Prepare the agent’s environment
Install project dependencies before an agent starts and reuse download caches.
Install dependencies before agent work
Section titled “Install dependencies before agent work”Use a sandboxReady hook to install project dependencies before the agent starts. The command runs in the prepared sandbox, so the agent can use the installed packages during its task.
npm ci runs inside the sandbox, in the repository root. The agent starts with node_modules installed. createSandbox() and openWorkspace() accept the same hooks; speculate() takes them under sandbox.
Choose where each hook runs
Section titled “Choose where each hook runs”API reference: LifecycleHooks.
hostReady and sandboxReady run at the same time. Install dependencies in sandboxReady: they then match the sandbox’s operating system and architecture.
Each entry is a command: executable, arguments, and optionally directory, variables and deadlineMs. These hooks prepare the environment; to intercept the agent’s tool calls, see Permissions and hooks.
Prepare once for several turns
Section titled “Prepare once for several turns”A sandbox runs its hooks once, when it is allocated. sandbox.dispatch(), sandbox.resume() and sandbox.command() reuse the prepared environment. Each top-level dispatch() allocates a fresh sandbox and runs them again.
A workspace from openWorkspace() runs workspaceReady once when it opens. It runs hostReady and sandboxReady for each sandbox it creates, unless that sandbox passes its own hooks, which replace the workspace’s.
Reuse downloads across containers
Section titled “Reuse downloads across containers”Docker and Podman providers accept caches: named volumes that survive the container. Point your package manager at the mounted directory.
Each cache is mounted at /outpost/cache/<name>, owned by the container user. The next sandbox with the same key finds the downloads there. Change key when cached content stops being compatible, for example after a runtime upgrade.
| Package manager | Variable |
|---|---|
| npm | npm_config_cache |
| Yarn | YARN_CACHE_FOLDER |
| pip | PIP_CACHE_DIR |
| Go modules | GOMODCACHE |
Keep the install command in sandboxReady. The cache saves downloads, not the installed project: the package manager still checks the lockfile and fills node_modules.
Manage cache volumes
Section titled “Manage cache volumes”A volume is shared by sandboxes with the same repository, image, container user, cache name and key. Closing a sandbox and outpost image remove keep it. Outpost labels its volumes io.outpost.cache=true:
Podman accepts the same commands with podman.
Limits
Section titled “Limits”- Other providers have no
caches:sandboxReadydownloads everything on each allocation. - Each hook command stops after 10 minutes unless you set
deadlineMs. - A command that exits with a nonzero status rejects with an
OutpostErrorof codeprocess, stops the other preparation commands and releases the sandbox. See Errors. - Commands run without a shell. Call
sh -cfor pipes and&&. - Cache names start with a lowercase letter and hold at most 48 lowercase letters, digits or hyphens. Explicit
volumescannot overlap/outpost/cache. - Every sandbox that mounts a cache can change its content, and later sandboxes read it. Keep credentials out of caches (Security).
API: dispatch · createSandbox · openWorkspace · LifecycleHooks · Command · ContainerOptions · DependencyCache.