159 lines
4.2 KiB
Markdown
159 lines
4.2 KiB
Markdown
|
|
---
|
|||
|
|
id: SAND-WP-0009
|
|||
|
|
type: workplan
|
|||
|
|
title: "TTL enforcement and operational hardening"
|
|||
|
|
domain: infotech
|
|||
|
|
repo: sand-boxer
|
|||
|
|
status: ready
|
|||
|
|
owner: codex
|
|||
|
|
topic_slug: custodian
|
|||
|
|
created: "2026-06-24"
|
|||
|
|
updated: "2026-06-24"
|
|||
|
|
---
|
|||
|
|
|
|||
|
|
# TTL enforcement and operational hardening
|
|||
|
|
|
|||
|
|
Close the largest post-v0 functional gap: **disposable-by-default TTL** with
|
|||
|
|
`extend_ttl`, automated expire/reap, and platform hygiene (classification,
|
|||
|
|
registry, HTTP parity).
|
|||
|
|
|
|||
|
|
Gap analysis: `history/2026-06-24-post-wp0007-intent-scope-gap-analysis.md`
|
|||
|
|
|
|||
|
|
**Predecessor:** SAND-WP-0007 (snapshots — finished)
|
|||
|
|
**Follow-on:** SAND-WP-0010 (real cloud adapters), SAND-WP-0011 (reachability +
|
|||
|
|
consumer profiles), SAND-WP-0012 (Packer orchestration)
|
|||
|
|
|
|||
|
|
---
|
|||
|
|
|
|||
|
|
## TTL duration parser
|
|||
|
|
|
|||
|
|
```task
|
|||
|
|
id: SAND-WP-0009-T01
|
|||
|
|
status: todo
|
|||
|
|
priority: high
|
|||
|
|
```
|
|||
|
|
|
|||
|
|
Module `src/sandboxer/lifecycle/ttl.py`: parse profile `ttl.default` / `ttl.max`
|
|||
|
|
and request override strings (`4h`, `30m`, `1d`). Unit tests for edge cases and
|
|||
|
|
max-cap enforcement.
|
|||
|
|
|
|||
|
|
## expires_at on create
|
|||
|
|
|
|||
|
|
```task
|
|||
|
|
id: SAND-WP-0009-T02
|
|||
|
|
status: todo
|
|||
|
|
priority: high
|
|||
|
|
```
|
|||
|
|
|
|||
|
|
Add `expires_at: datetime | None` and optional `ttl: str` on `SandboxStatus`.
|
|||
|
|
`SandboxManager.create` sets expiry from profile default or `SandboxCreateRequest.ttl`.
|
|||
|
|
Persist in `SandboxStore`. Emit expiry in State Hub `detail`.
|
|||
|
|
|
|||
|
|
## extend_ttl API
|
|||
|
|
|
|||
|
|
```task
|
|||
|
|
id: SAND-WP-0009-T03
|
|||
|
|
status: todo
|
|||
|
|
priority: high
|
|||
|
|
```
|
|||
|
|
|
|||
|
|
`SandboxManager.extend_ttl(sandbox_id, duration)` — cap at profile `ttl.max`,
|
|||
|
|
reject destroyed/expired sandboxes. CLI: `sandboxer extend-ttl <id> --duration 2h`.
|
|||
|
|
HTTP: `PATCH /v1/sandboxes/{id}/ttl` with body `{"duration": "2h"}`.
|
|||
|
|
|
|||
|
|
## Expire and TTL reap
|
|||
|
|
|
|||
|
|
```task
|
|||
|
|
id: SAND-WP-0009-T04
|
|||
|
|
status: todo
|
|||
|
|
priority: high
|
|||
|
|
```
|
|||
|
|
|
|||
|
|
CLI `sandboxer expire` — list sandboxes past `expires_at`; dry-run default;
|
|||
|
|
`--apply` transitions to `expired` then `destroy` (reuse destroy path). Optional
|
|||
|
|
`idle_reap` hook using `updated_at` when profile sets `ttl.idle_reap`. Integrate
|
|||
|
|
with existing `reap-stale` docs (host inventory vs TTL are distinct concerns).
