Documentation
¶
Overview ¶
Package main is the entrypoint for the workflow-sandbox-runner agent.
The agent serves the SandboxExecService gRPC interface over mTLS + bearer-token auth. It resolves secret:// references in env values server-side before launching commands, and clamps requested security profiles to a safe maximum (permissive → standard).
Design: docs/decisions/0019-remote-sandbox-agent.md (ADR 0019)
Click to show internal directories.
Click to hide internal directories.