Skip to main content
See the snapshot guide for workflows and examples. Use snapshot objects or references on cloud. Local operations also accept a group head, group:member, or artifact path.

Guest writeback

Set SnapshotCreateOptions.GuestFlush to msb.GuestFlushRequired, pass msb.WithBranchGuestFlush(msb.GuestFlushRequired) to Branch/BranchMany, or call source.PauseWithGuestFlush(ctx, msb.GuestFlushRequired). The default GuestFlushAuto flushes live disk-only captures, but adds no optional flush to full captures, branches, or pause. GuestFlushSkip retains mandatory storage barriers. A paused disk capture needs a matching prior flush; cloud rejects non-Auto policies. See guest flush policy reference. Disk capture, including SandboxHandle.Snapshot, requires a native library that supports guest-flush policies. Older libraries return an upgrade-required error, including for stopped disk captures. Full Auto capture and unrelated operations retain their compatibility.

Snapshot functions

Package-level helpers for snapshot artifacts. Access them through the exported Snapshot value, e.g. m.Snapshot.Create(ctx, ...).

Snapshot.Create()

Create a disk snapshot, or set Full to include memory and execution state. SnapshotCreateOptions.FromSandbox is required. An empty Name is generated; an empty Group uses the source sandbox’s name.

Parameters

ctxcontext.Context
Cancellation and deadline.
Name, source sandbox, labels, and integrity options.

Returns

The created local or cloud snapshot.

Snapshot.CreateArchive()

Capture directly into an archive without installing a local snapshot.

Snapshot.Open()

Open an existing artifact by group head, group:member, or filesystem path. This validates metadata only; call s.Verify() for content checks.

Parameters

ctxcontext.Context
Cancellation and deadline.
pathOrNamestring
Group head or group:member selector or artifact directory path.

Returns

The opened local or cloud snapshot.

Snapshot.Get()

Look up a lightweight handle by group head, group:member, stable snapshot ID, descriptor digest, or artifact path. Global IDs and digests must resolve unambiguously.

Parameters

ctxcontext.Context
Cancellation and deadline.
nameOrDigeststring
Group head, group:member, stable snapshot ID, digest, or artifact path.

Returns

Lightweight handle returned by the active backend.

Snapshot.List()

List snapshots visible through the active backend. Cloud lists managed snapshots; host-volume artifacts are opened explicitly by reference.

Returns

All indexed handles.

Snapshot.ListDir()

Walk a local directory and parse each subdirectory’s manifest without touching the local index. Cloud returns ErrUnsupportedOperation.

Parameters

ctxcontext.Context
Cancellation and deadline.
dirstring
Directory holding snapshot artifact subdirectories.

Returns

One artifact per parsed subdirectory.

Snapshot.Remove()

Remove a snapshot through the active backend. Locally, removal also updates the index and refuses indexed children unless force is true.

Parameters

ctxcontext.Context
Cancellation and deadline.
pathOrNamestring
Group head, group:member, or artifact path.
forcebool
Delete even if the snapshot has indexed children.

Snapshot.Reindex()

Walk dir and rebuild the local index from the artifacts it finds. Cloud returns ErrUnsupportedOperation.

Parameters

ctxcontext.Context
Cancellation and deadline.
dirstring
Directory to scan for snapshot artifacts.

Returns

uint32
Number of artifacts indexed.

Snapshot.Save()

function
Bundle a snapshot into a .msb archive at outPath. Set SnapshotSaveOptions.PlainTar to skip compression.

Parameters

ctxcontext.Context
Cancellation and deadline.
nameOrPathstring
Group head, group:member, or artifact path to save.
outPathstring
Destination archive path.
Whether to include parents, the base image, and compression.

Snapshot.Load()

function
Unpack a snapshot archive into the local snapshots directory or an explicit dest directory. Pass "" for the default destination. Cloud returns ErrUnsupportedOperation.

Parameters

ctxcontext.Context
Cancellation and deadline.
archivestring
Path to the snapshot archive.
deststring
Destination directory, or "" for the default snapshots directory.

Returns

Handle to the loaded snapshot.

Snapshot.LoadWithBase()

Import an archive with an explicit dependency base or destination group. See import options.

Snapshot.LoadWithOptions()

Import an archive with an explicit dependency base or destination group. See import options.

Snapshot.LoadMany()

Import archives as one batch. Returns handles in input order. Dependencies resolve from the batch, the named group, or an explicit base; input order does not matter. All members are validated before publication.

Snapshot.GroupHead()

Read a group’s head, or select an exact member with group:member. Returns the group, previous and current snapshot IDs, reason, and whether the head changed. See group selection.

Import options

Options for SnapshotLoadOptions. With divergent tips, the existing head stays selected; a new group has no head. Select a member explicitly. Identical members may be reused; conflicting identities fail. See archive imports.

SandboxHandle methods

Snapshots are taken from a metadata handle returned by GetSandbox. Local disk capture also supports a running or paused sandbox. Cloud requires a stopped persistent source.

h.Snapshot()

Snapshot this sandbox into its default group with the given member name. Local live disk captures preserve the source’s running or paused state. Cloud requires a stopped persistent source. Use the returned artifact path or sandbox:member to open it later.

Parameters

ctxcontext.Context
Cancellation and deadline.
namestring
Member name within the source sandbox’s group.

Returns

The created artifact.

