Container-wiring CLI verbs — prepare, run, cleanup.
Compose (or exec into) the podman flags that wire a user-owned
container into sandbox services. Mirrors terok-shield's prepare/run
shape and extends it with vault SSH signer, vault token broker, gate
token, and bridge-resource volume wiring. Container lifecycle stays
with the user; sandbox owns only the services and per-container
ancillary state.
Thin wrappers around terok_sandbox.launch,
which holds the actual composition logic.
LAUNCH_COMMANDS = (CommandDef(name='prepare', help='Print podman flags for sandboxing a user-owned container', handler=LazyHandler('terok_sandbox.commands.launch:_handle_prepare'), epilog=_BRIDGES_EPILOG, args=(*_WIRING_ARGS, ArgDef(name='--json', action='store_true', dest='output_json', help='Output JSON array instead of a shell-quoted string'))), CommandDef(name='run', help='Launch a sandboxed user-owned container (exec into podman run)', handler=LazyHandler('terok_sandbox.commands.launch:_handle_run'), epilog=_BRIDGES_EPILOG, args=_WIRING_ARGS), CommandDef(name='cleanup', help='Revoke tokens and drop shield rules for a sandboxed container', handler=LazyHandler('terok_sandbox.commands.launch:_handle_cleanup'), args=(ArgDef(name='container', help='Container name to clean up'),)))
module-attribute
PREPARE = LAUNCH_COMMANDS[0]
module-attribute
RUN = LAUNCH_COMMANDS[1]
module-attribute
CLEANUP = LAUNCH_COMMANDS[2]
module-attribute
__all__ = ['PREPARE', 'RUN', 'CLEANUP', 'LAUNCH_COMMANDS']
module-attribute