Documentation
¶
Overview ¶
Copyright 2023 Apoxy, Inc.
Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.
Directories
¶
| Path | Synopsis |
|---|---|
|
api
|
|
|
compute/v1alpha1
Package v1alpha1 contains the compute.apoxy.dev API group, a redesign of the extensions.apoxy.dev/v1alpha2 EdgeFunction around the workerd runtime and OCI bundles as the primary code-distribution mechanism.
|
Package v1alpha1 contains the compute.apoxy.dev API group, a redesign of the extensions.apoxy.dev/v1alpha2 EdgeFunction around the workerd runtime and OCI bundles as the primary code-distribution mechanism. |
|
config/v1alpha1
Package v1alpha1 contains API Schema definitions for the config v1alpha1 API group
|
Package v1alpha1 contains API Schema definitions for the config v1alpha1 API group |
|
controllers/v1alpha1
Package v1alpha1 contains API Schema definitions for the core v1alpha1 API group
|
Package v1alpha1 contains API Schema definitions for the core v1alpha1 API group |
|
coordination/v1
Package v1 contains the coordination.apoxy.dev/v1 Lease API type for the Apoxy apiserver.
|
Package v1 contains the coordination.apoxy.dev/v1 Lease API type for the Apoxy apiserver. |
|
core/v1alpha
Package v1alpha contains API Schema definitions for the core v1alpha API group
|
Package v1alpha contains API Schema definitions for the core v1alpha API group |
|
core/v1alpha2
Package v1alpha2 contains API Schema definitions for the core v1alpha2 API group
|
Package v1alpha2 contains API Schema definitions for the core v1alpha2 API group |
|
core/v1alpha3
Package v1alpha3 contains API Schema definitions for the core v1alpha3 API group
|
Package v1alpha3 contains API Schema definitions for the core v1alpha3 API group |
|
extensions/v1alpha1
Package v1alpha1 contains API Schema definitions for the exstensions v1alpha1 API group
|
Package v1alpha1 contains API Schema definitions for the exstensions v1alpha1 API group |
|
extensions/v1alpha2
Package v1alpha2 contains API Schema definitions for the exstensions v1alpha2 API group
|
Package v1alpha2 contains API Schema definitions for the exstensions v1alpha2 API group |
|
gateway/v1
Package v1 is the v1 version of the API.
|
Package v1 is the v1 version of the API. |
|
gateway/v1alpha2
Package v1alpha2 is the v1alpha2 version of the API.
|
Package v1alpha2 is the v1alpha2 version of the API. |
|
policy/v1alpha1
Package v1alpha1 contains API Schema definitions for the policy v1alpha1 API group.
|
Package v1alpha1 contains API Schema definitions for the policy v1alpha1 API group. |
|
vpc/v1alpha1
Package v1alpha1 contains the vpc.apoxy.dev API group: private connectivity domains (VPCNetwork), service-like addressing over tunnel connections (VPCService), relay instance tracking (Relay), and per-connection tracking (Tunnel).
|
Package v1alpha1 contains the vpc.apoxy.dev API group: private connectivity domains (VPCNetwork), service-like addressing over tunnel connections (VPCService), relay instance tracking (Relay), and per-connection tracking (Tunnel). |
|
workerd/v1
Package workerdv1 holds the workerd manager's control-plane protos: the EgressConfig service the backplane pushes compiled egress config through (APO-723/APO-726) and the DNSConfig service the manager's infra watch pushes the VPC name plane through.
|
Package workerdv1 holds the workerd manager's control-plane protos: the EgressConfig service the backplane pushes compiled egress config through (APO-723/APO-726) and the DNSConfig service the manager's infra watch pushes the VPC name plane through. |
|
client
|
|
|
versioned/fake
This package has the automatically generated fake clientset.
|
This package has the automatically generated fake clientset. |
|
versioned/scheme
This package contains the scheme of the automatically generated clientset.
|
This package contains the scheme of the automatically generated clientset. |
|
versioned/typed/compute/v1alpha1
This package has the automatically generated typed clients.
