-
Notifications
You must be signed in to change notification settings - Fork 13
Expand file tree
/
Copy pathruntime.openapi.yaml
More file actions
402 lines (402 loc) · 11.3 KB
/
Copy pathruntime.openapi.yaml
File metadata and controls
402 lines (402 loc) · 11.3 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
basePath: /
definitions:
api.CoreAPIError:
properties:
code:
type: string
x-nullable: true
details:
description: |-
Details contains only documented, Core-owned facts: string, finite number,
boolean, null or string array values. Never include request echoes, secrets
or native/provider error text. Empty or invalid details are omitted.
type: object
message:
type: string
param:
type: string
x-nullable: true
type:
type: string
required:
- message
- type
type: object
api.CoreErrorResponse:
properties:
error:
$ref: '#/definitions/api.CoreAPIError'
required:
- error
type: object
api.NativeInstallationClaim:
properties:
executor_token:
type: string
type: object
deployment.Enrollment:
properties:
backend_fingerprint:
type: string
core_url:
description: The Core origin this node stores and connects to, such as https://core.example. It must equal the installation public URL; otherwise enrollment gets 409 sandbox_node_address_mismatch and the token stays unused.
type: string
credential:
type: string
deployment_generation:
type: integer
name:
type: string
node_id:
type: string
provider:
type: string
specification_digest:
type: string
type: object
deployment.NodeConfiguration:
properties:
core_url:
type: string
generation:
type: integer
installation_id:
type: string
max_active:
type: integer
max_retained:
type: integer
provider:
type: string
specification:
$ref: '#/definitions/sandbox.DeploymentSpec'
specification_digest:
type: string
type: object
deployment.NodeIdentity:
properties:
deployment_generation:
type: integer
installation_id:
type: string
max_active:
type: integer
max_retained:
type: integer
node_id:
type: string
provider:
type: string
specification_digest:
type: string
type: object
deployment.NodeStatus:
properties:
connected:
type: boolean
deployment_generation:
type: integer
installation_id:
type: string
max_active:
type: integer
max_retained:
type: integer
node_id:
type: string
provider:
type: string
provider_ready:
type: boolean
specification_digest:
type: string
type: object
sandbox.DeploymentSpec:
properties:
resources:
$ref: '#/definitions/sandbox.Resources'
runtime:
$ref: '#/definitions/sandbox.RuntimeRelease'
type: object
sandbox.Resources:
properties:
cpus:
type: integer
environment_disk_mib:
type: integer
memory_mib:
type: integer
root_disk_mib:
type: integer
type: object
sandbox.RuntimeRelease:
properties:
firmware_sha256:
type: string
image_id:
type: string
image_manifest_digest:
type: string
microsandbox_ref:
type: string
runtime_sha256:
type: string
source_commit:
type: string
type: object
v1.APIError:
properties:
code:
type: string
x-nullable: true
message:
type: string
param:
type: string
x-nullable: true
type:
type: string
required:
- message
- type
type: object
v1.ErrorResponse:
properties:
error:
$ref: '#/definitions/v1.APIError'
required:
- error
type: object
v1.NativeInstallationContext:
properties:
environment_id:
type: string
harness:
type: string
protocol_version:
type: string
remote_url:
type: string
version:
type: string
workspace_directory:
type: string
type: object
info:
contact: {}
description: Machine connection routes under /api/v1. Sandbox nodes authenticate with a one-use enrollment token or their node credential; Project API keys and the Core key are not accepted. See each operation's security requirements.
license:
name: Apache 2.0
url: https://www.apache.org/licenses/LICENSE-2.0.html
title: OpenAgentCore Machine Connections
version: "1"
paths:
/api/v1/agent-daemon/installation:
post:
description: Accepts a short-lived Environment installation Bearer authorization, not a Project or Core key. Returns frozen connection constraints; it does not claim or rotate credentials.
produces:
- application/json
responses:
"200":
description: OK
schema:
$ref: '#/definitions/v1.NativeInstallationContext'
"401":
description: Unauthorized
schema:
$ref: '#/definitions/api.CoreErrorResponse'
"404":
description: Not Found
schema:
$ref: '#/definitions/api.CoreErrorResponse'
"503":
description: Service Unavailable
schema:
$ref: '#/definitions/api.CoreErrorResponse'
summary: Resolve a native installation authorization
tags:
- Native Installation
/api/v1/agent-daemon/installation/claim:
post:
consumes:
- application/json
description: A valid installation Bearer authorization can claim one connect-only key. The client persists its generated secret before submitting it. Retries must present that same secret; a different, rotated or revoked credential is never replaced.