SnapshotArtifact methods

A local or cloud disk snapshot. The accessors below are plain field reads.

s.SaveTo()

Bundle this snapshot through the active backend while preserving its typed identifier-or-path reference. Cloud returns ErrUnsupportedOperation.

s.CopyTo()

Create a new archive from this snapshot’s disk data while replacing its labels and integrity metadata. The source snapshot is unchanged. Cloud returns ErrUnsupportedOperation when Save is called.

s.ID()

Stable opaque snap_... identity.

s.Verify()

Verify the snapshot’s complete state closure. File state recomputes recorded upper-layer integrity. Checkpoint state validates the complete checkpoint closure and returns its root in Checkpoint.

Returns

Recomputed digest and upper-layer status.

s.Reference()

Stable backend-relative value. Prefer passing the SnapshotArtifact itself to RestoreSandbox so its typed reference is preserved as well.

s.ReferenceKind()

Returns "id" or "path". Most callers can pass the artifact itself and never inspect this value.

s.Digest()

Canonical manifest digest (sha256:...).

s.SizeBytes()

Backend-reported stored payload size in bytes.

s.ImageRef()

Image reference the snapshot was taken from.

s.ImageManifestDigest()

Pinned OCI manifest digest of the base image.

s.Format()

Upper-layer disk format: "raw" or "qcow2".

s.Scope()

method
Snapshot scope: SnapshotScopeDisk ("disk") or SnapshotScopeFull ("full").

s.Fstype()

Filesystem type inside the upper layer.

s.Parent()

Parent digest, or nil if this snapshot has no parent. Returns a defensive copy.

s.CreatedAt()

RFC 3339 creation timestamp.

s.Labels()

User labels recorded at creation. Returns a defensive copy.

s.SourceSandbox()

Best-effort source sandbox name, or nil. Returns a defensive copy.

SnapshotHandle methods

A lightweight handle returned by the active backend. The handle retains a stable reference used by Open, Remove, and SaveTo.

h.Open()

Open the underlying snapshot metadata using this handle’s stable reference.

Returns

The opened artifact.

h.Remove()

Remove this installed snapshot copy by its stored artifact path. Other groups containing the same snapshot ID or digest remain unchanged.

Parameters

ctxcontext.Context
Cancellation and deadline.
forcebool
Delete even if the snapshot has indexed children.

h.SaveTo()

Bundle the referenced snapshot through the active backend while preserving the handle’s typed identifier-or-path reference. Cloud returns ErrUnsupportedOperation.

h.Digest()

Manifest digest.

h.Name()

Member name within its group, or nil when no alias is recorded. Returns a defensive copy.

h.ParentDigest()

Parent digest, or nil. Returns a defensive copy.

h.ImageRef()

Pinned image reference.

h.Format()

Upper-layer disk format: "raw" or "qcow2".

h.Scope()

method
Snapshot scope: SnapshotScopeDisk ("disk") or SnapshotScopeFull ("full").

h.SizeBytes()

Backend-reported stored payload size, or nil if unknown.

h.ReferenceKind()

Returns "id" or "path" for the handle’s backend-neutral reference.

h.CreatedAt()

Snapshot creation time, decoded from the index’s Unix timestamp.

Restore

Restore into a new detached sandbox. Disk boots fresh; full resumes execution. See restore examples and progress.
Image, replacement, and startup-command options are not accepted. Full restore requires matching CPU and memory settings, keeps captured network devices, and cannot apply a new guest security profile. Use disk-only restore to change these. Full restore rejects missing external filesystems and additional disks by default. Use WithAllowMissingResources() to resume with unavailable devices and warnings. This is separate from strict/relaxed validation of supplied mappings; inheritance does not waive missing backing. Root and owned storage remain required.
Omitted controls retain destination defaults. Durations use time.Duration, rounded up to seconds. Binding fields belong in WithRestoreConfig(RestoreConfig{...}); nil pointers mean omitted. Network policy accepts factory results or NetworkConfig with only Rules, DefaultEgress, and DefaultIngress.

Compaction

Compact a local sandbox’s root or owned disks. See compaction for examples and recovery requirements.
Defaults to the root and owned data disks; excludes named/external volumes and directories. Requires a running or fully stopped local sandbox. Fewer than two sealed layers means no change; no eligible disks returns an empty result with zero counts.Results include aggregate counts and per-disk entries keyed by GuestPath. MaterializedBytes counts copied bytes, not reclaimed space. Times are microseconds: per-disk TotalUs covers preparation; aggregate TotalUs also includes switching; PauseUs measures the shared VM pause.

Constants

Snapshot scopes

Returned by s.Scope() · h.Scope()

Scope of what a snapshot captures: disk-only or disk plus complete VM state.

Types

SnapshotArtifactstruct

Returned by Snapshot.Create() · Snapshot.Open() · Snapshot.ListDir() · h.Snapshot() · h.Open()

A backend-neutral snapshot. Fields are unexported; read them through the accessor methods below.

SnapshotCopyBuilderstruct

Returned by SnapshotArtifact.CopyTo. Fields are unexported; use the fluent methods below.

SnapshotHandlestruct

Returned by Snapshot.Get() · Snapshot.List() · Snapshot.Load()

A lightweight handle returned by the active backend. Fields are unexported; read them through the accessor methods below.

SnapshotCreateOptionsstruct

Accepted by Snapshot.Create()

Configures Snapshot.Create. FromSandbox is required. An empty Name is generated; an empty Group uses the source sandbox’s name.

SnapshotSaveOptionsstruct

Accepted by Snapshot.Save() and instance SaveTo() methods

Configures Snapshot.Save and instance SaveTo() methods.

SnapshotVerifyReportstruct

Returned by s.Verify()

Result of Verify.

SnapshotUpperVerifyStatusstruct

Field of SnapshotVerifyReport

Upper-layer integrity details inside a SnapshotVerifyReport.