|
This package has the automatically generated typed clients. |
|
versioned/typed/compute/v1alpha1/fake
Package fake has the automatically generated clients.
|
Package fake has the automatically generated clients. |
|
versioned/typed/controllers/v1alpha1
This package has the automatically generated typed clients.
|
This package has the automatically generated typed clients. |
|
versioned/typed/controllers/v1alpha1/fake
Package fake has the automatically generated clients.
|
Package fake has the automatically generated clients. |
|
versioned/typed/coordination/v1
This package has the automatically generated typed clients.
|
This package has the automatically generated typed clients. |
|
versioned/typed/coordination/v1/fake
Package fake has the automatically generated clients.
|
Package fake has the automatically generated clients. |
|
versioned/typed/core/v1alpha
This package has the automatically generated typed clients.
|
This package has the automatically generated typed clients. |
|
versioned/typed/core/v1alpha/fake
Package fake has the automatically generated clients.
|
Package fake has the automatically generated clients. |
|
versioned/typed/core/v1alpha2
This package has the automatically generated typed clients.
|
This package has the automatically generated typed clients. |
|
versioned/typed/core/v1alpha2/fake
Package fake has the automatically generated clients.
|
Package fake has the automatically generated clients. |
|
versioned/typed/core/v1alpha3
This package has the automatically generated typed clients.
|
This package has the automatically generated typed clients. |
|
versioned/typed/core/v1alpha3/fake
Package fake has the automatically generated clients.
|
Package fake has the automatically generated clients. |
|
versioned/typed/extensions/v1alpha1
This package has the automatically generated typed clients.
|
This package has the automatically generated typed clients. |
|
versioned/typed/extensions/v1alpha1/fake
Package fake has the automatically generated clients.
|
Package fake has the automatically generated clients. |
|
versioned/typed/extensions/v1alpha2
This package has the automatically generated typed clients.
|
This package has the automatically generated typed clients. |
|
versioned/typed/extensions/v1alpha2/fake
Package fake has the automatically generated clients.
|
Package fake has the automatically generated clients. |
|
versioned/typed/gateway/v1
This package has the automatically generated typed clients.
|
This package has the automatically generated typed clients. |
|
versioned/typed/gateway/v1/fake
Package fake has the automatically generated clients.
|
Package fake has the automatically generated clients. |
|
versioned/typed/gateway/v1alpha2
This package has the automatically generated typed clients.
|
This package has the automatically generated typed clients. |
|
versioned/typed/gateway/v1alpha2/fake
Package fake has the automatically generated clients.
|
Package fake has the automatically generated clients. |
|
versioned/typed/policy/v1alpha1
This package has the automatically generated typed clients.
|
This package has the automatically generated typed clients. |
|
versioned/typed/policy/v1alpha1/fake
Package fake has the automatically generated clients.
|
Package fake has the automatically generated clients. |
|
versioned/typed/vpc/v1alpha1
This package has the automatically generated typed clients.
|
This package has the automatically generated typed clients. |
|
versioned/typed/vpc/v1alpha1/fake
Package fake has the automatically generated clients.
|
Package fake has the automatically generated clients. |
|
cmd
|
|
|
apiserver
command
|
|
|
backplane
command
|
|
|
dial-stdio
command
dial-stdio provides a dialer that connects to the standard I/O streams.
|
dial-stdio provides a dialer that connects to the standard I/O streams. |
|
openapi-dump
command
Command openapi-dump renders the apiserver's generated OpenAPI definitions to a static OpenAPI v3 JSON document offline — no running apiserver required.
|
Command openapi-dump renders the apiserver's generated OpenAPI definitions to a static OpenAPI v3 JSON document offline — no running apiserver required. |
|
tunnelproxy
command
|
|
|
workerd-host
command
Command workerd-host runs stock workerd inside a gVisor/runsc sandbox via clrk's extracted pkg/sandbox runtime.
|
Command workerd-host runs stock workerd inside a gVisor/runsc sandbox via clrk's extracted pkg/sandbox runtime. |
|
workerd-manager
command
Command workerd-manager is the data-plane half of the APO-796 ServiceManager.
