plugin-egress
| Placement | compiled-in (in-process) |
| Source | github.com/opencharly/plugin-egress/candy/plugin-egress |
| Version | 2026.181.0001 |
| Candy | plugin-egress |
This plugin is listed in charly/charly.yml’s compiled_plugins:, so its providers are compiled into the charly binary and register in-process.
Providers
Section titled “Providers”The reserved words this plugin serves:
egress— verb class
What it does
Section titled “What it does”EGRESS VALIDATION plugin (M16) — gates the config artifacts charly WRITES to a system (cloud-init user-data/meta/net, kubernetes manifests + kustomization, traefik routes, install-ledger records, the Containerfile + systemd/supervisord units, the libvirt domain XML) against a CUE schema BEFORE the bytes hit disk. The validation logic + the egress CUE schemas (incl. the vendored cloud-config) live here; the ValidateEgress* functions (candy/plugin-fleet/egress.go — the former charly/egress.go is DELETED, K-wave 2) Invoke this plugin’s OpValidate. Compiled-in (the build/deploy hot paths call it many times).
Parameter schema
Section titled “Parameter schema”The CUE schema below is the authoritative grammar for this plugin’s input. It is the same single source that generates the plugin’s Go parameter types and answers the runtime Describe RPC, so this page cannot disagree with either.
schema/egress.cue
Section titled “schema/egress.cue”// plugin-egress's OWN self-contained CUE schema — the plugin's declaration// surface, served over Describe exactly like every other// plugin's schema (there is no schema-less plugin)://// 1. SERVE over Describe — the host splices `base ++ plugin` at the load gate// (registerPluginUnitSchema), so the plugin's declarations travel WITH it and// a self-contained schema that will not splice is a LOUD load failure.// 2. DOCUMENT — `charly docs generate` renders this plugin's page from its// providers + this schema + the candy `description:`.//// verb:egress's authored input is NOT a plugin_input: callers resolve the word and// Invoke OpValidate with a `{kind, data}` envelope (the rendered artifact + the// egress kind it must validate against), so this schema DOCUMENTS the verb contract.// The egress VALIDATION schemas (#RenderedText, #K8sObject, ...) stay INTERNAL to the// plugin (egress-schemas/) and are never part of the served blob. SELF-CONTAINED: it// references no base def, so it compiles STANDALONE (the property that lets the SDK// compile it serve-side).#EgressPlugin: { // The capability word the plugin serves. verb: "egress"
// What the verb does, in one line (the public-docs surface): validate an egress // artifact against its kind's CUE schema BEFORE the bytes hit disk. contract: string & !=""}See also the candy reference for this candy’s install surface.