Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
15 changes: 15 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -67,6 +67,21 @@ The handshake cookie checks identity; it does not authenticate or sandbox the ex

See the [Runtime Protocol reference](https://devsy.sh/docs/developing-providers/runtime-protocol) for the complete lifecycle, streaming, error, and compatibility contract.

### Workspace identity in API 1.1

`RunImageRequest.remote_user` carries the developer identity used for workspace
ownership. It is distinct from `user`, which selects the container process user.
When `remote_user` is empty, use `user` if set, otherwise `root`.
`dockerless` means the host will provision the developer environment after the
image starts; the final developer identity may not yet exist in that image.
Runtimes that resolve mount ownership from image contents must validate this
case before making changes to workspace resources.

Hosts must forward both values and runtimes must handle them before enabling
an implementation that depends on workspace ownership. These fields describe
provisioning intent; they do not authorize resource replacement. Duplicate
creation and explicit Delete remain separate operations.

## Development

```sh
Expand Down
7 changes: 7 additions & 0 deletions proto/devsy/runtime/v1/runtime.proto
Original file line number Diff line number Diff line change
Expand Up @@ -149,6 +149,13 @@ message RunImageRequest {
string platform = 18;

HostRequirements host_requirements = 19;

// Developer identity for workspace ownership, distinct from the container user.
// When empty, use user if set, otherwise root.
string remote_user = 20;
// The host will provision the developer environment after starting this image.
// Runtimes must not assume the final developer identity exists in the image.
bool dockerless = 21;
}

message Mount {
Expand Down
33 changes: 29 additions & 4 deletions runtimev1/runtime.pb.go

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion runtimev1/validate.go
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ const (
// APIMajor changes when the runtime wire contract breaks compatibility.
APIMajor uint32 = 1
// APIMinor tracks compatible additions within the current major generation.
APIMinor uint32 = 0
APIMinor uint32 = 1
// ChunkSize is the recommended maximum payload for each Exec data frame.
ChunkSize = 32 * 1024
)
Expand Down
Loading