|
Command workerd-manager is the data-plane half of the APO-796 ServiceManager. |
|
pkg
|
|
|
apiserver/auth
Package auth contains APIServer authentication helpers.
|
Package auth contains APIServer authentication helpers. |
|
apiserver/controllers
Package controllers implements Apoxy Control Plane-side controllers.
|
Package controllers implements Apoxy Control Plane-side controllers. |
|
apiserver/extensions
Package extensions implements extensions controllers.
|
Package extensions implements extensions controllers. |
|
apiserver/gateway
Package gateway implements Gateway API controllers.
|
Package gateway implements Gateway API controllers. |
|
apiserver/migration
Package migration holds one-shot storage migrations run at apiserver startup.
|
Package migration holds one-shot storage migrations run at apiserver startup. |
|
apiserver/policy
Package policy implements API Server policy controllers.
|
Package policy implements API Server policy controllers. |
|
apiserver/secretstore
Package secretstore implements the REST plumbing that makes SecretStore values write-only: a redacting wrapper that strips stored values from every main-resource response, a "values" subresource that is the single path through which values are written and (by internal identities only) read, and the authorizer gate that enforces the read restriction.
|
Package secretstore implements the REST plumbing that makes SecretStore values write-only: a redacting wrapper that strips stored values from every main-resource response, a "values" subresource that is the single path through which values are written and (by internal identities only) read, and the authorizer gate that enforces the read restriction. |
|
backplane/logs
Package logs provides logging facilities for Envoy.
|
Package logs provides logging facilities for Envoy. |
|
backplane/logs/logtail
Package logtail consumes log files and manages compaction using fallocate.
|
Package logtail consumes log files and manages compaction using fallocate. |
|
backplane/metrics
Package metrics provides an HTTP handler for proxying metrics requests to specific upstream endpoints using net/http/httputil.ReverseProxy.
|
Package metrics provides an HTTP handler for proxying metrics requests to specific upstream endpoints using net/http/httputil.ReverseProxy. |
|
backplane/otel
Package otel provides functionality for managing OpenTelemetry collector processes.
|
Package otel provides functionality for managing OpenTelemetry collector processes. |
|
backplane/portforward
Package portforward watches a port on a ProxyReplica and forwards from a local port to the remote port on the ProxyReplica.
|
Package portforward watches a port on a ProxyReplica and forwards from a local port to the remote port on the ProxyReplica. |
|
backplane/wasm/manifest
Package manifest implements Edge Function Manifest utilities.
|
Package manifest implements Edge Function Manifest utilities. |
|
cert
Package cert provides X.509 fingerprint helpers used by the CLI's cert subcommands.
|
Package cert provides X.509 fingerprint helpers used by the CLI's cert subcommands. |
|
cert/reload
Package reload provides hot-reloading of TLS keypairs that are rotated in place on disk (e.g.
|
Package reload provides hot-reloading of TLS keypairs that are rotated in place on disk (e.g. |
|
clickhouse/migrations
Package migrations provides database migrations for ClickHouse.
|
Package migrations provides database migrations for ClickHouse. |
|
cmd/vpc
Package vpc provides the `apoxy vpc` command tree for managing vpc.apoxy.dev objects: networks, services, relays, and tunnels.
|
Package vpc provides the `apoxy vpc` command tree for managing vpc.apoxy.dev objects: networks, services, relays, and tunnels. |
|
diag
Package diag implements the agent-side debug surface that runs over the existing QUIC control channel to tunnelproxy.
|
Package diag implements the agent-side debug surface that runs over the existing QUIC control channel to tunnelproxy. |
|
diag/commands
Package commands holds the built-in diag commands.
|
Package commands holds the built-in diag commands. |
|
diag/protocol
Package protocol defines the wire format for the agent diag channel: nd-json frames over one long-lived HTTP/3 stream, demuxed by Id so multiple commands can interleave.
