Skip to content
Français

Choose isolation settings

Combine execution, Git and network controls according to the access your task needs.

Docker and Podman take both layers at once: the container reaches no network and never sees your worktree.

import { reportValue } from "./reporter.ts";
import { createDockerSandboxProvider } from "@elie-laloum/outpost/providers/docker";

const sandboxProvider = createDockerSandboxProvider({
  image: "outpost:dev",
  repositoryMode: "isolated",
  egress: { mode: "deny-all" },
});
reportValue(sandboxProvider.name);
// Example output: docker

Prepare the tools and dependencies in the image first. A CLI agent cut off from the network cannot reach its model; the built-in harness can, because its model requests leave from your host and only its tools run offline.

LayerSet onKeeps the agent away fromAvailable on
Egress policyThe sandbox providerHosts you did not allowDocker and Podman: deny-all only; allowlists on Vercel and Daytona
Private GitDocker or PodmanYour worktree and your host Git directoriesDocker and Podman
Hosted sandboxThe provider you chooseYour filesystem, your processesVercel, Daytona, Firecracker
Declared variablesdispatch() or the providerValues you did not declareEvery provider

Remote providers always work on a copy of the history. Host execution isolates nothing: createLocalSandboxProvider() runs commands on your machine, and you select it explicitly.

  • A policy is fixed when the provider is created, and an allowed destination can still receive whatever the agent sends it.
  • Egress does not govern traffic Outpost handles itself: harness model requests, image pulls, file transfers and cloud control-plane calls.
  • Private Git protects your Git metadata, not your host. You still trust the image, the engine, the kernel and every mount you add.
  • The code the agent writes comes back to your machine. Read it before you run it there.
  • Nothing falls back to the host: a missing engine, SDK or credential fails the task instead.

API: EgressPolicy · ContainerOptions · VercelOptions · DaytonaOptions · createDockerSandboxProvider · createLocalSandboxProvider.