Documentation
¶
Index ¶
- Variables
- type DiskStore
- func (s *DiskStore) Ack(_ context.Context, claim lifecycle.Claim) error
- func (s *DiskStore) Append(_ context.Context, event lifecycle.Event) error
- func (s *DiskStore) Claim(_ context.Context, now time.Time, lease time.Duration) (lifecycle.Claim, error)
- func (s *DiskStore) Compact(_ context.Context, before time.Time) error
- func (s *DiskStore) CreateSandbox(ctx context.Context, sb model.Sandbox) error
- func (s *DiskStore) Delete(_ context.Context, id jobs.ID) error
- func (s *DiskStore) DeleteAPIKey(_ context.Context, id model.APIKeyID) error
- func (s *DiskStore) DeleteAgentToken(_ context.Context, id model.AgentTokenID) error
- func (s *DiskStore) DeleteExecution(_ context.Context, id model.ExecutionID) error
- func (s *DiskStore) DeletePoolGuestCredential(ctx context.Context, poolName model.PoolName) error
- func (s *DiskStore) DeleteResource(_ context.Context, id model.ResourceID) error
- func (s *DiskStore) DeleteSandbox(_ context.Context, id model.SandboxID) error
- func (s *DiskStore) DeleteSession(_ context.Context, id model.SessionID) error
- func (s *DiskStore) Fail(_ context.Context, claim lifecycle.Claim, cause error) error
- func (s *DiskStore) Get(_ context.Context, id jobs.ID) (jobs.Job, error)
- func (s *DiskStore) GetAPIKey(_ context.Context, id model.APIKeyID) (model.APIKey, error)
- func (s *DiskStore) GetAgentIdentity(_ context.Context, agentID string) (model.AgentIdentity, error)
- func (s *DiskStore) GetAgentToken(_ context.Context, id model.AgentTokenID) (model.AgentRegistrationToken, error)
- func (s *DiskStore) GetExecution(_ context.Context, id model.ExecutionID) (model.Execution, error)
- func (s *DiskStore) GetLocalAdmin(_ context.Context) (model.LocalAdminAccount, error)
- func (s *DiskStore) GetPool(ctx context.Context, name model.PoolName) (model.Pool, error)
- func (s *DiskStore) GetPoolGuestCredential(ctx context.Context, poolName model.PoolName) (string, error)
- func (s *DiskStore) GetResource(ctx context.Context, id model.ResourceID) (model.Resource, error)
- func (s *DiskStore) GetSandbox(ctx context.Context, id model.SandboxID) (model.Sandbox, error)
- func (s *DiskStore) GetSession(_ context.Context, id model.SessionID) (model.Session, error)
- func (s *DiskStore) IsAgentIdentityRevoked(_ context.Context, certSerial string) (bool, error)
- func (s *DiskStore) List(_ context.Context) ([]jobs.Job, error)
- func (s *DiskStore) ListAPIKeys(_ context.Context) ([]model.APIKey, error)
- func (s *DiskStore) ListAgentTokens(_ context.Context) ([]model.AgentRegistrationToken, error)
- func (s *DiskStore) ListExecutions(_ context.Context) ([]model.Execution, error)
- func (s *DiskStore) ListPoolGuestCredentials(ctx context.Context) (map[model.PoolName]string, error)
- func (s *DiskStore) ListPools(_ context.Context) ([]model.Pool, error)
- func (s *DiskStore) ListResources(_ context.Context) ([]model.Resource, error)
- func (s *DiskStore) ListRevokedAgentIdentities(_ context.Context) ([]model.RevokedAgentIdentity, error)
- func (s *DiskStore) ListSandboxes(_ context.Context) ([]model.Sandbox, error)
- func (s *DiskStore) ListSessions(_ context.Context) ([]model.Session, error)
- func (s *DiskStore) Put(_ context.Context, job jobs.Job) error
- func (s *DiskStore) PutAPIKey(_ context.Context, key model.APIKey) error
- func (s *DiskStore) PutAgentIdentity(_ context.Context, identity model.AgentIdentity) error
- func (s *DiskStore) PutAgentToken(_ context.Context, tok model.AgentRegistrationToken) error
- func (s *DiskStore) PutExecution(_ context.Context, execution model.Execution) error
- func (s *DiskStore) PutLocalAdmin(_ context.Context, account model.LocalAdminAccount) error
- func (s *DiskStore) PutPool(ctx context.Context, pool model.Pool) error
- func (s *DiskStore) PutPoolGuestCredential(ctx context.Context, poolName model.PoolName, credential string) error
- func (s *DiskStore) PutResource(ctx context.Context, res model.Resource) error
- func (s *DiskStore) PutRevokedAgentIdentity(_ context.Context, rev model.RevokedAgentIdentity) error
- func (s *DiskStore) PutSandbox(ctx context.Context, sb model.Sandbox) error
- func (s *DiskStore) PutSession(_ context.Context, session model.Session) error
- func (s *DiskStore) Retry(_ context.Context, claim lifecycle.Claim, availableAt time.Time, cause error) error
- type LegacyPoolGuestCredentialStore
- type MemoryStore
