Skip to search

SandboxConfig

ate.dev / v1alpha1

apiVersion: ate.dev/v1alpha1 kind: SandboxConfig metadata: name: example
View raw schema
apiVersion string
APIVersion defines the versioned schema of this representation of an object. Servers should convert recognized schemas to the latest internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
kind string
Kind is a string value representing the REST resource this object represents. Servers may infer this from the endpoint the client submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
metadata object
spec object required
spec defines the desired state of SandboxConfig
assets object
Assets is the set of files atelet fetches for this runtime, keyed first by architecture (GOARCH, e.g. "amd64", "arm64") and then by asset name. The asset names are interpreted by the sandbox backend: gVisor expects a "gvisor" asset (the release's gvisor.tar.bz2, which atelet extracts so the gvisor-bin/ helpers sit next to runsc; a legacy bare-binary "runsc" asset is still accepted); a micro-VM backend expects several (e.g. "cloud-hypervisor", "kata-kernel", "kata-image"). The schema is intentionally generic; per-class requirements are enforced by a ValidatingAdmissionPolicy.
default boolean
Default marks this SandboxConfig as the cluster-wide default for its SandboxClass. A WorkerPool with no explicit SandboxConfigName resolves to the default config for its SandboxClass. At most one default is expected per SandboxClass.
pauseImage string required
PauseImage is the container image used as the root sandbox container. It holds the sandbox's namespaces and runs no workload code, so it is an implementation detail of the sandbox rather than something actor authors choose. It is captured in the snapshot manifest alongside the sandbox binaries, so a restore always re-creates the sandbox from the same image the snapshot was taken with. Typically, set it to [1] for on-gcp, and [2] for off-gcp - [1] gcr.io/gke-release/pause@sha256:bcbd57ba5653580ec647b16d8163cdd1112df3609129b01f912a8032e48265da - [2] registry.k8s.io/pause:3.10.2@sha256:f548e0e8e3dc1896ca956272154dde3314e8cc4fde0a57577ee9fa1c63f5baf4
sandboxClass string required
SandboxClass is the sandbox runtime family this config applies to. A WorkerPool only uses SandboxConfigs whose SandboxClass matches its own.
enum: gvisor, microvm

No matches. Try .spec.assets for an exact path