|
Package protocol defines the wire format for the agent diag channel: nd-json frames over one long-lived HTTP/3 stream, demuxed by Id so multiple commands can interleave. |
|
drivers
Package drivers implements common interfaces and utilities for Apoxy service drivers
|
Package drivers implements common interfaces and utilities for Apoxy service drivers |
|
edgefunc/controller
Package controller implements the edge function controller that manages per-namespace edge runtimes with multiple dynamically-loaded functions.
|
Package controller implements the edge function controller that manages per-namespace edge runtimes with multiple dynamically-loaded functions. |
|
edgefunc/runc
Package runc implements container runtime based on OpenContainers libcontainer package.
|
Package runc implements container runtime based on OpenContainers libcontainer package. |
|
edgefunc/runc/network/iptables
Package iptables container useful routines for manipulating iptables rules.
|
Package iptables container useful routines for manipulating iptables rules. |
|
gateway/xds/cache
This file contains code derived from Contour, https://github.com/projectcontour/contour from the source file https://github.com/projectcontour/contour/blob/main/internal/xds/v3/snapshotter.go and is provided here subject to the following: Copyright Project Contour Authors SPDX-License-Identifier: Apache-2.0
|
This file contains code derived from Contour, https://github.com/projectcontour/contour from the source file https://github.com/projectcontour/contour/blob/main/internal/xds/v3/snapshotter.go and is provided here subject to the following: Copyright Project Contour Authors SPDX-License-Identifier: Apache-2.0 |
|
gateway/xds/extensions
Import all Envoy filter types so they are registered and deserialization does not fail when using them in the "typed_config" attributes.
|
Import all Envoy filter types so they are registered and deserialization does not fail when using them in the "typed_config" attributes. |
|
kube-controller/apiregistration
Package apiregistration handles Apoxy API service registration with Kubernetes API Aggregation
|
Package apiregistration handles Apoxy API service registration with Kubernetes API Aggregation |
|
log
Package log provides logging routines based on slog package.
|
Package log provides logging routines based on slog package. |
|
net/dns/vpcdns
Package vpcdns is the serving core of the Apoxy VPC name plane: a CoreDNS plugin that answers, authoritatively, for names bound into a project's VPC (tunnel endpoints today, VPC-bound Services later) and passes everything else to the next plugin in the chain (typically cache -> upstream).
|
Package vpcdns is the serving core of the Apoxy VPC name plane: a CoreDNS plugin that answers, authoritatively, for names bound into a project's VPC (tunnel endpoints today, VPC-bound Services later) and passes everything else to the next plugin in the chain (typically cache -> upstream). |
|
netns
Package netns wraps the LockOSThread + setns + restore dance for running code — most notably dials — inside a named network namespace.
|
Package netns wraps the LockOSThread + setns + restore dance for running code — most notably dials — inside a named network namespace. |
|
netstack
icx_network.go
|
icx_network.go |
|
sandbox
Package sandbox is the tenant-neutral gVisor/runsc sandbox runtime spine shared by apoxy's workerd host and the clrk agent worker.
|
Package sandbox is the tenant-neutral gVisor/runsc sandbox runtime spine shared by apoxy's workerd host and the clrk agent worker. |
|
sandbox/sentrystack
The InitStr envelope is pure JSON with no gvisor dependencies — leave it without a //go:build constraint so cross-platform unit tests can exercise Encode/Decode without pulling in linux-only gvisor packages.
|
The InitStr envelope is pure JSON with no gvisor dependencies — leave it without a //go:build constraint so cross-platform unit tests can exercise Encode/Decode without pulling in linux-only gvisor packages. |
|
sandbox/sentrystack/egressfwd
Package egressfwd installs the in-Sentry egress forwarders for compute-worker sandboxes — the APO-713 data path that makes a worker fetch() actually leave the box.
|
Package egressfwd installs the in-Sentry egress forwarders for compute-worker sandboxes — the APO-713 data path that makes a worker fetch() actually leave the box. |
|
sandbox/sentrystack/egresswire
Package egresswire is the pure wire framing shared by the two ends of the compute egress data path: the in-Sentry forwarder (pkg/sandbox/sentrystack/ egressfwd) writes the preamble, and the host egress bridge (pkg/workerd/host) reads it.