- func (s *MemoryStore) Ack(_ context.Context, claim lifecycle.Claim) error
- func (s *MemoryStore) Append(_ context.Context, event lifecycle.Event) error
- func (s *MemoryStore) Claim(_ context.Context, now time.Time, lease time.Duration) (lifecycle.Claim, error)
- func (s *MemoryStore) Compact(_ context.Context, before time.Time) error
- func (s *MemoryStore) CreateSandbox(ctx context.Context, sb model.Sandbox) error
- func (s *MemoryStore) Delete(_ context.Context, id jobs.ID) error
- func (s *MemoryStore) DeleteAPIKey(_ context.Context, id model.APIKeyID) error
- func (s *MemoryStore) DeleteAgentToken(_ context.Context, id model.AgentTokenID) error
- func (s *MemoryStore) DeleteExecution(_ context.Context, id model.ExecutionID) error
- func (s *MemoryStore) DeletePoolGuestCredential(ctx context.Context, poolName model.PoolName) error
- func (s *MemoryStore) DeleteResource(_ context.Context, id model.ResourceID) error
- func (s *MemoryStore) DeleteSandbox(_ context.Context, id model.SandboxID) error
- func (s *MemoryStore) DeleteSession(_ context.Context, id model.SessionID) error
- func (s *MemoryStore) Fail(_ context.Context, claim lifecycle.Claim, cause error) error
- func (s *MemoryStore) Get(_ context.Context, id jobs.ID) (jobs.Job, error)
- func (s *MemoryStore) GetAPIKey(_ context.Context, id model.APIKeyID) (model.APIKey, error)
- func (s *MemoryStore) GetAgentIdentity(_ context.Context, agentID string) (model.AgentIdentity, error)
- func (s *MemoryStore) GetAgentToken(_ context.Context, id model.AgentTokenID) (model.AgentRegistrationToken, error)
- func (s *MemoryStore) GetExecution(_ context.Context, id model.ExecutionID) (model.Execution, error)
- func (s *MemoryStore) GetLocalAdmin(_ context.Context) (model.LocalAdminAccount, error)
- func (s *MemoryStore) GetPool(ctx context.Context, name model.PoolName) (model.Pool, error)
- func (s *MemoryStore) GetPoolGuestCredential(ctx context.Context, poolName model.PoolName) (string, error)
- func (s *MemoryStore) GetResource(ctx context.Context, id model.ResourceID) (model.Resource, error)
- func (s *MemoryStore) GetSandbox(ctx context.Context, id model.SandboxID) (model.Sandbox, error)
- func (s *MemoryStore) GetSession(_ context.Context, id model.SessionID) (model.Session, error)
- func (s *MemoryStore) IsAgentIdentityRevoked(_ context.Context, certSerial string) (bool, error)
- func (s *MemoryStore) List(_ context.Context) ([]jobs.Job, error)
- func (s *MemoryStore) ListAPIKeys(_ context.Context) ([]model.APIKey, error)
- func (s *MemoryStore) ListAgentTokens(_ context.Context) ([]model.AgentRegistrationToken, error)
- func (s *MemoryStore) ListExecutions(_ context.Context) ([]model.Execution, error)
- func (s *MemoryStore) ListPoolGuestCredentials(ctx context.Context) (map[model.PoolName]string, error)
- func (s *MemoryStore) ListPools(_ context.Context) ([]model.Pool, error)
- func (s *MemoryStore) ListResources(_ context.Context) ([]model.Resource, error)
- func (s *MemoryStore) ListRevokedAgentIdentities(_ context.Context) ([]model.RevokedAgentIdentity, error)
- func (s *MemoryStore) ListSandboxes(_ context.Context) ([]model.Sandbox, error)
- func (s *MemoryStore) ListSessions(_ context.Context) ([]model.Session, error)
- func (s *MemoryStore) Put(_ context.Context, job jobs.Job) error
- func (s *MemoryStore) PutAPIKey(_ context.Context, key model.APIKey) error
- func (s *MemoryStore) PutAgentIdentity(_ context.Context, identity model.AgentIdentity) error
- func (s *MemoryStore) PutAgentToken(_ context.Context, tok model.AgentRegistrationToken) error
- func (s *MemoryStore) PutExecution(_ context.Context, execution model.Execution) error
- func (s *MemoryStore) PutLocalAdmin(_ context.Context, account model.LocalAdminAccount) error
- func (s *MemoryStore) PutPool(ctx context.Context, pool model.Pool) error
- func (s *MemoryStore) PutPoolGuestCredential(ctx context.Context, poolName model.PoolName, credential string) error
- func (s *MemoryStore) PutResource(ctx context.Context, res model.Resource) error
- func (s *MemoryStore) PutRevokedAgentIdentity(_ context.Context, rev model.RevokedAgentIdentity) error
- func (s *MemoryStore) PutSandbox(ctx context.Context, sb model.Sandbox) error
- func (s *MemoryStore) PutSession(_ context.Context, session model.Session) error
- func (s *MemoryStore) Retry(_ context.Context, claim lifecycle.Claim, availableAt time.Time, cause error) error
- type Store
Constants ¶
This section is empty.
