Greenfield architecture spec set for the alknet-docker crate — a thin, single-host bollard wrapper exposing docker container/image operations as call-protocol ops on the shared alknet/call ALPN, plus a DockerTtyBackend (impl TtyBackend) behind a tty feature for interactive terminal sessions into containers over alknet/tty. Six ADRs: - 058: docker ops on alknet/call (no separate ALPN; raw-carriage handoff dissolved by alknet-tty extraction — interactive attach moved to alknet/tty via DockerTtyBackend, no carriage field on call.requested) - 059: bollard 0.21 (verified current on crates.io) + feature selection (http+pipe+time; no ssl/ssh/websocket/buildkit) - 060: container resource model (ADR-050 application) — alknet.managed/ alknet.owner labels, list owned_only flag, hosted-services operator role via static-resource fallback, handler-driven revoke with autonomous-death tolerance, resource-action vocabulary - 061: DockerTtyBackend in alknet-docker behind tty feature (attach vs exec mode; POC drive_attach_raw as reference) - 062: Docker client + OwnershipStore injection via closure capture (not Capabilities, not OperationContext — matches from_openapi pattern) - 063: exit code on terminal call.responded for non-interactive exec (call.completed stays empty, ADR-012 unchanged) Four spec docs (crates/docker/): README, overview, docker-operations, docker-tty-backend. Four deferred-scope OQs (048-051): network/volume ops, buildkit, system events subscription, create options surface. Updates the tty-backend.md Backend implementations table (DockerTtyBackend row now specced) and the architecture README (doc table, ADR table, current-state paragraph, OQ count). Grounded in the alknet-docker POC (docs/research/alknet-docker/poc-summary.md) which validated the hard parts; the remaining lifecycle ops are mechanical bollard wrapping. Reviewed by architecture-reviewer subagent; criticals (the docker_client injection model conflicting with the Capabilities contract) resolved via ADR-062/063 before commit.
1.5 KiB
1.5 KiB
OQ-49: Image Build (buildkit) Scope
- Origin:
crates/docker/docker-operations.md
§"Out of scope for v1"; ADR-059
§3 (no
buildkitfeature). - Status: deferred(scope)
- Door type: Two-way
- Priority: low
- Blocked on: a concrete use case for building images over the
call protocol. The two container use cases (disposable dev
containers, hosted services) pull pre-built images (
docker/image/pull) rather than building them. The reverse-proxy and other hosted services build viadocker compose build(operator-side), not via alknet. - Resolution: Not yet decidable. bollard's
build_image(image.rs:655) and thebuildkitfeature (which pulls tonic + bollard-buildkit-proto) are available but deferred. Build is a large feature (build context upload, layer caching, multi-stage, buildkit progress streaming) and is not needed for the current scope. When a use case forces it, the operation is aSubscription(progress events →call.responded, build complete →call.completed) and thebuildkitfeature is enabled inCargo.toml(two-way-door feature addition, per ADR-059). The v1 surface hasimage/pull+image/list+image/inspect;image/buildis added when needed. - Cross-references:
ADR-059
(feature set decision —
buildkitnot enabled), crates/docker/overview.md §"bollard version and features"