Sign inSign up

michaelirwin244/temp-pre-load-images-kit:latest

Multi-platform
Manifest digest

sha256:ceaffbc5a76634d47655b53b210fe52edcc82f0549ac0c2a2a21fe694370bc95

Last pushed

3 days by michaelirwin244

Type

Sandbox Kit

Manifest digest

sha256:ceaffbc5a76634d47655b53b210fe52edcc82f0549ac0c2a2a21fe694370bc95

yaml
schemaVersion: "3"
displayName: Image Cache
description: Preloads container images into the sandbox's Docker engine from the host-side kit registry, so `docker run postgres:16` starts without a Docker Hub round trip. Proof of concept — see README.md for the threat model.
sourceUrl: https://github.com/docker/sandbox-kit-spec
version: 0.1.0
kind: mixin
provides:
    - [email protected]
capabilities:
    - type: com.docker.sandbox/kit-registry@1
      description: Pull preloaded images from (and optionally push them to) the host's image cache
    - type: com.docker.sandbox/network-policy@1
      optional: true
      config:
        runtime:
            allow:
                - registry-1.docker.io
                - auth.docker.io
                - production.cloudflare.docker.com
    - type: com.docker.sandbox/lifecycle@1
      config:
        startup:
            - background: false
              command:
                - /usr/local/bin/sbx-image-cache
              description: Preload images from the host kit registry into the sandbox engine
              env:
                - SBX_KIT_REGISTRY_URL
                - SBX_IMAGE_CACHE_IMAGES
                - SBX_IMAGE_CACHE_WRITE_BACK
                - SBX_IMAGE_CACHE_WAIT
                - DOCKER_HOST
              user: "0"
    - type: com.docker.sandbox/agent-context@1
      config:
        content: |
            ## Preloaded container images

            These images were preloaded into this sandbox's Docker engine at boot
            and can be used without pulling: `${{ kit.args.images }}`.
            Prefer them as-is (don't add `--pull always`). The preload log is
            /var/log/sbx-image-cache.log.
args:
    images:
        default: ""
        description: Comma- or space-separated image references to preload (e.g. postgres:16,redis:7)
        pattern: ^[A-Za-z0-9._/:@+, -]*$
        env: SBX_IMAGE_CACHE_IMAGES
    wait:
        default: "true"
        description: Block boot until preloading finishes
        enum:
            - "false"
            - "true"
        env: SBX_IMAGE_CACHE_WAIT
    writeBack:
        default: "false"
        description: On a cache miss, push the upstream pull back into the host cache (shared with other sandboxes)
        enum:
            - "false"
            - "true"
        env: SBX_IMAGE_CACHE_WRITE_BACK