Skip to content
Français

createPodmanSandboxProvider

import { createPodmanSandboxProvider } from "@elie-laloum/outpost/providers/podman";

Create the container provider on the Podman engine, with the same options as Docker. When Outpost does not run as root, userns keep-id maps your user by default; on macOS a Podman machine must be running.

Complete example and detailed rules.

  • optionsOptional
    ContainerOptions | undefined
    Container image, repository mode, mounts, environment, network and resource limits.
  • options.egressOptional
    EgressPolicy | undefined
    deny-all only, applied as the none network. An allowlist, or networks other than none, fails with code configuration at creation.
  • options.repositoryModeOptional
    "mounted" | "isolated" | undefined
    mounted (default) mounts the worktree at /workspace with its Git metadata. isolated makes the provider remote: the history is uploaded to /tmp/outpost/workspace, volumes cannot expose the host repository, and durable speculation recovery is unavailable.
  • options.cachesOptional
    readonly DependencyCache[] | undefined
    Named engine volumes mounted at /outpost/cache/<name> that outlive the sandbox. The volume is derived from repository, image, user, name and key; explicit volumes must not overlap /outpost/cache.
  • options.imageOptional
    string | undefined
    Image to run, default outpost:<repository directory name>. When user is unset and the image declares another numeric user than yours, acquisition fails with code provider.
  • options.userOptional
    { readonly uid: number; readonly gid: number; } | undefined
    UID and GID of commands in the container, default your host UID and GID (1000:1000 where unavailable).
  • options.volumesOptional
    readonly Volume[] | undefined
    Extra host mounts into the container.
  • options.variablesOptional
    Readonly<Record<string, string>> | undefined
    Environment variables set for every command in the sandbox, as literal values. A key the agent also declares fails with code configuration.
  • options.networksOptional
    string | readonly string[] | undefined
    Engine network or networks to attach, passed as —network.
  • options.groupsOptional
    readonly (string | number)[] | undefined
    Supplementary groups for the container user, passed as —group-add.
  • options.devicesOptional
    readonly string[] | undefined
    Host devices exposed to the container, passed as —device.
  • options.cpusOptional
    number | undefined
    CPU limit passed as —cpus; must be positive.
  • options.memoryMbOptional
    number | undefined
    Memory limit in megabytes, an integer of at least 64.
  • options.labelOptional
    false | "z" | "Z" | undefined
    SELinux relabeling of bind mounts on Linux: z shared (default), Z private, false plain bind mounts.
  • options.retainOptional
    number | undefined
    Bytes of output tail kept per stream, default 65536.
  • options.usernsOptional
    false | "keep-id" | undefined
    Podman user namespace: keep-id maps your user and applies by default when Outpost does not run as root; false disables it. Docker ignores it.

SandboxProvider

export declare const createPodmanSandboxProvider: (
  options?: ContainerOptions,
) => SandboxProvider;