clusterflux-public/docs/environments.md
2026-07-21 20:36:04 +02:00

1.1 KiB

Environments

Clusterflux disables network access while a task executes. Materializing an environment for the first time can still fetch declared inputs; subsequent task execution uses the materialized environment with networking disabled.

Declare environments in the bundle under:

envs/<name>/Containerfile
envs/<name>/Dockerfile

Reference one by logical name:

use clusterflux::env;

let linux = env!("linux");

Bundle inspection reports every discovered environment and its digest:

clusterflux bundle inspect --project .

The bundle definition is authoritative for every spawn. The coordinator passes the declared environment identity and digest in the TaskSpec, and the node resolves that exact definition. A same-named local recipe with different bytes is rejected rather than substituted.

On Linux, container-backed environments use rootless Podman. Clusterflux does not enable privileged containers by default.

A task may use a bind-mounted local checkout for speed. That source path is non-hermetic. Choose a source snapshot when you need a reproducible input identity independent of the current working tree.