|
|||
|
|
|
|||
|
|
## activity-core integration contract
|
|||
|
|
|
|||
|
|
```task
|
|||
|
|
id: SAND-WP-0009-T05
|
|||
|
|
status: todo
|
|||
|
|
priority: medium
|
|||
|
|
```
|
|||
|
|
|
|||
|
|
`docs/integrations/activity-core.md`: how a scheduled job invokes
|
|||
|
|
`sandboxer expire --apply` (or HTTP equivalent); lifecycle events for `expired`
|
|||
|
|
state; no Temporal code in this repo.
|
|||
|
|
|
|||
|
|
## Repo classification and registry refresh
|
|||
|
|
|
|||
|
|
```task
|
|||
|
|
id: SAND-WP-0009-T06
|
|||
|
|
status: todo
|
|||
|
|
priority: medium
|
|||
|
|
```
|
|||
|
|
|
|||
|
|
Add `.repo-classification.yaml` (clears State Hub C-24). Update
|
|||
|
|
`registry/capabilities/execution.sandbox-provision.md` maturity to reflect v0
|
|||
|
|
(A4/C4). Document `reuse-surface validate` operator steps in `registry/README.md`;
|
|||
|
|
run validate if reuse-surface CLI available in environment.
|
|||
|
|
|
|||
|
|
## HTTP API parity
|
|||
|
|
|
|||
|
|
```task
|
|||
|
|
id: SAND-WP-0009-T07
|
|||
|
|
status: todo
|
|||
|
|
priority: medium
|
|||
|
|
```
|
|||
|
|
|
|||
|
|
Add `POST /v1/sandboxes/{id}/recreate` and TTL endpoints to `api/app.py`.
|
|||
|
|
Align OpenAPI with CLI surface from SAND-WP-0007.
|
|||
|
|
|
|||
|
|
## Documentation
|
|||
|
|
|
|||
|
|
```task
|
|||
|
|
id: SAND-WP-0009-T08
|
|||
|
|
status: todo
|
|||
|
|
priority: medium
|
|||
|
|
```
|
|||
|
|
|
|||
|
|
`docs/ttl.md` — semantics, extend, expire, profile fields. Update
|
|||
|
|
`docs/meta-framework.md`, `SCOPE.md`, `docs/migration-gaps.md`. Brief security
|
|||
|
|
note in `docs/runbooks/` or `docs/security.md`: sandbox limits blast radius, not
|
|||
|
|
intent enforcement (INTENT design principle).
|
|||
|
|
|
|||
|
|
## Tests
|
|||
|
|
|
|||
|
|
```task
|
|||
|
|
id: SAND-WP-0009-T09
|
|||
|
|
status: todo
|
|||
|
|
priority: high
|
|||
|
|
```
|
|||
|
|
|
|||
|
|
`tests/test_ttl.py` (parser, extend cap), manager expire flow with mocked
|
|||
|
|
backend, API tests for extend/recreate. `make check` green.
|
|||
|
|
|
|||
|
|
---
|
|||
|
|
|
|||
|
|
## Out of scope (deferred)
|
|||
|
|
|
|||
|
|
| Item | Track |
|
|||
|
|
|------|-------|
|
|||
|
|
| Real E2B / Modal / BYOK / fin-hub | SAND-WP-0010 (WP-0006-T06) |
|
|||
|
|
| ops-bridge tunnel descriptor | SAND-WP-0011 |
|
|||
|
|
| glas-harness / snuggle consumer profiles | SAND-WP-0011 |
|
|||
|
|
| Packer build from `create` | SAND-WP-0012 (WP-0005-T06) |
|
|||
|
|
| Cross-host snapshot transfer | Future |
|
|||
|
|
| sandboxer01 host provisioning | Operator / infra |
|
|||
|
|
| wise-validator T09 remote smoke | wise-validator repo |
|
|||
|
|
|
|||
|
|
---
|
|||
|
|
|
|||
|
|
## Acceptance criteria
|
|||
|
|
|
|||
|
|
- Ready sandbox has `expires_at`; `extend_ttl` respects `ttl.max`
|
|||
|
|
- `sandboxer expire --apply` destroys expired sandboxes idempotently
|
|||
|
|
- `.repo-classification.yaml` present; C-24 warn cleared on fix-consistency
|
|||
|
|
- HTTP exposes recreate + extend_ttl
|
|||
|
|
- `docs/ttl.md` published; gap analysis P1–P4 addressed
|