Skip to content
Français

Choose a sandbox

Choose where your agent runs commands: a container, a cloud sandbox, a microVM or your machine.

Import the provider from its subpath and pass it as sandboxProvider. The agent, the brief and the branch stay the same.

import { reportValue } from "./reporter.ts";
import { dispatch } from "@elie-laloum/outpost";
import { createVercelSandboxProvider } from "@elie-laloum/outpost/providers/vercel";
import { coder, repository } from "./outpost.config.ts";

const result = await dispatch({
  agent: coder,
  repository,
  sandboxProvider: createVercelSandboxProvider(),
  brief: { text: "Fix the broken links in the README and commit the change." },
});
reportValue(result.branch, result.commits.length);
// Example output: outpost/job-… 1

Each provider has its own subpath, @elie-laloum/outpost/providers/<name>: docker, podman, vercel, daytona, firecracker and local. Omit sandboxProvider and Outpost uses Docker.

Vercel and Daytona load their SDK when they allocate a sandbox. Install it next to Outpost: npm install @vercel/sandbox or npm install @daytona/sdk. The other providers need no extra package.

Docker, PodmanVercelDaytonaFirecrackerHost
Repository accessMounted worktreeUploaded snapshotUploaded snapshotUploaded snapshotHost filesystem
IsolationContainerHosted sandboxHosted sandboxMicroVMNone
Interactive attach()YesNoYesNoYes
Live input for steeringYesYesYesYesYes
Dependency cachesYesNoNoNoNo
Egress rulesdeny-all onlyYesYes, with limitsNoNo
Durable speculation recoveryYesNoNoNoNo
Installs a missing agent CLINoYesYesYesNo
Default branch modecurrentintegrateintegrateintegratecurrent
SetupEngine and image@vercel/sandbox, credentials@daytona/sdk, API keyKVM host, kernel, rootfs, TAP, SSHAgent CLI and tools

Remote providers (Vercel, Daytona, Firecracker) work on a copy of the Git history. They install a missing supported CLI before the first turn unless you pass bootstrap: false, and they reject the current branch mode.

With repositoryMode: "isolated", Docker and Podman behave like a remote provider: see Private Git. They then lose durable speculation recovery, which needs the default mounted mode.

  • Nothing falls back to the host. A missing engine, SDK or credential fails the task; only createLocalSandboxProvider() runs on the host, and you choose it explicitly.
  • A mounted container can write the repository’s Git metadata. It is not a boundary against a hostile agent: read Security.
  • Remote synchronization stops instead of overwriting concurrent host edits, and keeps recovery data. See Cloud sandboxes.
  • A Firecracker provider owns one TAP device and runs one VM at a time. Create one provider per concurrent VM.

API: SandboxProvider · createDockerSandboxProvider · createPodmanSandboxProvider · createVercelSandboxProvider · createDaytonaSandboxProvider · createFirecrackerSandboxProvider · createLocalSandboxProvider.