Client API
Run the gateway
Start cellar-gateway and use the HTTP JSON API
On each node that should serve HTTP (typically every manager, optionally workers):
sudo systemctl enable --now cellar-gateway
# or manually:
cellar-gateway --listen :8080 --data-dir /var/lib/cellar
# optional: --upstreams 192.0.2.10:17946,192.0.2.11:17946The gateway loads the cluster CA from --data-dir. Managers dial their advertise address; workers dial their stored manager_addr plus any rediscovered manager_addrs from heartbeats/join. Override with --upstreams for an explicit multi-manager list.
Health endpoints
No auth:
| Path | Meaning |
|---|---|
/healthz | Process is up |
/readyz | Can reach a manager SandboxAPI |
HTTP API
Routes follow the microsandbox cloud shape. All require Authorization: Bearer cellar_… or X-Api-Key:
| Method | Path | Notes |
|---|---|---|
| POST | /v1/sandboxes | create body is microsandbox CloudSandboxSpec (Cellar does not extend it; create-time network.secrets supported) |
| GET | /v1/sandboxes | list |
| GET | /v1/sandboxes/:id | get |
| POST | /v1/sandboxes/:id/start | start |
| POST | /v1/sandboxes/:id/stop | stop |
| DELETE | /v1/sandboxes/:id | remove |
| GET | /v1/sandboxes/:id/logs | log stream |
| GET | /v1/sandboxes/:id/agent | agent WebSocket relay |
| GET | /v1/sandboxes/by-name/:name | get by name |
| POST | /v1/sandboxes/by-name/:name/start | start by name |
| POST | /v1/sandboxes/by-name/:name/stop | stop by name |
| DELETE | /v1/sandboxes/by-name/:name | remove by name |
| GET | /v1/volumes | list volumes |
| POST | /v1/volumes | create volume |
| GET | /v1/volumes/default | default volume |
| DELETE | /v1/volumes/:id | delete volume |
| * | /v1/volumes/:id/files… | volume filesystem ops |
Point official microsandbox SDKs at this gateway as the cloud backend.