpoint ...
pub const DEFAULT_FLEET_BASE_URL: &str = "https://run.cua.ai";
/// Poll interval cua-sandbox uses for ...
pub const DEFAULT_POLL_INTERVAL_MS: u64 = 2000;
/// Poll limit cua-sandbox uses for pools ...
pub const DEFAULT_POLL_LIMIT: u32 = 300;
/// Default OAuth token endpoint ...
pub const DEFAULT_TOKEN_URL: &str = /* ... */;
/// vCPUs per cloud sandbox ...
pub const FLEET_ABSOLUTE_CPUS: RangeInclusive<u32> = _;
/// Most sandboxes per pool ...
pub const FLEET_ABSOLUTE_MAX_POOL_SIZE: u32 = 50;
/// Memory per cloud sandbox in MiB ...
pub const FLEET_ABSOLUTE_MEMORY_MB: RangeInclusive<u32> = _;
/// Why a macOS image or the `macos` ...
pub const MACOS_UNSUPPORTED: &str = cua_image::resolve::FLEET_MACOS_UNSUPPORTED;
/// The hostname sidecars reach the sandbox ...
pub const MAIN_CONTAINER_NAME: &str = "main";
/// Most sidecars a template may carry ...
pub const MAX_SIDECARS: usize = 8;
/// The one "no Fleet credentials" message ...
pub const MISSING_CREDENTIALS: &str = "Fleet credentials missing: run `cua auth login` or set \
CUA_CLIENT_ID/CUA_CLIENT_SECRET, or pass local=True";
/// How long an answer is reused.
pub const PRICING_TTL: Duration = _;
/// Name prefix of tenant registry pull ...
pub const REGISTRY_SECRET_PREFIX: &str = "cua-registry-";
/// Whether Fleet builds `kind: container` ...
pub const REMOTE_BUILDS_SUPPORTED: bool = false;
/// Service names a sandbox with sidecars ...
pub const RESERVED_SERVICE_NAMES: [&str; 3] = _;
// mod autopool
/// Name prefix of managed pools.
pub const AUTO_POOL_PREFIX: &str = "cua-auto-";
/// Default idle threshold of the automatic ...
pub const DEFAULT_IDLE_GC_SECS: u64 = _;
/// Name prefix of legacy ephemeral pools ...
pub const EPHEMERAL_POOL_PREFIX: &str = "cua-eph-";
/// Label carrying the last use (unix ...
pub const LABEL_LAST_USED: &str = "cua.ai/last-used";
/// Label naming the creator.
pub const LABEL_MANAGED_BY: &str = "cua.ai/managed-by";
/// Label carrying the first 32 hex digits ...
pub const LABEL_SPEC_HASH: &str = "cua.ai/spec-hash";
/// Value of `LABEL_MANAGED_BY`.
pub const MANAGED_BY: &str = "cua-sdk";
/// Candidate names tried per key before ...
pub const MAX_NAME_PROBES: usize = 8;
/// Floor of a claim's `bindDeadline`: live ...
pub const MIN_BIND_DEADLINE_SECS: u64 = 900;
/// Hex digits of the spec hash stored in ...
pub const SPEC_HASH_LABEL_LEN: usize = 32;
// mod builds
/// Prefix of content-named Image resources.
pub const BUILD_NAME_PREFIX: &str = "cua-b-";
/// Prefix of the per-account build ...
pub const BUILD_NAMESPACE_PREFIX: &str = "cua-build-";
/// Default build budget.
pub const DEFAULT_BUILD_TIMEOUT: Duration = _;
/// Most environment variables a remote ...
pub const MAX_BUILD_ENV: usize = 128;
/// Longest environment value a remote ...
pub const MAX_BUILD_ENV_VALUE: usize = 8192;
/// Largest file `copy` uploads (read into ...
pub const MAX_COPY_BYTES: u64 = _;
// mod claim_secrets
/// Label on a claim Secret naming its ...
pub const CLAIM_SECRET_CLAIM_LABEL: &str = "osgym.cua.ai/claim";
/// Name prefix of a claim's Secret ...
pub const CLAIM_SECRET_PREFIX: &str = "cua-claim-";
/// Longest wait after Bound for the token ...
pub const DEFAULT_WAIT: Duration = _;
/// The Secret key (and in-guest file name) ...
pub const ENV_TOKEN_KEY: &str = "env-token";
/// Pause between token probes.
pub const PROBE_EVERY: Duration = _;
/// Claim secrets are always available ...
pub const SUPPORTED: bool = true;
// mod runtime
/// Set to `0`/`off`/`false` to skip ...
pub const INSPECT_ENV: &str = "CUA_FLEET_IMAGE_INSPECT";
// mod spec
/// Default autoscaling ceiling of a pool ...
pub const DEFAULT_MAX_POOL_SIZE: u32 = 10;/// Result alias.
pub type Result<T, E = Error> = Result<T, E>;
// mod autopool
/// Clock returning unix seconds (tests ...
pub type Clock = Arc<dyn Fn() -> i64 + Send + Sync>;
// mod builds
/// Progress of a remote build, in the ...
pub type BuildProgress<'a> = &'a dyn Fn(&str) + Send + Sync;cyclops_sdk::Sandbox, cyclops_sdk::Claim, cyclops_sdk::HttpClient, cua_image::spec::ImageLayer, cua_image::normalize_registry, cua_image::RegistryCredentials, cyclops_sdk::Pool, cua_image::registry_of, parity::RegistryCredentials, pool::RuntimeKind, cyclops_sdk_schema, cyclops_sdk, cyclops_sdk::SdkError, cyclops_sdk::Template.