Project templates on top of the agent template #5
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Motivation
Some projects need heavy, project-specific tooling in the VM: a database
server, a DCC application, language runtimes. That does not belong in the
shared agent template, but installing it by hand in each sandbox is lost on
every
remove && createand needs a wide network allowlist at runtime.Proposal
A project template is built from the agent template plus a provisioning
script that the project provides (referenced from the manifest, see
#3 (Multi-repo projects: design)):
audit-template.shruns on the result, as today: a project template mustnot capture credentials either. This matters more here, because a
provisioning step may log in to something (a license server, a registry).
agentbox createuses the manifest's template when set.build time, not downloaded in the VM, so the builder allowlist stays small.
To evaluate first
sbx kitmixins (experimental in 0.46) declare network policies, env vars,startup commands and files. A kit might cover the "start a service when the
sandbox starts" part better than a template does. Template for the heavy
install, kit for the runtime wiring?
Done when
The e2e suite builds a small project template (e.g. one extra package) and
creates a sandbox from it.
--no-share-skillsis gone #2