Skip to main content

terok-sandbox

terok-sandbox

PyPI License: Apache-2.0 REUSE status Quality Gate Status

The hardened-Podman runtime — terok-sandbox launches per-task containers with a credential vault, a gated git server, and an egress firewall.

terok ecosystem — terok-sandbox sits between the per-task launcher and the firewall it installs

What it provides

  • Hardened container lifecycle — rootless Podman containers.
  • Credential vault — long-lived secrets stay in an encrypted database on the host. The container receives short-lived phantom tokens and never sees the real credentials.
  • Per-task git gate — a token-authenticated HTTP mirror of an arbitrary upstream git repository. Tasks clone and push through the gate, and the gate forwards to upstream automatically (online mode) or after operator review (gatekeeping mode).
  • Shield firewall — installs the terok-shield OCI hooks at setup time and drives the firewall at runtime.
  • Clearance in-supervisor — each container's supervisor hosts the terok-clearance hub, verdict server, and desktop notifier, so the operator can authorise blocked outbound connections live.
  • Setup as one call — idempotent terok-sandbox setup installs the shield + supervisor OCI hooks and provisions the encrypted credentials DB; terok-sandbox uninstall reverses it.

Where it sits in the stack

terok-sandbox is the boundary layer. Above it, single-task callers (terok-executor) and multi-task orchestrators (terok) treat the sandbox as a black-box "give me a hardened container." Below it, it composes terok-shield for egress filtering and terok-clearance for the operator-in-the-loop verdict path.

Public API

from terok_sandbox import (
    # Lifecycle
    Sandbox,
    SandboxConfig,
    RunSpec,
    VolumeSpec,
    Sharing,
    # Runtime backends
    PodmanRuntime,
    KrunRuntime,
    NullRuntime,
    ContainerRuntime,
    # Vault + credentials
    CredentialDB,
    SSHManager,
    NoPassphraseError,
    WrongPassphraseError,
    # Gate
    GateServer,
    GitGate,
    mint_gate_token,
    # Shield adapter
    ShieldManager,
    ShieldHooks,
    check_environment,
    # Per-container wiring / setup state
    write_sidecar,
    remove_container_state,
    sandbox_uninstall,
    check_setup,
)

The full export list lives in src/terok_sandbox/__init__.py.

CLI

Command Purpose
terok-sandbox setup Install shield + supervisor OCI hooks, provision the credentials DB; idempotent
terok-sandbox uninstall Reverse of setup
terok-sandbox prepare / run / cleanup Wire a user-owned container into the sandbox services
terok-sandbox doctor Run host-side sandbox health checks
terok-sandbox vault … Vault status / unlock / lock / passphrase-tier management
terok-sandbox gate … Git gate inspection (gate path <project>)
terok-sandbox shield … Shield hooks install / status / direct control
terok-sandbox ssh … Per-scope SSH key management in the credentials DB
terok-sandbox credentials encrypt-db Encrypt (migrate) a plaintext credentials DB

SSH keys

terok-sandbox ssh add myscope
terok-sandbox ssh add myscope -c gitlab-deploy
terok-sandbox ssh list --scope myscope
terok-sandbox ssh pub myscope
terok-sandbox ssh default myscope 2
terok-sandbox ssh pub myscope --key-id 2

ssh add always creates another key. Without -c / --comment, its name is the next unused myscope-N; an interactive terminal prompts to accept or override that suggestion. Imports preserve their original comment unless -c / --comment overrides it.

The first assigned key becomes the scope's default. Adding or renaming keys does not change it. ssh list marks the default with *; ssh default selects another assigned key to offer first through the SSH agent socket. ssh pub prints every assigned public key, one per line with the default first, or just the key selected by --key-id. ssh add --force replaces the scope's existing keys with a fresh default.

Requirements

  • Linux with Podman (rootless, ≥ 5.6 recommended)
  • systemd ≥ 257 — optional; backs the systemd-creds vault passphrase tier (gate / vault / clearance run inside the per-container supervisor, no systemd units)
  • nftables (nft binary) — provided by terok-shield's runtime
  • D-Bus session bus — for the clearance notifier path; the system degrades gracefully when D-Bus is absent
  • Python 3.12+

Installation

pip install terok-sandbox

For most users this dependency is pulled in transitively by terok-executor or terok. Install it directly only when building a custom orchestrator on top of the sandbox API.

License

Apache-2.0 — see LICENSES/Apache-2.0.txt.

Metadata

Release files for terok-sandbox 0.6.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for terok-sandbox 0.6.0
File Size Uploaded
terok_sandbox-0.6.0.tar.gz 943.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for terok-sandbox 0.6.0
File Interpreter ABI Platform
terok_sandbox-0.6.0-py3-none-any.whl Python 3 none any Details

Total release size: 1.4 MB

Release files / terok_sandbox-0.6.0.tar.gz

Download URL terok_sandbox-0.6.0.tar.gz
Size 943.4 kB
Tags Source
SHA-256 checksum
How to use checksums
eab96e0932296a60bd005e7e2f86e8acdfd1ed9c7130d52c8715e10c8bd483b9
BLAKE2b-256 checksum
How to use checksums
efcec9728f90071d3ffdfab98d157e9fc00f9f0d1a3ed0dbd150460c096e10e3
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 29, 2026.

Transparency log

Release files / terok_sandbox-0.6.0-py3-none-any.whl

Download URL terok_sandbox-0.6.0-py3-none-any.whl
Size 431.5 kB
Tags Python 3
SHA-256 checksum
How to use checksums
aa5b3e6d33c0b6d3244c79845ff932ba23d52560f91bae9ad792bde1f5c10549
BLAKE2b-256 checksum
How to use checksums
ff9c2d8bb42a2a7c296ecd600321bb2d288e9d0594f3439e9b7107123d62891c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 29, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.6.0 This release

2 release files

0.5.0

2 release files

0.4.1

2 release files

0.4.0

2 release files

0.3.1

2 release files

0.3.0

2 release files

0.2.0

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page