Variables ¶
var ErrNotFound = errors.New("not found")
Functions ¶
This section is empty.
Types ¶
type DiskStore ¶
type DiskStore struct {
// contains filtered or unexported fields
}
DiskStore is a simple JSON-backed Store implementation.
It exists to make the CLI work end-to-end in environments where pulling new dependencies (e.g. bbolt) is not possible. It can be replaced with a bbolt implementation later without changing the Store interface.
func NewDiskStore ¶
func (*DiskStore) CreateSandbox ¶
func (*DiskStore) DeleteAPIKey ¶ added in v0.1.34
func (*DiskStore) DeleteAgentToken ¶
func (*DiskStore) DeleteExecution ¶ added in v0.1.60
func (*DiskStore) DeletePoolGuestCredential ¶ added in v0.1.42
DeletePoolGuestCredential removes a legacy plaintext pool credential. New runtime code stores credentials through pkg/secrets; this method exists for the explicit migration command only.
func (*DiskStore) DeleteResource ¶
func (*DiskStore) DeleteSandbox ¶
func (*DiskStore) DeleteSession ¶ added in v0.1.53
func (*DiskStore) GetAgentIdentity ¶
func (*DiskStore) GetAgentToken ¶
func (s *DiskStore) GetAgentToken(_ context.Context, id model.AgentTokenID) (model.AgentRegistrationToken, error)
func (*DiskStore) GetExecution ¶ added in v0.1.60
func (*DiskStore) GetLocalAdmin ¶ added in v0.1.53
func (*DiskStore) GetPoolGuestCredential ¶ added in v0.1.40
func (*DiskStore) GetResource ¶
func (*DiskStore) GetSandbox ¶
func (*DiskStore) GetSession ¶ added in v0.1.53
func (*DiskStore) IsAgentIdentityRevoked ¶
IsAgentIdentityRevoked does a linear scan over revoked identities — an accepted tradeoff at the expected 10s-100s scale, rather than maintaining a secondary index keyed by cert serial.
func (*DiskStore) ListAPIKeys ¶ added in v0.1.34
func (*DiskStore) ListAgentTokens ¶
func (*DiskStore) ListExecutions ¶ added in v0.1.60
func (*DiskStore) ListPoolGuestCredentials ¶ added in v0.1.42
func (*DiskStore) ListResources ¶
func (*DiskStore) ListRevokedAgentIdentities ¶
func (*DiskStore) ListSandboxes ¶
func (*DiskStore) ListSessions ¶ added in v0.1.53
func (*DiskStore) PutAgentIdentity ¶
func (*DiskStore) PutAgentToken ¶
func (*DiskStore) PutExecution ¶ added in v0.1.60
func (*DiskStore) PutLocalAdmin ¶ added in v0.1.53
func (*DiskStore) PutPoolGuestCredential ¶ added in v0.1.40
func (*DiskStore) PutResource ¶
func (*DiskStore) PutRevokedAgentIdentity ¶
func (*DiskStore) PutSandbox ¶
func (*DiskStore) PutSession ¶ added in v0.1.53
type LegacyPoolGuestCredentialStore ¶ added in v0.1.42
type LegacyPoolGuestCredentialStore interface {
ListPoolGuestCredentials(context.Context) (map[model.PoolName]string, error)
DeletePoolGuestCredential(context.Context, model.PoolName) error
}
LegacyPoolGuestCredentialStore is the migration-only surface for plaintext credentials embedded in the historical state.json format.
