Skip to main content

YOLO Jail

CI License

Describe your agentic development environment once — agents, config, skills, tools and credentials — and run it anywhere from a sealed jail to your own shell.

yolo composes everything an AI coding agent works with: which agents are installed (Claude Code, Codex, Copilot, opencode, pi, Antigravity), their settings and house rules, skills, MCP and language servers, packages, and the credentials and host services they may reach. You describe it once, declaratively and per workspace, and yolo renders that description wherever the agent runs. Runs on Linux and macOS (Apple silicon, and Intel for now).

Why?

Setting up an AI coding agent well means installing it, configuring it, writing its house rules, wiring its MCP and language servers, giving it skills and tools, and handing it the logins it needs, then doing it all again for the next agent, the next project and the next machine. yolo turns that into one declaration you can version, share as a pack, and apply anywhere.

How much the agent is confined is one setting of that declaration:

  • A jail, the default: an isolated Linux container, with Podman on Linux or Apple Container or Podman on a Mac. Your project is mounted read-write at /workspace, and your SSH keys, git credentials and cloud tokens are not there, so agents run without permission prompts.
  • Your own machine: yolo host apply writes the same settings, skills and house rules into your real home, and yolo host -- <agent> runs an agent there with its keys and profile.
  • macos-user, in development: the agent runs as a hidden macOS user inside Apple's sandbox, with no VM.

The user guide (source) explains how it works, and its feature index lists everything yolo can set up.

Prerequisites

Three things on the host, whichever way you install:

  • Nix, a reproducible package builder, which builds the jail image. On a Mac, the Nix daemon must also trust your user, so that it can download yolo's prebuilt image pieces and build anything uncached in a temporary container.
  • A container runtime: Apple Container on a Mac with Apple silicon and macOS 26 or later (the Mac default), or Podman — rootless on Linux, or with its Podman Machine VM on any Mac.
  • yolo itself, below.

Platforms:

  • Linux, x86_64 and arm64 — rootless Podman. Both are CI-tested, from one Nix image definition.
  • macOS, Apple silicon — Apple Container (recommended) or Podman Machine, running a native arm64 Linux container with no emulation. The macos-user sandbox, which needs no container runtime, is coming. See the macOS guide.
  • macOS, Intel — Podman Machine only, and ending: Apple Container, Podman 6, Homebrew's prebuilt packages and the NixOS Nix installer have dropped Intel Macs, and the Nix packages yolo uses there stop receiving fixes at the end of 2026. Install yolo there from a release archive rather than Homebrew.

Install

brew install mschulkind-oss/tap/yolo-jail

Homebrew works on macOS and Linux and installs yolo only, so install Nix and a runtime first. Getting Started has the copy-paste steps for each Mac and Linux setup: the Nix installer and the one setting it needs, each runtime and how to check it, the other ways to install yolo, and the first launch.

yolo builds each jail from its flake bundle — flake.nix, its lockfile and the prebuilt in-jail binaries — which it finds beside its own binary, never in your working directory. Homebrew, a release archive and the from-source install ship one. go install and pipx install yolo-jail (or uvx --from yolo-jail yolo) ship the binary alone, so they need a checkout named by YOLO_REPO_ROOT: details.

From source

For hacking on yolo-jail itself, or running an unreleased working tree. Identical on Linux and macOS. You need git, Go and just, or mise to install the pinned Go and just (without them installed):

git clone https://github.com/mschulkind-oss/yolo-jail.git
cd yolo-jail
just setup             # pinned toolchain (mise) + Go module deps
just deploy            # builds + installs the yolo CLI

To upgrade later, run yolo update; Upgrade covers each way of installing.

Upgrading from the Python version

yolo-jail used to ship as a Python package installed with uv tool install. just deploy retires that install for you — it uninstalls the yolo-jail uv tool and clears the console scripts it left in $GOBIN (yolo, yolo-ps, yolo-host-processes, yolo-claude-oauth-broker-host), which otherwise make go install fail with build output "…/yolo" already exists and is not an object file.

Nothing is deleted that cannot be positively identified as part of that old install. If something unrecognized is sitting at $GOBIN/yolo, the migration stops and asks you to look at it rather than guessing. uv itself is no longer a prerequisite.

For development, see Contributing.

Quick Start

yolo init-user-config    # creates ~/.config/yolo-jail/config.jsonc; add "packs": ["claude"] to it
cd ~/code/my-project     # any repository
yolo check               # checks Nix, the runtime and your config; the first run builds the jail
yolo -- claude           # Claude Code in the jail, with its permission prompts off
yolo                     # or a shell in the jail

The shipped agent packs include claude, codex, copilot, opencode, pi and agy; list as many as you like, and each installs the first time you type its name in the jail. With no packs, a jail is a shell with no coding agent. Run yolo check after every config edit, and yolo stop, then yolo again, for a running jail to pick the edit up. On Apple Container, yolo stop does not see the jail yet: stop it with container stop <name>, taking the name from container ls.

Next steps, in the user guide:

Contributing

yolo-jail is a Go module, and AGENTS.md is the guide to developing it: the architecture, the build and test traps, and the file that enforces each rule. From a clone:

just setup           # the toolchain mise.toml pins, and the Go module deps
just check-ci        # the gate CI runs, before you land: go vet and staticcheck for linux and darwin,
                     # gofmt, the changelog and user-guide checks, and the short test suite

The gate also needs python3 on your PATH, for the user-guide checks. Commit messages follow Conventional Commits. Changes a user can notice are described under [Unreleased] in CHANGELOG.md, which becomes the release notes.

The organization's code of conduct and security policy apply here. Its contributing guide describes the pull-request process; its toolchain and code-quality sections are written for the organization's Python projects and do not apply to this one.

