project-sandbox
Container/microVM sandbox for coding agents — supervised or headless sessions, credential & network isolation, git/jj workspace integration: project-sandbox runs Claude Code, Codex CLI, OpenCode, Pi, or a plain Bash shell
inside per-project Linux containers. On macOS, direct CLI runs default to Apple's
container runtime, where each container
runs in its own VM. On Linux, direct CLI runs support Docker or Podman.
⚠️ Created with the help of AI.
🚧 Experimental work in progress
‼️ Use at your own risk.
Main features
Many sandboxes exist - this is the one with a feature-set / configureable agency-boundary that I was comfortable with in the end:
- Strong isolation - on OSX with Apple Container VMs. Custom Dockerfile support (as long as it's based on Debian)
- Agent config glue: Forward host credentials / agent subscriptions into containers selectively, update settings to bypass permissions inside the container.
- Devcontainer support: Creates a matched devcontainer config for editor support (weaker isolation but integrated workflow).
- Unsupervised job runs - submit batch jobs.
- Network access restrictions: restrict to allowed domains, (somewhat) hardened firewall script.
- git/jj integration: Managed execution with worktrees / workspaces. No credentials to push inside containers.
- pinned dependencies: pre-install agents & extra tools into the image, manual upversioning.
- Simple workflow (in my view).
- Minimal dependencies (jinja2)
Quick Start
Install from PyPI:
uv tool install project-sandbox
project-sandbox --help
Or run directly from PyPI without installing:
uvx project-sandbox --help
uvx project-sandbox /absolute/path/to/repo python:3.12-slim
From a source checkout:
uv sync
uv run project-sandbox --help
Generate sandbox files for a project:
project-sandbox /absolute/path/to/repo python:3.12-slim
Preview every action without writing files or starting a runtime:
project-sandbox --dry-run /absolute/path/to/repo python:3.12-slim
Start an agent in the sandbox:
project-sandbox --agent codex /absolute/path/to/repo python:3.12-slim
Build on top of an existing project Dockerfile:
project-sandbox /absolute/path/to/repo --dockerfile /absolute/path/to/repo/Dockerfile
Web projects with npm and headless browser tests can use a generated image (see Node.js + npm projects):
project-sandbox --node-npm --agent claude /absolute/path/to/repo
Documentation
- Usage guide
- Agent proxy setup and security
- Generated files and runtime behavior
- Security model
- Development guide
- References and related projects
- Changelog
- Roadmap and future work
License
MIT. See LICENSE.
Metadata
Release files for project-sandbox 0.2.2
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| project_sandbox-0.2.2.tar.gz | 92.5 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| project_sandbox-0.2.2-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 200.5 kB
Release files / project_sandbox-0.2.2.tar.gz
| Download URL | project_sandbox-0.2.2.tar.gz |
|---|---|
| Size | 92.5 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
677a0501b3420a691f7c87e6dae2ee1ade033d8b2b6bb0bd23b42792b8bdf653
|
|
BLAKE2b-256 checksum How to use checksums |
8515a35b5b18f6da34b441e90b8259fade26309044bcbb18a172b2c0eeec45d8
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.11.24 {"installer":{"name":"uv","version":"0.11.24","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"macOS","version":null,"id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}
|
Release files / project_sandbox-0.2.2-py3-none-any.whl
| Download URL | project_sandbox-0.2.2-py3-none-any.whl |
|---|---|
| Size | 108.0 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
de58b79eaebcb38063871c6e0ccd7284667a3b644d17b872e87a8eb247870806
|
|
BLAKE2b-256 checksum How to use checksums |
3179b4a424c9e0f1537f345127c8589411b6566365a99f6b5eaf8d01960b1bb0
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.11.24 {"installer":{"name":"uv","version":"0.11.24","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"macOS","version":null,"id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}
|