Sandbox API - #3520
Sandbox API#3520
Conversation
ce10c95 to
5791c96
Compare
5791c96 to
31c37c5
Compare
d8dca07 to
d2911ee
Compare
7ef09e1 to
9be9ec9
Compare
Strix Security ReviewNo security issues found. Review summaryReviewed the Sandbox API end-to-end: the GraphQL surface and authorization wiring ( Authorization is enforced correctly. The CodeQL SSRF flags at Updated for Reviewed by Strix |
jshearer
left a comment
There was a problem hiding this comment.
We talked offline and you addressed the feedback I had. LGTM!
113a7d6 to
4e6e1f0
Compare
Adds GraphQL API for Linux sandboxes backed by Fly.io Sprites. Users (and their agents) can create a sandbox with
flowctlpreinstalled, run shell commands asynchronously, inspect output, restore the initial baseline, and delete the sandbox.max_run_after_disconnect=0on the exec call to Sprite API)The main implementation is split across three files:
graphql/sandboxes.rsdefines our sandboxes API and enforces authorizationsrc/sandboxes.rsimplements sandbox lifecycle and behavior, including our shell scripts and persisted stdout/stderrsrc/sprites.rswraps the native Sprites APIs and handles transport and response decoding.There are some scenarios where a sprite could get orphaned, for example if the delete call to the sprites API fails when the user is deleting a sandbox - the control plane record gets removed, but we don't retry the sprite API. A reaper could clean up orphans, but that's future work.
Tests are also coming later, trying to keep this light for now.