|
Package egresswire is the pure wire framing shared by the two ends of the compute egress data path: the in-Sentry forwarder (pkg/sandbox/sentrystack/ egressfwd) writes the preamble, and the host egress bridge (pkg/workerd/host) reads it. |
|
tunnel/agent
Package agent implements the tunnel agent: the client side of the vpc.apoxy.dev relay stack.
|
Package agent implements the tunnel agent: the client side of the vpc.apoxy.dev relay stack. |
|
tunnel/bfdl
Package bfdl implements a BFD-lite (RFC 5880 subset) protocol for application-level liveness detection between tunnel agents and the tunnelproxy server.
|
Package bfdl implements a BFD-lite (RFC 5880 subset) protocol for application-level liveness detection between tunnel agents and the tunnelproxy server. |
|
tunnel/conntrack
Package conntrack provides a lightweight TCP connection tracker that implements connection.PacketObserver.
|
Package conntrack provides a lightweight TCP connection tracker that implements connection.PacketObserver. |
|
tunnel/conntrackpc
Package conntrackpc provides a conntrack-style multiplexer for net.PacketConn, suitable for QUIC clients that want multiple "virtual" PacketConns over one UDP socket.
|
Package conntrackpc provides a conntrack-style multiplexer for net.PacketConn, suitable for QUIC clients that want multiple "virtual" PacketConns over one UDP socket. |
|
tunnel/endpointselect
Package endpointselect provides endpoint selection strategies for tunnel connections.
|
Package endpointselect provides endpoint selection strategies for tunnel connections. |
|
tunnel/fasttun
Package fasttun implements a high-performance interface to Linux TUN devices with support for multi-queue and batched packet I/O.
|
Package fasttun implements a high-performance interface to Linux TUN devices with support for multi-queue and batched packet I/O. |
|
tunnel/ipalloc
Package ipalloc holds the relay-side, in-process connection address allocators for the vpc.apoxy.dev relay (APO-825 §2.8).
|
Package ipalloc holds the relay-side, in-process connection address allocators for the vpc.apoxy.dev relay (APO-825 §2.8). |
|
utils/docker
Package docker implements Docker utils.
|
Package docker implements Docker utils. |
|
workerd/build
Package build turns a JS/TS project into a staged compute service bundle: esbuild runs in-process (wrangler-style: ESM output, workerd conditions) with a module-collector plugin that turns wasm/text/data imports into separate bundle modules instead of inlining them.
|
Package build turns a JS/TS project into a staged compute service bundle: esbuild runs in-process (wrangler-style: ESM output, workerd conditions) with a module-collector plugin that turns wasm/text/data imports into separate bundle modules instead of inlining them. |
|
workerd/bundle
Package bundle packs, pushes, and stages compute service bundles: the OCI artifact shape the workerd data plane pulls (pkg/workerd/host).
|
Package bundle packs, pushes, and stages compute service bundles: the OCI artifact shape the workerd data plane pulls (pkg/workerd/host). |
|
workerd/host
Package host drives stock workerd inside a gVisor/runsc sandbox via clrk's extracted pkg/sandbox.Runtime.
|
Package host drives stock workerd inside a gVisor/runsc sandbox via clrk's extracted pkg/sandbox.Runtime. |
|
workerd/manager
Package manager implements the APO-796 ServiceManager: the control-plane Service->ServiceRevision minting reconciler (platform-neutral, this file) and the data-plane resident reconciler (resident_reconciler.go) that drives the workerd resident and publishes this node's serveable routing.
|
Package manager implements the APO-796 ServiceManager: the control-plane Service->ServiceRevision minting reconciler (platform-neutral, this file) and the data-plane resident reconciler (resident_reconciler.go) that drives the workerd resident and publishes this node's serveable routing. |
|
workerd/names
Package names is the single owner of the workerd resident naming scheme.
|
Package names is the single owner of the workerd resident naming scheme. |
Click to show internal directories.
Click to hide internal directories.