Pods, images, and CID-backed mounts: a docker/podman-style control surface over the container sandbox, for *testing* container images without going through a build. CID in (rootfs + mounts), stdout/stderr + a diff CID out; no host paths.
Pods, images, and CID-backed mounts: a docker/podman-style control surface
over the container sandbox, for testing container images without going
through a build. CID in (rootfs + mounts), stdout/stderr + a diff CID out;
no host paths.
Allocate a pseudo-terminal so the process sees a tty (isatty → colored output). stdout+stderr merge into one stream.
internet_access
Give the pod internet egress via a userspace stack (pasta). When set — or when publish is non-empty — the pod runs in its own isolated network namespace (instead of sharing the host network). Default: host network.
publish
Host→pod port forwards (also isolates the pod + attaches pasta).
workdir
Working directory override; empty → the image's own WORKDIR (or the rootfs root for a raw rootfs CID).
Create + start + attach in one streamed call, with a build-style progress
tree (image fetch/cache → per-layer download → untar/merge), then a "run"
node with the container's logs, then exit.
Capture selected overlay diffs as FsNode CIDs. Defaults to the rootfs only;
mounts names specific mutable mounts to diff instead; all does rootfs +
every mutable mount.
A pod's resource history, then its live samples: the daemon records every
pod at 1 Hz for its whole life, so the stream first replays every recorded
sample (oldest first, each carrying the time it was taken) and then
continues with new ones. A client that connects half-way through a run
therefore still sees it from the beginning. Old samples may be thinned —
spacing is not uniform, so read each sample's timestamp, never its index.
The stream ends when the pod has exited and its history is drained, or when
the pod is removed.
How often the server checks for newly recorded samples to deliver; 0 → the 1000ms default. Recording is fixed at 1 Hz by the daemon's per-pod sampler, so values below 1000 are clamped up — they would only add empty polls.
A snapshot of one pod's resource use. CPU time, IO bytes and network bytes are
cumulative (monotonic — difference successive samples for a rate); memory
and pids are instantaneous. available is false when the pod has no per-pod
cgroup (cgroup v2 isn't delegated to the daemon), in which case the counters
are zero and no history is recorded.
The sources differ per field, and that is deliberate: CPU, memory and pids come
from the pod's cgroup, filesystem IO from its FUSE mounts and network bytes
from its network namespace. See the per-field notes below for why.
timestamp is when the sample was taken, which for a replayed sample is
not when it was sent — plot against it, and derive rates by dividing by the
difference between successive timestamps rather than assuming a fixed period.
Cumulative filesystem bytes the pod moved. NOT the cgroup's block-IO counters: a pod's whole filesystem is a FUSE overlay served by the daemon, so the block layer sees the daemon's reads and writes, not the pod's, and cgroup io.stat for a pod is legitimately ~0. These count the bytes crossing the pod's own FUSE mounts, which is what "how much IO did this build do?" actually means here.
io_wbytes
cumulative bytes written
pids_current
process/thread count
net_rx_bytes
Cumulative bytes on the interfaces of the pod's own network namespace, from the pod's point of view: rx is what it received, tx what it sent. Zero with net_available false when the pod shares the host's network namespace (the default for a build step) — the host's counters are not the pod's, so they are withheld rather than reported as if they were.
The log stream carrying this pod's stdout/stderr, published once the pod starts. Read live via the Logs service (StreamLog).
log_cid
The sealed log Blob CID, set once the pod has exited. Empty while running.
owner
The resource that created/owns this pod, if any (a run, a build, or a deployment). Extensible like BuildOwner. Absent for a standalone bldr pod.
workdir
Working directory the main process runs in (the image's WORKDIR or an override). Empty → the rootfs root.
runtime
The container runtime this pod runs on: runtime is the configured runtime id (e.g. "native", "vm"); runtime_kind is "native" | "cloud-hypervisor". Empty on older snapshots.
runtime_kind
profile_cid
CPU-profile Blob CID (collapsed stacks: proc;frame;frame <count>), set once the pod has exited if host-side profiling was on for it. Empty otherwise — which is the normal case, since profiling is opt-in.
Set when this mount is owned by a build (created from a BuildMountTarget). Empty for a user-created mount. A build-controlled mount is refreshed by its build on each successful run and removed when the build is removed; deleting it directly via DeleteMount is discouraged.
mutable
A mutable (writable overlay) mount whose content can be captured with CaptureMount; false for a read-only mount.