Skip to content
Français

Pass environment variables

Declare which variables reach the sandbox, agent and commands.

Declare each variable where it is needed: on the sandbox provider, on a CLI harness or on one command. Outpost forwards declared names; choose the scope that reaches only the processes needing the value.

import { createAgent, createClaudeHarness } from "@elie-laloum/outpost";
import { createDockerSandboxProvider } from "@elie-laloum/outpost/providers/docker";

export const sandboxProvider = createDockerSandboxProvider({
  image: "outpost:dev",
  variables: { CI: "true", NODE_ENV: "test" },
});

export const coder = createAgent({
  harness: createClaudeHarness({
    authentication: "usage",
    variables: { ANTHROPIC_API_KEY: process.env.ANTHROPIC_API_KEY ?? "" },
  }),
});
WhereReachesUse it for
Sandbox provider variablesEvery command in the sandbox, the agent includedTool settings such as CI or NODE_ENV
Harness variables (CLI agents)The agent’s processes onlyAPI keys, agent settings, MCP secrets
Command variablesThat one commandA per-call override
.outpost/.env in the target repositoryEvery command in the sandbox, like the provider’sValues you keep out of code for a checkout

Values are strings. Select each name from process.env explicitly: spreading process.env would send every host secret into the sandbox. Per-command variables are shown in Sandbox sessions.

When a name appears in several places, the more specific source wins:

.outpost/.env → sandbox provider → harness → command

Outpost also sets GIT_AUTHOR_* and GIT_COMMITTER_* from the repository’s Git configuration; any declared source overrides them.

Outpost reads .outpost/.env at the root of the target repository when it prepares a sandbox. A missing file is ignored.

NODE_ENV=test
LINEAR_API_KEY=

A nonempty value is used as written. An empty declaration such as LINEAR_API_KEY= takes the value from the environment of the process running Outpost. Lines accept export, quotes and trailing # comments.

Node.js can load an environment file before running your script:

node --env-file=.env run.ts

Your code then selects the values to forward with variables. Loading the file into Node.js does not automatically send its contents to the sandbox. The .env path is relative to the directory where you run the command.

Declare only what code in the sandbox needs. Sandbox allocation keys and storage keys stay on the host with their clients: see Authentication.

  • With host execution, commands also inherit the whole environment of the Outpost process.
  • An unset process.env.NAME ?? "" forwards an empty string, not an absent variable.

API: Variables · Command · createDockerSandboxProvider · createClaudeHarness · createHarness.