Skip to main content

OpenShell sandbox management CLI

Project description

sandboxctl

Safe, isolated sandboxes for using LLMs with minimal guardrails to maximize developer productivity.

Experimental. sandboxctl is under active development. Commands, configuration, and behavior may change between releases.

Features

  • Isolated sandboxes -- each sandbox runs in its own OpenShell container with a dedicated filesystem and toolchain.
  • Profile system -- define reusable sandbox configurations (repos, extensions, settings) as declarative profiles.
  • Cross-platform credentials -- OS keychain integration for GitHub and GitLab tokens on macOS and Linux.
  • Scoped Git tokens -- per-sandbox token injection so credentials never leak across projects.
  • Health checks and auto-recovery -- doctor and validate commands detect drift and repair common issues automatically.
  • CLI lifecycle management -- create, list, inspect, delete, and upgrade sandboxes from a single tool.

Prerequisites

Requirement Version
Python 3.12+
NVIDIA OpenShell latest
OS macOS or Linux

Installation

Install from PyPI:

pip install sandboxctl

Or install with uv:

uv tool install sandboxctl

For development:

git clone https://github.com/butler54/sandboxctl.git
cd sandboxctl
make dev

Quickstart

# 1. Create the default configuration file
sandboxctl config init

# 2. Edit the config with your identity and preferences
#    (see Configuration section below)
$EDITOR "$(sandboxctl config path)"

# 3. Create a new profile skeleton
sandboxctl init my-project

# 4. Edit the profile to add repos, extensions, and settings
$EDITOR ~/.config/sandboxctl/profiles/my-project.toml

# 5. Create a sandbox from the profile (planned)
sandboxctl create my-project

# 6. Open the sandbox in VS Code (planned)
sandboxctl open my-project

Configuration

sandboxctl uses an XDG-compliant TOML configuration file, typically located at ~/.config/sandboxctl/config.toml. Run sandboxctl config init to generate the default template:

[identity]
# user_name = "Your Name"
# user_email = "you@example.com"

[defaults]
# model = "claude-sonnet-4-20250514"
# theme = "dark"
# zoom = -1

[providers]
# provider = "anthropic"                  # "anthropic" (default) or "vertex"
# anthropic_api_key = ""                  # API key for direct Anthropic access
# vertex_project_id = ""                  # Google Cloud project (vertex only)
# vertex_region = "global"               # Vertex AI region (vertex only)

[paths]
# ssh_key = "~/.ssh/sandboxctl_ed25519"
# ca_bundle = ""

[keychain]
# github_service = "sandboxctl-github-token"
# gitlab_service = "sandboxctl-gitlab-token"

All values can also be set via environment variables with the SANDBOXCTL_ prefix (e.g., SANDBOXCTL_IDENTITY__USER_NAME).

Profiles

Profiles are TOML files under ~/.config/sandboxctl/profiles/ that describe a sandbox environment. Run sandboxctl init <name> to scaffold a new profile, then customize the generated file with your repositories, container settings, and SSH configuration.

Commands

Command Description
sandboxctl --version Show version and exit
sandboxctl list List profiles and running sandboxes
sandboxctl status Show gateway and sandbox status
sandboxctl init <name> Create a new profile skeleton
sandboxctl delete <name> Delete a sandbox
sandboxctl validate <name> Run validation tests inside a sandbox
sandboxctl doctor <name> Diagnose and recover sandbox issues (--no-recover to skip recovery)
sandboxctl upgrade Upgrade OpenShell to latest version
sandboxctl config init Create default configuration file
sandboxctl config show Show current configuration
sandboxctl config path Print config file path
sandboxctl create <name> Create a sandbox from a profile (planned)
sandboxctl open <name> Open a sandbox in VS Code (planned)
sandboxctl setup Initial setup and credential configuration (planned)
sandboxctl restart <name> Restart a sandbox (planned)

Development

This project uses uv for dependency management and ruff for linting and formatting.

make dev       # Install in dev mode with all dependencies
make lint      # Check code style (ruff check + format check)
make format    # Auto-format code
make test      # Run tests with coverage
make clean     # Remove build artifacts

Tests run with pytest and require no external services. Integration tests that need a running OpenShell instance are marked with @pytest.mark.integration and skipped by default in CI.

License

Apache-2.0

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

sandboxctl-1.8.4.tar.gz (70.1 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

sandboxctl-1.8.4-py3-none-any.whl (42.7 kB view details)

Uploaded Python 3

File details

Details for the file sandboxctl-1.8.4.tar.gz.

File metadata

  • Download URL: sandboxctl-1.8.4.tar.gz
  • Upload date:
  • Size: 70.1 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.13

File hashes

Hashes for sandboxctl-1.8.4.tar.gz
Algorithm Hash digest
SHA256 0164b61066997c9ad63ff35d3f1538c6b868fff6af0ce9e785f714a2be6c0144
MD5 978760c3e9ce6ff981553721d246f6b7
BLAKE2b-256 9c78c8d64fdfea6e02612c75e104893e70c906915206ddac26c4f2c006c1a05f

See more details on using hashes here.

Provenance

The following attestation bundles were made for sandboxctl-1.8.4.tar.gz:

Publisher: release.yml on butler54/sandboxctl

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file sandboxctl-1.8.4-py3-none-any.whl.

File metadata

  • Download URL: sandboxctl-1.8.4-py3-none-any.whl
  • Upload date:
  • Size: 42.7 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.13

File hashes

Hashes for sandboxctl-1.8.4-py3-none-any.whl
Algorithm Hash digest
SHA256 d76b1713973672c49511b8db83ab9dd54d91f3672fb844d78fd9868aa3f25a86
MD5 efbc59fe366a2f8ad6c8752a2b04abab
BLAKE2b-256 8ea369cb97fcfa5b3d02633432347a724401d0362adcd98c25d7bcb544477c33

See more details on using hashes here.

Provenance

The following attestation bundles were made for sandboxctl-1.8.4-py3-none-any.whl:

Publisher: release.yml on butler54/sandboxctl

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page