egressOptional
EgressPolicy | undefined
deny-all only, applied as the none network. An allowlist, or networks other than none, fails with code configuration at creation.
repositoryModeOptional
"mounted" | "isolated" | undefined
mounted (default) mounts the worktree at /workspace with its Git metadata. isolated makes the provider remote: the history is uploaded to /tmp/outpost/workspace, volumes cannot expose the host repository, and durable speculation recovery is unavailable.
cachesOptional
readonly DependencyCache[] | undefined
Named engine volumes mounted at /outpost/cache/<name> that outlive the sandbox. The volume is derived from repository, image, user, name and key; explicit volumes must not overlap /outpost/cache.
imageOptional
string | undefined
Image to run, default outpost:<repository directory name>. When user is unset and the image declares another numeric user than yours, acquisition fails with code provider.
userOptional
{ readonly uid: number; readonly gid: number; } | undefined
UID and GID of commands in the container, default your host UID and GID (1000:1000 where unavailable).
volumesOptional
readonly Volume[] | undefined
Extra host mounts into the container.
variablesOptional
Readonly<Record<string, string>> | undefined
Environment variables set for every command in the sandbox, as literal values. A key the agent also declares fails with code configuration.
networksOptional
string | readonly string[] | undefined
Engine network or networks to attach, passed as —network.
groupsOptional
readonly (string | number)[] | undefined
Supplementary groups for the container user, passed as —group-add.
devicesOptional
readonly string[] | undefined
Host devices exposed to the container, passed as —device.
cpusOptional
number | undefined
CPU limit passed as —cpus; must be positive.
memoryMbOptional
number | undefined
Memory limit in megabytes, an integer of at least 64.
labelOptional
false | "z" | "Z" | undefined
SELinux relabeling of bind mounts on Linux: z shared (default), Z private, false plain bind mounts.
retainOptional
number | undefined
Bytes of output tail kept per stream, default 65536.
usernsOptional
false | "keep-id" | undefined
Podman user namespace: keep-id maps your user and applies by default when Outpost does not run as root; false disables it. Docker ignores it.