type MemoryStore ¶
type MemoryStore struct {
// contains filtered or unexported fields
}
MemoryStore is an in-memory Store implementation for scaffolding and tests.
func NewMemoryStore ¶
func NewMemoryStore() *MemoryStore
func (*MemoryStore) CreateSandbox ¶
func (*MemoryStore) DeleteAPIKey ¶ added in v0.1.34
func (*MemoryStore) DeleteAgentToken ¶
func (s *MemoryStore) DeleteAgentToken(_ context.Context, id model.AgentTokenID) error
func (*MemoryStore) DeleteExecution ¶ added in v0.1.60
func (s *MemoryStore) DeleteExecution(_ context.Context, id model.ExecutionID) error
func (*MemoryStore) DeletePoolGuestCredential ¶ added in v0.1.42
DeletePoolGuestCredential removes a legacy plaintext pool credential. New runtime code stores credentials through pkg/secrets; this method exists for the explicit migration command only.
func (*MemoryStore) DeleteResource ¶
func (s *MemoryStore) DeleteResource(_ context.Context, id model.ResourceID) error
func (*MemoryStore) DeleteSandbox ¶
func (*MemoryStore) DeleteSession ¶ added in v0.1.53
func (*MemoryStore) GetAgentIdentity ¶
func (s *MemoryStore) GetAgentIdentity(_ context.Context, agentID string) (model.AgentIdentity, error)
func (*MemoryStore) GetAgentToken ¶
func (s *MemoryStore) GetAgentToken(_ context.Context, id model.AgentTokenID) (model.AgentRegistrationToken, error)
func (*MemoryStore) GetExecution ¶ added in v0.1.60
func (s *MemoryStore) GetExecution(_ context.Context, id model.ExecutionID) (model.Execution, error)
func (*MemoryStore) GetLocalAdmin ¶ added in v0.1.53
func (s *MemoryStore) GetLocalAdmin(_ context.Context) (model.LocalAdminAccount, error)
func (*MemoryStore) GetPoolGuestCredential ¶ added in v0.1.40
func (*MemoryStore) GetResource ¶
func (s *MemoryStore) GetResource(ctx context.Context, id model.ResourceID) (model.Resource, error)
func (*MemoryStore) GetSandbox ¶
func (*MemoryStore) GetSession ¶ added in v0.1.53
func (*MemoryStore) IsAgentIdentityRevoked ¶
func (*MemoryStore) ListAPIKeys ¶ added in v0.1.34
func (*MemoryStore) ListAgentTokens ¶
func (s *MemoryStore) ListAgentTokens(_ context.Context) ([]model.AgentRegistrationToken, error)
func (*MemoryStore) ListExecutions ¶ added in v0.1.60
func (*MemoryStore) ListPoolGuestCredentials ¶ added in v0.1.42
func (*MemoryStore) ListResources ¶
func (*MemoryStore) ListRevokedAgentIdentities ¶
func (s *MemoryStore) ListRevokedAgentIdentities(_ context.Context) ([]model.RevokedAgentIdentity, error)
func (*MemoryStore) ListSandboxes ¶
func (*MemoryStore) ListSessions ¶ added in v0.1.53
func (*MemoryStore) PutAgentIdentity ¶
func (s *MemoryStore) PutAgentIdentity(_ context.Context, identity model.AgentIdentity) error
func (*MemoryStore) PutAgentToken ¶
func (s *MemoryStore) PutAgentToken(_ context.Context, tok model.AgentRegistrationToken) error
func (*MemoryStore) PutExecution ¶ added in v0.1.60
func (*MemoryStore) PutLocalAdmin ¶ added in v0.1.53
func (s *MemoryStore) PutLocalAdmin(_ context.Context, account model.LocalAdminAccount) error
func (*MemoryStore) PutPoolGuestCredential ¶ added in v0.1.40
func (*MemoryStore) PutResource ¶
func (*MemoryStore) PutRevokedAgentIdentity ¶
func (s *MemoryStore) PutRevokedAgentIdentity(_ context.Context, rev model.RevokedAgentIdentity) error
func (*MemoryStore) PutSandbox ¶
func (*MemoryStore) PutSession ¶ added in v0.1.53
type Store ¶
type Store interface {
jobs.Store
// Pools
GetPool(ctx context.Context, name model.PoolName) (model.Pool, error)
PutPool(ctx context.Context, pool model.Pool) error
PutPoolGuestCredential(ctx context.Context, poolName model.PoolName, credential string) error
GetPoolGuestCredential(ctx context.Context, poolName model.PoolName) (string, error)
// Resources
GetResource(ctx context.Context, id model.ResourceID) (model.Resource, error)
PutResource(ctx context.Context, res model.Resource) error
DeleteResource(ctx context.Context, id model.ResourceID) error
// Sandboxes
GetSandbox(ctx context.Context, id model.SandboxID) (model.Sandbox, error)
CreateSandbox(ctx context.Context, sb model.Sandbox) error
PutSandbox(ctx context.Context, sb model.Sandbox) error
DeleteSandbox(ctx context.Context, id model.SandboxID) error
// Durable sandbox executions. Implementations must make each Put atomic
// with respect to concurrent readers; callers update one execution at a
// time, so no separate transaction API is needed for the JSON backend.