parameters:
- description: Locally persisted executor secret
in: body
name: body
required: true
schema:
$ref: '#/definitions/api.NativeInstallationClaim'
responses:
"204":
description: No Content
"400":
description: Bad Request
schema:
$ref: '#/definitions/api.CoreErrorResponse'
"401":
description: Unauthorized
schema:
$ref: '#/definitions/api.CoreErrorResponse'
"409":
description: Conflict
schema:
$ref: '#/definitions/api.CoreErrorResponse'
"503":
description: Service Unavailable
schema:
$ref: '#/definitions/api.CoreErrorResponse'
summary: Claim an Environment's installation credential
tags:
- Native Installation
/api/v1/sandbox-node/configuration:
get:
description: Authenticates with an unconsumed enrollment token, or a retained node credential with X-OAC-Node-ID. Does not consume the token or expose E2B credentials. Node files cannot override this specification.
parameters:
- description: Retained node UUID
in: header
name: X-OAC-Node-ID
type: string
- description: Exact kept generation (registered nodes only); omitted reads the current target
in: query
name: generation
type: integer
produces:
- application/json
responses:
"200":
description: OK
schema:
$ref: '#/definitions/deployment.NodeConfiguration'
"400":
description: Bad Request
schema:
$ref: '#/definitions/v1.ErrorResponse'
"401":
description: Unauthorized
schema:
$ref: '#/definitions/v1.ErrorResponse'
"409":
description: Conflict
schema:
$ref: '#/definitions/v1.ErrorResponse'
"500":
description: Internal Server Error
schema:
$ref: '#/definitions/v1.ErrorResponse'
"503":
description: Service Unavailable
schema:
$ref: '#/definitions/v1.ErrorResponse'
security:
- NodeEnrollmentAuth: []
summary: Read the active configuration for node installation
tags:
- Sandbox Node
/api/v1/sandbox-node/enroll:
post:
consumes:
- application/json
description: Node machine connection. Consumes a one-use enrollment token; grants no project or administrator access. Responses contain only explicit safe fields. core_url is required and must equal the installation public URL; a different address gets 409 sandbox_node_address_mismatch and leaves the token unused.
parameters:
- description: Request
in: body
name: body
required: true
schema:
$ref: '#/definitions/deployment.Enrollment'
produces:
- application/json
responses:
"201":
description: Created
schema:
$ref: '#/definitions/deployment.NodeIdentity'
"400":
description: Bad Request
schema:
$ref: '#/definitions/v1.ErrorResponse'
"401":
description: Unauthorized
schema:
$ref: '#/definitions/v1.ErrorResponse'
"404":
description: Not Found
schema:
$ref: '#/definitions/v1.ErrorResponse'
"409":
description: Conflict
schema:
$ref: '#/definitions/v1.ErrorResponse'
"500":
description: Internal Server Error
schema:
$ref: '#/definitions/v1.ErrorResponse'
"503":
description: Service Unavailable
schema:
$ref: '#/definitions/v1.ErrorResponse'
security:
- NodeEnrollmentAuth: []
summary: Enroll a sandbox node
tags:
- Sandbox Node
/api/v1/sandbox-node/identity:
get:
description: Node machine connection. Authenticates with the retained node credential; grants no project or administrator access. Responses contain only explicit safe fields.
parameters:
- description: Sandbox node UUID
in: query
name: node_id
required: true
type: string
produces:
- application/json
responses:
"200":
description: OK
schema:
$ref: '#/definitions/deployment.NodeStatus'
"400":
description: Bad Request
schema:
$ref: '#/definitions/v1.ErrorResponse'
"401":
description: Unauthorized
schema:
$ref: '#/definitions/v1.ErrorResponse'
"404":
description: Not Found
schema:
$ref: '#/definitions/v1.ErrorResponse'
"409":
description: Conflict
schema:
$ref: '#/definitions/v1.ErrorResponse'
"500":
description: Internal Server Error
schema:
$ref: '#/definitions/v1.ErrorResponse'
"503":
description: Service Unavailable
schema:
$ref: '#/definitions/v1.ErrorResponse'
security:
- NodeAuth: []
summary: Recover an enrolled sandbox node identity and observe its readiness
tags:
- Sandbox Node
schemes:
- http
- https
securityDefinitions:
NodeAuth:
in: header
name: Authorization
type: apiKey
NodeEnrollmentAuth:
in: header
name: Authorization
type: apiKey
swagger: "2.0"