Skip to content
Français

Understand security boundaries

Review the files, credentials and network access available to agents and host code.

An agent can run project commands with the access provided by its sandbox. Review the environment, mounted files and credentials before starting a task; the sandbox provider determines these boundaries.

SandboxThe agent reachesBoundary
Docker and PodmanThe worktree and the repository’s Git metadata, both writable; a private home; declared variables.A container with dropped capabilities. Not a boundary against a hostile agent.
Private GitA private checkout and Git directory in the container; a private home; declared variables.Your host Git metadata stays out. Commits return only after validation.
Cloud sandboxesA copy of the history with every branch and tag, selected files, credentials and declared variables.A hosted sandbox in your cloud account. Commits return only after validation.
FirecrackerThe same copy in a microVM with its own guest kernel, reached over SSH.The VM, plus the jailer when you enable it. You operate the host.
Host executionEverything your user can reach: files, network, your home and your full process environment.None.

Each piece of data goes only where your configuration sends it.

DataWhere it goes
Agent loginOutpost reads the selected CLI’s login file on the host, never a system keychain, and copies it into the private sandbox home. Host execution gets variables only.
API keys and variablesInto the sandbox environment. The agent can read every one of them.
Provider and storage keysStay on the host with the cloud provider or transport client. Agents never receive them.
Repository and inputsCloud sandboxes and Firecracker receive the Git history, copies and, on request, uncommitted work.
Persisted objectsA transport receives the artifacts, journals, checkpoints, transcripts and recovery data you route to it.
Transcripts, logs and recovery bundlesKept on the host or in your transport. They can hold any secret that passed through the agent.

MCP servers act with the agent’s authority and receive the variables you name. Their configuration holds variable names, never values. An MCP login copied into a sandbox can rotate its refresh token and sign out the host.

Outpost records who did what and fences concurrent writers. Identity and permission checks stay in your application.

ValueWhat Outpost checksWhat you check
Approval actorIt is listed in the gate’s actorsWho the person is and whether they may decide.
Signed gate decisionAn Ed25519 signature from the actor’s keyThat your signing service authenticated the person.
Artifact producerThe payload matches its digestWho published it: anyone who can write the store can.
Conditional writes and revisionsStale writers are rejectedWho the writer is.
Remote PID in recovery dataNothing: it is metadataThat the remote process stopped before you recover its ownership.
Task cache entryIts key and JSON shapeWho can write the transport: they choose the restored values.
Webhook signatureThe request comes from the configured sourceWhether event.actor may start the workflow.
HTTP queue tokenThe caller holds a configured tokenWho holds it: one token grants every queue operation.

Network restrictions limit outbound connections from the sandbox. They do not govern mounts, credentials or host sockets you expose to it.

Traffic that leaves from the host stays outside the policy: built-in harness model requests, image pulls and cloud control-plane calls. An allowed destination can still receive whatever the agent sends it.

Harden the sandbox first. This Docker provider keeps your Git metadata out of the container and blocks its network:

import { createDockerSandboxProvider } from "@elie-laloum/outpost/providers/docker";

export const sandboxProvider = createDockerSandboxProvider({
  image: "outpost:dev",
  repositoryMode: "isolated",
  egress: { mode: "deny-all" },
});

Without network, a CLI agent cannot reach its model. Use the built-in harness, whose model requests leave from your host, or a cloud sandbox with a domain allowlist.

  • Isolate GitUse Private Git, a cloud sandbox or Firecracker, never host execution.
  • Mount nothing extraAdd no volumes, devices, host sockets or shared caches the task does not need.
  • Scope credentialsSign in with a dedicated profile through account.file, and declare only the keys the task needs.
  • Restrict the networkBlock or allowlist egress where the provider supports it.
  • Keep host hooks trustedRun project scripts in sandboxReady, not in hostReady or workspaceReady.
  • Review before runningRead the returned diff before you build, test or push it on the host.
  • A mounted container is not a boundary against a hostile agent. Outpost disables Git hooks for its own commands, not for yours or for project tooling.
  • Private Git protects your Git metadata, not the host. You still trust the image, the engine, the kernel and every explicit mount.
  • With the Firecracker jailer, the Outpost process runs as root. Run only a trusted workflow project and configuration there.
  • A cloud account stores what Outpost uploads according to its own storage and network policy.

Report a vulnerability privately through the repository’s security policy, without live credentials.

API: ContainerOptions · EgressPolicy · AgentAuthentication · createLocalSandboxProvider · defineHarnessTool · defineHarnessHook.