Skip to content

Capabilities ​

The package exposes a Docker sandbox client, a runtime contract, an inspection adapter, and policy-constrained agent tools.

SurfaceCapability
LifecycleExplicit image pull, create, stop, resume by ID, destroy, and async disposal
CommandsBuffered exec and event-based execStream, stdin, env, cwd, timeout, abort signal, and output bounds
FilesBinary/text read and write, listing, bounded paged text reads, and creation-time seeding
WorkspacesEphemeral Docker volumes or existing named Docker volumes
ProcessesStart, list, read bounded logs, and stop long-running processes
PortsPublish declared ports to random loopback host ports and wait for readiness
InspectionOpt-in, read-only file, port, and process capabilities through sandbox.inspector(...)
Agent toolsExplicit command, file, process, port, and readiness tool selection with policy limits
Image CLIGenerate and optionally build composed runtime images with create-image

Image builder ​

sh
pnpm dlx @anvia/sandbox create-image \
  --name reports \
  --runtime node \
  --runtime python \
  --feature artifacts

The CLI supports curated runtimes/features plus explicit apt, npm, and uv packages. --dry-run prints without writing or building; --no-build writes the Docker context only. Generated custom package versions can drift unless pinned.

Boundaries ​

The package does not provide a remote sandbox service, scheduler, artifact registry, secret manager, automatic image pulling, or complete hostile-code guarantee. Docker and host configuration remain part of the isolation boundary.

See lifecycle, security, and the API reference.

Built for Anvia.