Documentation

  • User Guide: installing, configuring and troubleshooting yolo (source)
  • Settings per setup: what each setting does on each runtime
  • yolo config-ref: every config key; yolo --help: every command
  • AGENTS.md: the guide to developing yolo itself

License

Apache License 2.0

Metadata

Release files for yolo-jail 0.11.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Built distributions (wheels)

Table of built distributions (wheels) for yolo-jail 0.11.1
File
yolo_jail-0.11.1-py3-none-musllinux_1_2_x86_64.whl Python 3 none Linux musl 1.2+ x86-64 Details
yolo_jail-0.11.1-py3-none-musllinux_1_2_aarch64.whl Python 3 none Linux musl 1.2+ ARM64 Details
yolo_jail-0.11.1-py3-none-manylinux_2_17_x86_64.whl Python 3 none Linux glibc 2.17+ x86-64 Details
yolo_jail-0.11.1-py3-none-manylinux_2_17_aarch64.whl Python 3 none Linux glibc 2.17+ ARM64 Details
yolo_jail-0.11.1-py3-none-macosx_11_0_arm64.whl Python 3 none macOS 11.0+ ARM64 Details
yolo_jail-0.11.1-py3-none-macosx_10_9_x86_64.whl Python 3 none macOS 10.9+ x86-64 Details

Total release size: 121.4 MB

Release files / yolo_jail-0.11.1-py3-none-musllinux_1_2_x86_64.whl

Download URL yolo_jail-0.11.1-py3-none-musllinux_1_2_x86_64.whl
Size 21.2 MB
Tags Linux musl 1.2+ x86-64 Python 3
SHA-256 checksum
How to use checksums
d82874b95f5d380419f0242af5bb79fbd1aea21a70ad34d5f38ffa05abbd486e
BLAKE2b-256 checksum
How to use checksums
5e3770e9df496665f859b31f74aefebf087d7f67276346ddd703ab6f9645dcc2
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.12.22 {"installer":{"name":"uv","version":"0.12.22","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Release files / yolo_jail-0.11.1-py3-none-musllinux_1_2_aarch64.whl

Download URL yolo_jail-0.11.1-py3-none-musllinux_1_2_aarch64.whl
Size 19.1 MB
Tags Linux musl 1.2+ ARM64 Python 3
SHA-256 checksum
How to use checksums
b2e6fca250d101f9b9afcff887c47eec3b00e5b09a179a9f7492f727d3e018ea
BLAKE2b-256 checksum
How to use checksums
e4fe0b483a4e753b2c3e24d6912c4d4e33e7eadc93879fab481dd53a066cc083
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.12.22 {"installer":{"name":"uv","version":"0.12.22","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Release files / yolo_jail-0.11.1-py3-none-manylinux_2_17_x86_64.whl

Download URL yolo_jail-0.11.1-py3-none-manylinux_2_17_x86_64.whl
Size 21.2 MB
Tags Linux glibc 2.17+ x86-64 Python 3
SHA-256 checksum
How to use checksums
e5283d9fcf949c42246294094b76318677970a022187ec0bb8c8922e7b8b92af
BLAKE2b-256 checksum
How to use checksums
6159f4b2be9ebf05bed264291621fba7d859eff3db5778f91f881c39cbd05047
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.12.22 {"installer":{"name":"uv","version":"0.12.22","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Release files / yolo_jail-0.11.1-py3-none-manylinux_2_17_aarch64.whl

Download URL yolo_jail-0.11.1-py3-none-manylinux_2_17_aarch64.whl
Size 19.1 MB
Tags Linux glibc 2.17+ ARM64 Python 3
SHA-256 checksum
How to use checksums
c4177299453b30782aab98b8662ced5777d131d8736a70220157f5dbd6f713eb
BLAKE2b-256 checksum
How to use checksums
ef0c1d347a7ba5ff2f686535f0e0ef6f0610562e027d3222d8bafcc045b6dd28
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.12.22 {"installer":{"name":"uv","version":"0.12.22","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Release files / yolo_jail-0.11.1-py3-none-macosx_11_0_arm64.whl

Download URL yolo_jail-0.11.1-py3-none-macosx_11_0_arm64.whl
Size 19.4 MB
Tags Python 3 macOS 11.0+ ARM64
SHA-256 checksum
How to use checksums
e16c5c8e94afb55c709a6114a1eba0b6e21fa81ff74879e841fd21c460f81cdc
BLAKE2b-256 checksum
How to use checksums
ae11d9400ac351b39ff02928baeaa6149255dc019082bbc371be906f7a27ab2b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.12.22 {"installer":{"name":"uv","version":"0.12.22","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Release files / yolo_jail-0.11.1-py3-none-macosx_10_9_x86_64.whl

Download URL yolo_jail-0.11.1-py3-none-macosx_10_9_x86_64.whl
Size 21.4 MB
Tags Python 3 macOS 10.9+ x86-64
SHA-256 checksum
How to use checksums
5359aba9769631b1413d1c10c9df3e6379a93e18e92b9eac8ab1783dcb73b265
BLAKE2b-256 checksum
How to use checksums
4142aac33b7b4b289ea3ef0190a33ed7b98568cdd29268447329592300197050
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.12.22 {"installer":{"name":"uv","version":"0.12.22","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Release history Release notifications | RSS feed

This release

0.11.1 This release

6 release files

0.11.0

6 release files

0.10.0

6 release files

0.9.0

6 release files

0.8.0

6 release files

0.7.1

6 release files

0.6.0

2 release files

0.5.0

2 release files

0.4.3

2 release files

0.4.2

2 release files

0.4.1

2 release files

0.4.0

2 release files

0.3.1

2 release files

0.3.0

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page