Use Docker or Podman
Configure local containers, repository mounts and the user that runs agent commands.
Prerequisites
Section titled “Prerequisites”Before running a task, check that the container engine responds and the agent image is available:
- Docker or PodmanInstalled and running. On macOS, start a Podman machine with
podman machine start. - An agent imageContains the agent CLIs your tasks will use.
- A Git repositoryThe checkout the container mounts.
Configure
Section titled “Configure”Both providers take the same options. Pass the provider to dispatch(), createSandbox() or any workflow task.
Each allocation starts a fresh container from the image. Closing the sandbox removes it.
API reference: ContainerOptions, Volume and DependencyCache.
Repository access
Section titled “Repository access”The container mounts the task’s checkout at /workspace and the repository’s Git metadata under /outpost/git. The agent’s edits and commits land directly on the host, in the worktree Outpost prepared.
To expose more host paths, add volumes. A relative source starts from the repository; a target starting with ~/ lands in the agent home, any other relative target under /workspace.
- Private home
/home/agentis a tmpfs, discarded with the container. The harness copies the agent’s credentials there. - Reduced privilegesLinux capabilities are dropped (
CHOWNstays when caches, file mounts or Private Git need it) andno-new-privilegesis set. - No engine accessThe Docker or Podman socket is never mounted.
Every mount, device and network you add widens what the agent can reach. To keep the host Git metadata out of the container, use Private Git.
Podman
Section titled “Podman”Rootless Podman maps your host user into the container with --userns keep-id, so files the agent writes stay owned by you. Set userns: false to leave the mapping to your Podman configuration. When Podman runs as root, set userns: "keep-id" to request it.
Choose SELinux labels that match your host instead of loosening repository permissions.
API reference: ContainerOptions.
outpost init --sandbox-provider podman writes a Containerfile instead of a Dockerfile.
Limits
Section titled “Limits”- The provider never falls back to host execution. If the engine or image is missing, allocation fails; run Diagnostics.
- The image must provide
sh,setsid,kill,tarandcp. Generated images do. - When the image declares a numeric user that differs from the requested UID, allocation fails. Rebuild the image with your UID or set
user. egressaccepts onlydeny-all. Domain allowlists need a cloud sandbox or an external firewall.- A single file can be mounted only inside the agent home; mount its directory for other destinations.
- Mounted checkout and Git metadata are writable: this is not a boundary against a hostile agent (Security).
API: createDockerSandboxProvider · createPodmanSandboxProvider · ContainerOptions · Volume · DependencyCache.