Keep Git metadata inside the container
Try isolated container repositories and inspect how changes return to the host.
Turn it on
Section titled “Turn it on”Set repositoryMode: "isolated" on a Docker or Podman provider to give the container its own Git checkout. This option is experimental; the rest of the task uses the same agent and dispatch settings.
Outpost copies the branch history into the container and the agent works on that copy. When the task ends, its commits land on outpost/private-fix on your host.
What changes compared with mounted mode
Section titled “What changes compared with mounted mode”| Aspect | Mounted (default) | Isolated |
|---|---|---|
| What the container sees | Your worktree at /workspace and the host Git directories | A private checkout at /tmp/outpost/workspace with its own .git |
| How changes come back | At once: the agent writes to your worktree | After each dispatch, sandbox.command() or attach, validated then applied |
| Host hooks, config, refs | Shared and writable: what the agent writes applies on the host | Not copied in or back: only the branch’s commits and files return |
| Default branch policy | current | integrate; current is rejected |
| Agent CLI | Must be in the image | Installed in the sandbox when missing; bootstrap: false turns this off |
| Durable speculation | Supported | Rejected: the provider cannot recover abandoned containers |
| Interactive terminal | Supported | Supported; changes come back when you quit |
copies and includeUncommitted select extra inputs as on cloud sandboxes. Branch policies: Repository and branch.
Synchronize changes to the host
Section titled “Synchronize changes to the host”Isolated containers use the same synchronization as cloud sandboxes. Before applying anything, Outpost validates the incoming commits and files and backs up the host worktree.
If the host worktree changed while the sandbox was active, or incoming files overlap uncommitted or ignored host files, synchronization stops. Your host files stay untouched, and the error’s details.recovery names a transfer directory under .outpost/recovery/. Inspect and restore it with Recover work.
Mount extra directories
Section titled “Mount extra directories”volumes still works, within three rules:
- Host sideA source cannot contain or sit inside the repository, the worktree or the Git directories, even read-only.
- Container sideA target cannot overlap
/tmpor/outpost; relative targets resolve inside the checkout and are rejected. - Dependency caches
cachesvolumes keep working; Outpost mounts them under/outpost/cache.
Limits
Section titled “Limits”- Isolation protects your host Git metadata, not your host from a hostile agent. You still trust the image, the container engine, the kernel and every explicit mount. See Security.
- The code the agent writes comes back to your host. Review it before running it there.
- Only Docker and Podman have this mode. Cloud sandboxes and Firecracker always work on a copy; host execution never does.
API: ContainerOptions · createDockerSandboxProvider · createPodmanSandboxProvider · Volume.