createPodmanSandboxProvider
Purpose and behavior
Section titled “Purpose and behavior”Create the container provider on the Podman engine, with the same options as Docker. When Outpost does not run as root, userns keep-id maps your user by default; on macOS a Podman machine must be running.
Complete example and detailed rules.
Parameters and properties
Section titled “Parameters and properties”optionsOptionalContainerOptions | undefinedContainer image, repository mode, mounts, environment, network and resource limits.options.egressOptionalEgressPolicy | undefineddeny-all only, applied as the none network. An allowlist, or networks other than none, fails with code configuration at creation.options.repositoryModeOptional"mounted" | "isolated" | undefinedmounted (default) mounts the worktree at /workspace with its Git metadata. isolated makes the provider remote: the history is uploaded to /tmp/outpost/workspace, volumes cannot expose the host repository, and durable speculation recovery is unavailable.options.cachesOptionalreadonly DependencyCache[] | undefinedNamed engine volumes mounted at /outpost/cache/<name> that outlive the sandbox. The volume is derived from repository, image, user, name and key; explicit volumes must not overlap /outpost/cache.options.imageOptionalstring | undefinedImage to run, default outpost:<repository directory name>. When user is unset and the image declares another numeric user than yours, acquisition fails with code provider.options.userOptional{ readonly uid: number; readonly gid: number; } | undefinedUID and GID of commands in the container, default your host UID and GID (1000:1000 where unavailable).options.volumesOptionalreadonly Volume[] | undefinedExtra host mounts into the container.options.variablesOptionalReadonly<Record<string, string>> | undefinedEnvironment variables set for every command in the sandbox, as literal values. A key the agent also declares fails with code configuration.options.networksOptionalstring | readonly string[] | undefinedEngine network or networks to attach, passed as —network.options.groupsOptionalreadonly (string | number)[] | undefinedSupplementary groups for the container user, passed as —group-add.options.devicesOptionalreadonly string[] | undefinedHost devices exposed to the container, passed as —device.options.cpusOptionalnumber | undefinedCPU limit passed as —cpus; must be positive.options.memoryMbOptionalnumber | undefinedMemory limit in megabytes, an integer of at least 64.options.labelOptionalfalse | "z" | "Z" | undefinedSELinux relabeling of bind mounts on Linux: z shared (default), Z private, false plain bind mounts.options.retainOptionalnumber | undefinedBytes of output tail kept per stream, default 65536.options.usernsOptionalfalse | "keep-id" | undefinedPodman user namespace: keep-id maps your user and applies by default when Outpost does not run as root; false disables it. Docker ignores it.