pocketdock
Portable, offline-first container sandboxes for LLM agents and dev workflows.
One Container class. Podman-first, Docker-compatible. Python SDK + CLI. Zero cloud. Zero API keys.
Why pocketdock?
Managed sandbox platforms require API keys, cloud accounts, and an internet connection. Rolling your own container glue means rewriting hundreds of lines of boilerplate every time. pocketdock sits in between: a clean Python SDK that talks directly to your container engine over its Unix socket, works entirely offline, and has zero external dependencies for the core SDK.
Features
- Three execution modes — blocking, streaming, and detached (background) with ring buffer
- File operations — read, write, list, push, and pull files between host and container
- Persistent sessions — long-lived shell sessions with state (cwd, env vars, history)
- Resource limits — memory caps, CPU throttling, per-container isolation
- Port mapping — expose container ports on the host (e.g.,
ports={8080: 80}) - Container persistence — stop/resume, snapshot to image, volume mounts
- Project management —
.pocketdock/project directories with config, logging, and health checks - Image profiles — six pre-baked Dockerfiles: minimal-python, minimal-node, minimal-bun, dev, agent, embedded
- Full CLI — 22 commands for container lifecycle, file ops, and project management
- Async-first — sync facade over async core; use either API style
- Callbacks — register handlers for stdout, stderr, and exit events
Quick Example
from pocketdock import create_new_container
with create_new_container() as c:
result = c.run("echo hello")
print(result.stdout) # "hello\n"
print(result.ok) # True
Install
pip install pocketdock # SDK + CLI (includes click, rich)
pip install pocketdock[agent] # + LLM agent (litellm, python-dotenv)
Single-file downloads (no pip required) are available from GitHub Releases.
Requires Podman (recommended) or Docker.
# Build the minimal-python image (~25MB, <500ms startup)
pocketdock build minimal-python
Documentation
Full documentation is available at deftio.github.io/pocketdock.
- Quickstart — install, build, run your first container
- User Guide — containers, commands, files, sessions, persistence, profiles
- CLI Reference — all 22 commands with examples
- API Reference — full SDK reference
Architecture
User Code / LLM Agent / CLI
|
v
pocketdock SDK
+--------------------------------------+
| Container (sync) -> AsyncContainer | facade pattern
| +- _socket_client (raw HTTP/Unix) |
+- ProjectManager (.pocketdock/) |
+- Persistence (resume, snapshot) |
+- Sessions (persistent shells) |
+--------------------------------------+
| raw HTTP over Unix socket
| (one connection per operation)
v
Podman (rootless) / Docker Engine
Design principles:
- Connection-per-operation — each API call opens its own Unix socket. No pooling.
- Async core, sync facade —
AsyncContainerdoes all real work.Containeris a sync wrapper. - No cached state — always polls live from the engine.
- Minimal dependencies — stdlib-only for the core SDK.
Development
uv sync --dev # Install dependencies
uv run pytest # Run tests (100% coverage enforced)
uv run ruff check . # Lint (zero warnings)
uv run mypy --strict python/ # Type checking (strict mode)
uv run mkdocs serve # Local docs site
License
BSD-2-Clause. Copyright (c) deftio llc.
Release files for pocketdock 1.2.6
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| pocketdock-1.2.6.tar.gz | 173.1 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| pocketdock-1.2.6-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 232.6 kB
Release files / pocketdock-1.2.6.tar.gz
| Download URL | pocketdock-1.2.6.tar.gz |
|---|---|
| Size | 173.1 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
1103a67dc402b0822800660db3eea712e83dd9a6aaa9f7120a2bd47f7a46bb6d
|
|
BLAKE2b-256 checksum How to use checksums |
c89d5ea9e914c35a6da30ec9617198e033925d6dfa256c953c81d0bd54c1039d
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Feb 18, 2026.
Transparency logRelease files / pocketdock-1.2.6-py3-none-any.whl
| Download URL | pocketdock-1.2.6-py3-none-any.whl |
|---|---|
| Size | 59.5 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
a3e3fa17dec57f9fe0bbebe932b746337c204eef1f5ef6a1e4c8e9593d2c82dd
|
|
BLAKE2b-256 checksum How to use checksums |
41c9d4663ce91d29ef8a586d55ef4621dbfa6e08edd7913331afebcd499770b6
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Feb 18, 2026.
Transparency log