Run in the cloud
Configure Vercel or Daytona and synchronize the agent’s work with your repository.
Prerequisites
Section titled “Prerequisites”Install the SDK for the cloud provider you want to use alongside Outpost. The sandbox runs remotely, so your machine does not need Docker or Podman.
The host needs allocation credentials to create sandboxes. They stay on the host and are separate from the agent’s credentials, which Outpost installs in the sandbox’s private home.
| Provider | Allocation credentials on the host |
|---|---|
| Vercel | VERCEL_OIDC_TOKEN (from npx vercel env pull), or token, teamId and projectId in create |
| Daytona | DAYTONA_API_KEY, or apiKey in connection |
The sandbox image needs sh and git to synchronize the repository, and node to stream input to the agent.
Vercel Sandbox
Section titled “Vercel Sandbox”Vercel stops a sandbox after create.timeout milliseconds: set it longer than your task.
API reference: VercelOptions.
Daytona Sandbox
Section titled “Daytona Sandbox”Create a Daytona provider with a Node.js 24 image. Use this sandboxProvider in your configuration or pass it directly to the task, as shown below.
API reference: DaytonaOptions.
Compare Vercel and Daytona
Section titled “Compare Vercel and Daytona”| Vercel | Daytona | |
|---|---|---|
attach() | No: interactive terminals are rejected | Yes, through Daytona’s PTY API |
| Live input | Each instruction is appended to a file in the sandbox | Same |
| Egress rules | Native firewall: domains, CIDRs allowed and denied | Confirmed by Daytona: domains or IPv4 CIDRs |
| Billing | Until Outpost stops the sandbox | Until Outpost deletes the sandbox |
Live input costs one provider command per instruction: a wrapper started with the agent reads the file and feeds its standard input.
Run a task
Section titled “Run a task”Pass the provider to dispatch() or createSandbox() as with any sandbox.
Before the first turn, Outpost installs the agent’s CLI at its pinned version if the image lacks it, on every remote sandbox. Set bootstrap: false when the image must provide it. The sandboxReady hook then installs the project’s dependencies (Prepare the environment).
dispatch() releases the sandbox when it returns. Close a sandbox from createSandbox() in finally, or with await using: the provider bills it until then.
Repository access
Section titled “Repository access”The sandbox works on its own copy of the repository. Outpost keeps it in step with the managed worktree on your machine. Firecracker and private Git containers synchronize the same way.
Choose the branch
Section titled “Choose the branch”Without branch, a cloud sandbox uses integrate: a new outpost/job-… branch, merged into your current branch at the end. named keeps the work on a branch you name. current is rejected, because the sandbox cannot edit your checkout in place. See Repository and branch.
Send files Git does not have
Section titled “Send files Git does not have”Commit the files the sandbox needs before running a task. For ignored test configuration or other local inputs, consult the workspace and synchronization options below.
API reference: WorkspaceOptions and SandboxOptions.
A copy that .gitignore excludes travels one way: the agent’s edits to it stay in the sandbox. Any other copy becomes uncommitted work in the worktree, so pass includeUncommitted: true with it.
When synchronization stops
Section titled “When synchronization stops”Outpost never overwrites work it cannot back up. It stops with an error of code workspace whose details.recovery names the directory under .outpost/recovery holding the downloaded changes and the backup. Inspect it with Recover work.
| Cause | Fix |
|---|---|
| The managed worktree changed while the sandbox was open | Leave .outpost/workspaces alone during the run |
| The agent changed a file that is uncommitted in the worktree | Commit the file first, or pass includeUncommitted: true |
A copy is not excluded by the committed .gitignore (first synchronization) | Pass includeUncommitted: true, or ignore the file in .gitignore |
The agent created a file your host ignores outside .gitignore | Move the ignore rule into the committed .gitignore |
| The agent rewrote a commit that was already synchronized | Ask for new commits instead of an amend or a rebase |
recoveryTransport on dispatch() or createSandbox() also archives each backup to object storage.
Limits
Section titled “Limits”- All refs upload: The history bundle holds every branch and tag of the repository, not only the work branch.
- Command deadline:
sandbox.command()withoutdeadlineMsstops after 10 minutes. Agent turns follow their own limits. - Output tail: A command result keeps the last 64 KiB of each stream.
retainon the provider changes it. - Bootstrap: Installing the CLI needs
npm(orcurlfor Antigravity) and network access in the sandbox. With a fallback agent, only the first candidate is installed. - Unplanned exits: Outpost releases sandboxes on
SIGINTandSIGTERM. A killed process leaves the sandbox running until the provider’s own timeout.
Implementing another remote provider: Add a sandbox provider.
API: SandboxOptions · EgressPolicy.