Class NamespaceClient
- All Implemented Interfaces:
Closeable,AutoCloseable
ComputeService gRPC API.
One instance owns one ManagedChannel; callers must close()
it. The channel is cheap to keep open and expensive to rebuild, so the cloud
holds a long-lived client rather than creating one per provisioning request.
-
Nested Class Summary
Nested ClassesModifier and TypeClassDescriptionstatic final recordWhich of the actions the plugin needs this token actually carries.static enumOutcome of checking a configured workspace prefix against the registry. -
Field Summary
Fields -
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionvoidclose()static StringcomputeEndpointForRegion(String region) ComputeService is served per-region, not globally.Creates an instance.voiddestroyInstance(String instanceId, String reason) Destroys an instance.endpoint()listByLabel(String key, String value) Lists instances carrying the given label, used to reap instances whose Jenkins-side node disappeared (controller restart, crash, manual delete).listImageRefs(int maxRepositories) Lists the images available in the workspace's own registry, as fully qualified references ready to be used as an agent image.listImageRefs(int maxRepositories, String workspacePrefix) intRead-only probe used by the configuration page's "Test connection" button.Establishes which instance actions the token permits, without creating anything.Fetches the SSH endpoint for an instance; only used by the SSH launch strategy.static InstanttoInstant(com.google.protobuf.Timestamp ts) static com.google.protobuf.TimestamptoTimestamp(Instant when) Converts an absolute wall-clock deadline into the protobuf type the API expects.verifyWorkspacePrefix(Secret token, String prefix) Checks a workspace prefix by asking the registry for a repository that is known to exist.waitForRunning(String instanceId, Duration timeout) Blocks until the instance reaches RUNNING.
-
Field Details
-
DEFAULT_REGION
- See Also:
-
REGISTRY_ENDPOINT
ContainerRegistryService is global, not regional.- See Also:
-
REGISTRY_HOST
Host prefix for images in a workspace's own registry.- See Also:
-
-
Constructor Details
-
NamespaceClient
-
-
Method Details
-
computeEndpointForRegion
ComputeService is served per-region, not globally.global.namespaceapis.comreturns an nginx 404 for every compute route, so the region matters. -
endpoint
-
listInstanceCount
public int listInstanceCount()Read-only probe used by the configuration page's "Test connection" button. Requires onlyinstance:list, so it is safe to run from a least-privilege token and creates nothing.- Returns:
- the number of instances currently visible to the token.
-
createInstance
Creates an instance. Returns immediately; the instance is not yet RUNNING. -
waitForRunning
public Compute.InstanceMetadata waitForRunning(@NonNull String instanceId, @NonNull Duration timeout) Blocks until the instance reaches RUNNING.Uses the unary
WaitInstanceSyncrather than the streamingWaitInstance: the plugin has no use for intermediate state transitions, and a unary call carries a deadline cleanly. -
describe
-
destroyInstance
Destroys an instance. Treats "already gone" as success. -
listByLabel
Lists instances carrying the given label, used to reap instances whose Jenkins-side node disappeared (controller restart, crash, manual delete). -
sshConfig
Fetches the SSH endpoint for an instance; only used by the SSH launch strategy. -
probePermissions
Establishes which instance actions the token permits, without creating anything.Every check but
listruns against a non-existent instance id. Any status other than PERMISSION_DENIED means authorization passed, so NOT_FOUND (and even INVALID_ARGUMENT, if the id shape is rejected) both count as "granted".createcannot be probed this way and is the one action that only shows up at provisioning time. -
listImageRefs
Lists the images available in the workspace's own registry, as fully qualified references ready to be used as an agent image.Namespace reports a repository name; whether that already includes the workspace segment varies, so a name that already looks like a path is used as-is and a bare name is left bare. Either way the caller offers these as suggestions, not as the only permitted values.
-
listImageRefs
- Parameters:
workspacePrefix- the workspace segment of an nscr.io reference; the registry reports bare repository names, so without this the produced references are not pullable.
-
verifyWorkspacePrefix
public NamespaceClient.PrefixCheck verifyWorkspacePrefix(@NonNull Secret token, @NonNull String prefix) Checks a workspace prefix by asking the registry for a repository that is known to exist.The gRPC registry API cannot do this: it is tenant-scoped by the token and never reports the tenant id, so a wrong prefix is indistinguishable there. The Docker registry HTTP API can, because the prefix is part of the path:
nscr.io/<prefix>/<repo>.Deliberately returns
NamespaceClient.PrefixCheck.INCONCLUSIVErather than failing when anything is unexpected. A wrong answer here would block a correct configuration, which is worse than not checking at all. -
toTimestamp
Converts an absolute wall-clock deadline into the protobuf type the API expects. -
toInstant
-
close
public void close()- Specified by:
closein interfaceAutoCloseable- Specified by:
closein interfaceCloseable
-