fabro/lib/apps/fabro-server/src/lib.rs
Bryan Helmkamp 0cc645b2d1
Reach run sandboxes from the server through the sandbox driver
`fabro-server/src/sandbox_access.rs` is the server's own path to a run's
sandbox: it connects the record's provider (the driver's Host, Docker and
Daytona providers in process, a plugin executable for any other kind),
keys ownership on the `petri.run` label Petri stamps on every sandbox it
creates, attaches by the recorded id, and for a host record designates
the recorded directory again when the id lives only in the worker's
registry. The Docker client resolves its endpoint from the same variables
Petri forwards to its plugin, so both meet on one daemon.

The doctor's Docker check and the Daytona credential probe move here with
`DaytonaCredentials`, and the `/sandboxes` inventory is rebuilt over the
driver's `list`, narrowed to sandboxes that carry Petri's run label.
Preflight asks the provider for its health instead of creating and
deleting a throwaway sandbox in Fabro's own shape, which no run uses; the
git retry policy behind the repository probe moves into run_manifest.

The callers still on fabro-sandbox's reconnect read their access through
a `legacy_provider_access` shim until they move.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-19 13:47:02 -04:00

65 lines
1.5 KiB
Rust

#![cfg_attr(
test,
allow(
clippy::absolute_paths,
clippy::await_holding_lock,
clippy::float_cmp,
reason = "Test-only server modules favor explicit assertions and fixture code."
)
)]
pub mod auth;
#[allow(
dead_code,
reason = "Automation materializer test hooks and helpers are only referenced by selected targets."
)]
mod automation_materializer;
mod canonical_host;
mod canonical_origin;
pub mod csp;
#[allow(
clippy::wildcard_imports,
clippy::absolute_paths,
reason = "The demo module is isolated fixture-style code."
)]
mod demo;
pub mod diagnostics;
pub mod error;
mod git_checkout;
pub mod github_webhooks;
pub mod install;
mod interp;
pub mod jwt_auth;
pub mod manifest_validation;
mod petri_check;
mod petri_runs;
mod principal_middleware;
mod request_id;
mod run_compiler;
mod run_files;
mod run_files_security;
mod run_intent;
mod run_manifest;
mod run_selector;
mod run_title_generation;
#[cfg(test)]
mod run_tool_create;
mod sandbox_access;
pub mod security_headers;
pub mod serve;
pub mod server;
mod server_secrets;
mod spawn_env;
mod startup;
pub mod static_files;
#[cfg(any(test, feature = "test-support"))]
pub mod test_support;
pub mod web_auth;
mod worker_control;
mod worker_runtime;
mod worker_token;
pub use error::{ApiError, Error, Result};
pub use run_manifest::workflow_bundle_from_manifest;
pub use server_secrets::process_env_snapshot;
pub use startup::{validate_startup, validate_startup_configuration};