createDockerSandboxProvider
Purpose and behavior
Section titled “Purpose and behavior”Create the Docker provider, used when sandboxProvider is omitted. By default the worktree and its Git metadata are mounted at /workspace; repositoryMode isolated uploads the history instead. Each acquire creates a container, and release removes it.
Complete example and detailed rules.
Parameters and properties
Section titled “Parameters and properties”optionsOptionalContainerOptions | undefinedContainer image, repository mode, mounts, environment, network and resource limits.options.egressOptionalEgressPolicy | undefineddeny-all only, applied as the none network. An allowlist, or networks other than none, fails with code configuration at creation.options.repositoryModeOptional"mounted" | "isolated" | undefinedmounted (default) mounts the worktree at /workspace with its Git metadata. isolated makes the provider remote: the history is uploaded to /tmp/outpost/workspace, volumes cannot expose the host repository, and durable speculation recovery is unavailable.options.cachesOptionalreadonly DependencyCache[] | undefinedNamed engine volumes mounted at /outpost/cache/<name> that outlive the sandbox. The volume is derived from repository, image, user, name and key; explicit volumes must not overlap /outpost/cache.options.imageOptionalstring | undefinedImage to run, default outpost:<repository directory name>. When user is unset and the image declares another numeric user than yours, acquisition fails with code provider.options.userOptional{ readonly uid: number; readonly gid: number; } | undefinedUID and GID of commands in the container, default your host UID and GID (1000:1000 where unavailable).options.volumesOptionalreadonly Volume[] | undefinedExtra host mounts into the container.options.variablesOptionalReadonly<Record<string, string>> | undefinedEnvironment variables set for every command in the sandbox, as literal values. A key the agent also declares fails with code configuration.options.networksOptionalstring | readonly string[] | undefinedEngine network or networks to attach, passed as —network.options.groupsOptionalreadonly (string | number)[] | undefinedSupplementary groups for the container user, passed as —group-add.options.devicesOptionalreadonly string[] | undefinedHost devices exposed to the container, passed as —device.options.cpusOptionalnumber | undefinedCPU limit passed as —cpus; must be positive.options.memoryMbOptionalnumber | undefinedMemory limit in megabytes, an integer of at least 64.options.labelOptionalfalse | "z" | "Z" | undefinedSELinux relabeling of bind mounts on Linux: z shared (default), Z private, false plain bind mounts.options.retainOptionalnumber | undefinedBytes of output tail kept per stream, default 65536.options.usernsOptionalfalse | "keep-id" | undefinedPodman user namespace: keep-id maps your user and applies by default when Outpost does not run as root; false disables it. Docker ignores it.