GetExecution(ctx context.Context, id model.ExecutionID) (model.Execution, error)
PutExecution(ctx context.Context, execution model.Execution) error
DeleteExecution(ctx context.Context, id model.ExecutionID) error
ListExecutions(ctx context.Context) ([]model.Execution, error)
// Agent registration tokens (single-use bootstrap credentials, see
// docs/adr/0005-remote-agent-transport-and-registration.md). PutAgentToken
// doubles as both create and mark-used: callers read, mutate UsedAt, and
// write back, the same upsert convention used for sandboxes/resources.
GetAgentToken(ctx context.Context, id model.AgentTokenID) (model.AgentRegistrationToken, error)
PutAgentToken(ctx context.Context, tok model.AgentRegistrationToken) error
DeleteAgentToken(ctx context.Context, id model.AgentTokenID) error
ListAgentTokens(ctx context.Context) ([]model.AgentRegistrationToken, error)
// Operator API keys. Only hashes and metadata are persisted; raw key values
// are returned once at creation and are never stored by the daemon.
GetAPIKey(ctx context.Context, id model.APIKeyID) (model.APIKey, error)
PutAPIKey(ctx context.Context, key model.APIKey) error
DeleteAPIKey(ctx context.Context, id model.APIKeyID) error
ListAPIKeys(ctx context.Context) ([]model.APIKey, error)
// Web-UI login sessions (see model.Session). Only hashes and metadata
// are persisted, the same discipline as API keys; ListSessions backs
// authentication (linear scan + constant-time compare, same pattern
// as ListAPIKeys/auth.Authenticate) and expiry sweeping.
GetSession(ctx context.Context, id model.SessionID) (model.Session, error)
PutSession(ctx context.Context, session model.Session) error
DeleteSession(ctx context.Context, id model.SessionID) error
ListSessions(ctx context.Context) ([]model.Session, error)
// LocalAdminAccount is the single bootstrapped local-admin account (see
// model.LocalAdminAccount). GetLocalAdmin returns ErrNotFound before
// the daemon has ever bootstrapped one.
GetLocalAdmin(ctx context.Context) (model.LocalAdminAccount, error)
PutLocalAdmin(ctx context.Context, account model.LocalAdminAccount) error
// Revoked agent identities (deny-list, keyed by client certificate
// serial). No bbolt or other new persistence engine — this reuses the
// same Store this interface already defines, since revocation counts
// are expected to stay in the 10s-100s.
PutRevokedAgentIdentity(ctx context.Context, rev model.RevokedAgentIdentity) error
IsAgentIdentityRevoked(ctx context.Context, certSerial string) (bool, error)
ListRevokedAgentIdentities(ctx context.Context) ([]model.RevokedAgentIdentity, error)
// Agent identities record which cert serial an agent ID currently
// holds, so `boxy agent revoke <id>` can populate a serial-keyed
// RevokedAgentIdentity even for a currently-disconnected agent.
PutAgentIdentity(ctx context.Context, identity model.AgentIdentity) error
GetAgentIdentity(ctx context.Context, agentID string) (model.AgentIdentity, error)
// List operations return all entities of a given type.
// An empty store returns a non-nil, zero-length slice.
ListPools(ctx context.Context) ([]model.Pool, error)
ListResources(ctx context.Context) ([]model.Resource, error)
ListSandboxes(ctx context.Context) ([]model.Sandbox, error)
}
Store is the minimal persistence surface the runtime managers need.
This is intentionally small and may be split into narrower interfaces later.