fabro/lib/apps/fabro-server/src
Bryan Helmkamp 28d4242df0
Route Daytona sandboxes through the sandbox driver
The `daytona` provider kind now maps onto the sandbox-driver Daytona
provider instead of fabro's own SDK client. Fabro keeps what is its own:
the HMAC-named snapshot built from the environment's image or Dockerfile,
the explicit 120 minute auto-stop default, the managed labels that gate
destructive operations, the clone decision and layout, and push
credentials. The driver creates the sandbox, clones natively, and serves
exec, files, search, terminal, SSH, preview, and VNC through its facets.

- `daytona.rs` builds the driver `SandboxSpec` (snapshot source,
  `/home/daytona/workspace`, labels, timers, network policy, run name),
  ensures the snapshot through the driver `SnapshotProvider`, attaches by
  persisted id with fabro's label guard, and probes credentials through
  the provider health check under fabro's 20 second budget.
- `DriverSandbox` gains a create plan that settles the spec right before
  the provider call, records the snapshot a sandbox came from, and
  reports the provider console URL on `Ready`.
- Terminals use the driver `Pty` facet; the server's SSH, preview, and
  VNC endpoints use the `SshAccess`, `PreviewUrls`, and `Vnc` facets
  through the driver-typed reconnect. The preview endpoint now answers
  for every provider with a preview facet, so the local sandbox returns
  its loopback URL.
- Daytona credentials travel as `DaytonaCredentials` built from the
  vault key plus configured URL and organization; nothing reads the
  process environment implicitly. The inventory registry uses the shared
  `DriverInventoryProvider`.
- The SDK-based `daytona/mod.rs`, `provider/daytona.rs`, the Daytona
  terminal, the `daytona` cargo feature, and the direct daytona-sdk,
  git2 (in fabro-sandbox), tungstenite, and rustls dependencies are
  gone. The live Daytona tests run against the driver-backed sandbox.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-09 19:14:13 -06:00
..
auth Keep auth code store naming consistent 2026-08-24 17:26:17 -04:00
demo Open sandbox provider identity to plugin kinds 2026-09-09 15:17:32 -06:00
prompts Render the run title prompt with Jinja instead of string replacement 2026-07-27 17:23:16 -04:00
server Route Daytona sandboxes through the sandbox driver 2026-09-09 19:14:13 -06:00
worker_control refactor: organize crates into three layers 2026-07-23 17:59:34 -04:00
automation_materializer.rs Tighten automation Git validation types 2026-08-31 18:02:08 -04:00
canonical_host.rs refactor: organize crates into three layers 2026-07-23 17:59:34 -04:00
canonical_origin.rs refactor: organize crates into three layers 2026-07-23 17:59:34 -04:00
csp.rs refactor: organize crates into three layers 2026-07-23 17:59:34 -04:00
diagnostics.rs Route Daytona sandboxes through the sandbox driver 2026-09-09 19:14:13 -06:00
error.rs Make pull request creation durable and asynchronous 2026-08-01 19:28:52 -04:00
git_checkout.rs Tighten automation Git validation types 2026-08-31 18:02:08 -04:00
github_webhooks.rs refactor: organize crates into three layers 2026-07-23 17:59:34 -04:00
install.rs Route Daytona sandboxes through the sandbox driver 2026-09-09 19:14:13 -06:00
interp.rs refactor: organize crates into three layers 2026-07-23 17:59:34 -04:00
jwt_auth.rs refactor: organize crates into three layers 2026-07-23 17:59:34 -04:00
lib.rs Remove expired startup secret migrations 2026-09-05 14:05:48 -04:00
manifest_validation.rs Simplify local RunIntent producer support 2026-08-31 14:08:35 -04:00
migrations.rs Remove expired startup secret migrations 2026-09-05 14:05:48 -04:00
principal_middleware.rs Unify blob hash vocabulary 2026-08-17 13:56:19 -04:00
request_id.rs refactor: organize crates into three layers 2026-07-23 17:59:34 -04:00
run_compiler.rs Harden automation workflow source handling 2026-08-31 13:45:08 -04:00
run_files.rs Route Daytona sandboxes through the sandbox driver 2026-09-09 19:14:13 -06:00
run_files_security.rs refactor: organize crates into three layers 2026-07-23 17:59:34 -04:00
run_intent.rs Reject automatic pull requests for Local runs 2026-09-02 17:15:52 -04:00
run_manifest.rs Route Daytona sandboxes through the sandbox driver 2026-09-09 19:14:13 -06:00
run_selector.rs refactor: organize crates into three layers 2026-07-23 17:59:34 -04:00
run_title_generation.rs Warn when run title generation fails 2026-08-26 13:18:39 -04:00
run_tool_manifest.rs Remove run IDs from create manifest producers 2026-08-01 11:47:11 -04:00
security_headers.rs refactor: organize crates into three layers 2026-07-23 17:59:34 -04:00
serve.rs Remove expired startup secret migrations 2026-09-05 14:05:48 -04:00
server.rs Route Daytona sandboxes through the sandbox driver 2026-09-09 19:14:13 -06:00
server_secrets.rs refactor: organize crates into three layers 2026-07-23 17:59:34 -04:00
spawn_env.rs refactor: organize crates into three layers 2026-07-23 17:59:34 -04:00
startup.rs Remove expired startup secret migrations 2026-09-05 14:05:48 -04:00
static_files.rs feat(web): tell open tabs when a new build ships 2026-07-25 14:45:26 -04:00
test_support.rs Open sandbox provider identity to plugin kinds 2026-09-09 15:17:32 -06:00
web_auth.rs Serve CLI auth sessions from SQLite 2026-07-26 00:00:15 -04:00
worker_runtime.rs refactor: simplify cancellation lifecycle code from review 2026-07-23 21:15:35 -04:00
worker_token.rs refactor: organize crates into three layers 2026-07-23 17:59:34 -04:00