Secret
Secrets the SDK writes in a pool's namespace: a claim's env token and registry pull credentials.
Secrets the SDK writes in a pool's namespace: a claim's env token and registry pull credentials.
Every claim the SDK makes carries a fresh env token for the sandbox's cua-spacesd. The SDK writes it as an Opaque Secret cua-claim-<claim> (key env-token, label osgym.cua.ai/claim: <claim>), then creates the claim with spec.secretRef naming it. Fleet delivers it into the bound sandbox at /run/cua/env-token; the token never crosses the network to the guest. After the claim binds, the SDK waits up to 90 seconds for the guest to accept the token, then releases the claim with ClaimSecretsNotDelivered.
{
"apiVersion": "v1",
"data": {
"env-token": "MDEyMzQ1Njc4OWFiY2RlZjAxMjM0NTY3ODlhYmNkZWYwMTIzNDU2Nzg5YWJjZGVmMDEyMzQ1Njc4OWFiY2RlZg=="
},
"kind": "Secret",
"metadata": {
"labels": {
"osgym.cua.ai/claim": "claim-1"
},
"name": "cua-claim-claim-1",
"namespace": "my-pool"
},
"type": "Opaque"
}Credentials for a private registry, written as a kubernetes.io/dockerconfigjson Secret cua-registry-<16 hex> (a hash of registry and user, so a new password updates the same Secret) and named by the template's imagePullSecret.
{
"apiVersion": "v1",
"data": {
".dockerconfigjson": "eyJhdXRocyI6eyJnaGNyLmlvIjp7ImF1dGgiOiJiMk4wYjJOaGREbzhkRzlyWlc0KyIsInBhc3N3b3JkIjoiPHRva2VuPiIsInVzZXJuYW1lIjoib2N0b2NhdCJ9fX0="
},
"kind": "Secret",
"metadata": {
"labels": {
"cua.ai/registry-secret": "true"
},
"name": "cua-registry-91c6584ad5bdef3a",
"namespace": "my-pool"
},
"type": "kubernetes.io/dockerconfigjson"
}Secrets are core Kubernetes objects behind the same proxy as the Fleet resources.
POST /api/k8s/api/v1/namespaces/{namespace}/secretsBody: the Secret. 409 means a Secret of that name exists (another claim attempt); the SDK does not overwrite it.
DELETE /api/k8s/api/v1/namespaces/{namespace}/secrets/{name}404 is treated as success. The SDK deletes a claim's Secret when it releases the claim.