project-sandbox
Container/microVM sandbox for coding agents — supervised or headless sessions, credential & network isolation, git/jj workspace integration: project-sandbox runs Claude Code, Codex CLI, OpenCode, Pi, or a plain Bash shell
inside per-project Linux containers. On macOS, direct CLI runs default to Apple's
container runtime, where each container
runs in its own VM. On Linux, direct CLI runs support Docker or Podman.
⚠️ Created with the help of AI.
🚧 Experimental work in progress
‼️ Use at your own risk.
Main features
Many sandboxes exist - this is the one with a feature-set / configureable agency-boundary that I was comfortable with in the end:
- Strong isolation - on OSX with Apple Container VMs. Custom Dockerfile support (as long as it's based on Debian)
- Agent config glue: Forward host credentials / agent subscriptions into containers selectively, update settings to bypass permissions inside the container.
- Devcontainer support: Creates a matched devcontainer config for editor support (weaker isolation but integrated workflow).
- Unsupervised job runs - submit batch jobs.
- Network access restrictions: restrict to allowed domains, (somewhat) hardened firewall script.
- git/jj integration: Managed execution with worktrees / workspaces. No credentials to push inside containers.
- pinned dependencies: pre-install agents & extra tools into the image, manual upversioning.
- Simple workflow (in my view).
- Minimal dependencies (jinja2)
Quick Start
Install from PyPI:
uv tool install project-sandbox
project-sandbox --help
Or run directly from PyPI without installing:
uvx project-sandbox --help
uvx project-sandbox /absolute/path/to/repo python:3.12-slim
From a source checkout:
uv sync
uv run project-sandbox --help
Generate sandbox files for a project:
project-sandbox /absolute/path/to/repo python:3.12-slim
Preview every action without writing files or starting a runtime:
project-sandbox --dry-run /absolute/path/to/repo python:3.12-slim
Start an agent in the sandbox:
project-sandbox --agent codex /absolute/path/to/repo python:3.12-slim
Build on top of an existing project Dockerfile:
project-sandbox /absolute/path/to/repo --dockerfile /absolute/path/to/repo/Dockerfile
Documentation
- Usage guide
- Agent proxy setup and security
- Generated files and runtime behavior
- Security model
- Development guide
- References and related projects
- Changelog
- Roadmap and future work
License
MIT. See LICENSE.
Metadata
Release files for project-sandbox 0.1.4
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| project_sandbox-0.1.4.tar.gz | 87.8 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| project_sandbox-0.1.4-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 191.0 kB
Release files / project_sandbox-0.1.4.tar.gz
| Download URL | project_sandbox-0.1.4.tar.gz |
|---|---|
| Size | 87.8 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
478d018713dd308faa94362ad7589dd3f6a4c8c213c99a54e6539131444344eb
|
|
BLAKE2b-256 checksum How to use checksums |
c0f64932ed0c083ae78a2b81448c6464de284c70bd16ca1318ed97ce3b1b94a8
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.11.24 {"installer":{"name":"uv","version":"0.11.24","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"macOS","version":null,"id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}
|
Release files / project_sandbox-0.1.4-py3-none-any.whl
| Download URL | project_sandbox-0.1.4-py3-none-any.whl |
|---|---|
| Size | 103.2 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
b202ec81b9cd05f25d0fe70fcee1bb3238d3bd3d26e91692b7a744b3cea6f1e3
|
|
BLAKE2b-256 checksum How to use checksums |
adc5a9fef4ef7c6d59e5d0d7be3a6b0b6d323befcbb96c8ccfdc7ec6014ae8a4
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.11.24 {"installer":{"name":"uv","version":"0.11.24","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"macOS","version":null,"id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}
|