sbx

command module
v0.16.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 30, 2026 License: MIT Imports: 3 Imported by: 0

README

sbx

CI Go Reference Go Report Card release dependencies license

Self-hosted sandboxes for AI agents. sbx gives every agent, test run or branch its own sandbox on your machine or cluster: a fresh Firecracker microVM with its own kernel, or a container. Idle sandboxes sleep at 0 B of RAM and wake the moment anything connects.

Agents drive it through the OpenSandbox API, an open standard with SDKs in five languages, or as tools over MCP. Anything else only has to connect: point psql, Playwright or a test runner at a sleeping sandbox and sbx holds the connection while it wakes, then hands it over.

  • A microVM per sandbox on Linux with KVM, or a container anywhere Docker runs
  • Written in Go with only the standard library: one static binary, zero dependencies
  • No account and nothing hosted: MIT licensed, on your own hardware

Not to be confused with Docker's own sbx CLI (docker/tap/sbx).

Install

brew install aryanmehrotra/tap/sbx

Or curl -fsSL https://raw.githubusercontent.com/aryanmehrotra/sbx/main/scripts/install.sh | sh, or go install github.com/aryanmehrotra/sbx@latest. It needs Docker or a Kubernetes cluster, and Linux with /dev/kvm for microVMs. Run sbx doctor to see what your machine supports, and sbx install to add what it reports missing (it shows every command and asks first).

Sandboxes for AI agents

# The daemon, serving the OpenSandbox API with four sandboxes started ahead of time
sbx serve --osb-addr 127.0.0.1:8080 --osb-pool python:3.11-slim=4 &
export OPEN_SANDBOX_DOMAIN=127.0.0.1:8080 OPEN_SANDBOX_API_KEY="$(cat ~/.sbx/osb/key)"
pip install opensandbox
from opensandbox import SandboxSync

sandbox = SandboxSync.create("python:3.11-slim")
print(sandbox.commands.run("python -c 'print(6 * 7)'").logs.stdout[0].text)  # 42
sandbox.destroy()

Add --provider firecracker to sbx serve and every sandbox is a microVM with its own kernel, booted fresh from the image. To give Claude Code sandboxes as tools, run claude mcp add sbx -- sbx mcp while the daemon runs. Cursor and Codex are in GUIDES.md.

Databases for branches and tests

sbx serve --idle 5m &                               # once per machine
sbx create my-branch --template postgres            # a Postgres for this branch
eval "$(sbx env my-branch)"
PGPASSWORD=app psql -U app -d app                   # connecting wakes it

sbx snapshot my-branch seeded && sbx fork seeded agent-1         # seed once, copy per agent
sbx with test-db --template postgres -- go test ./...            # removed even if tests fail

Templates: postgres, browser, nginx, web-stack (Postgres and Redis) and analytics. For your own stack, write a sandbox.json (SPEC.md).

Documentation

Contributing

Issues and pull requests are welcome. See CONTRIBUTING.md; coding agents should read AGENTS.md.

License

MIT

Documentation

Overview

Command sbx gives every branch, task or agent its own copy of a project's backing services, and charges nothing for the ones nobody is using. The program lives in internal/app; this root file is only the entry point and the one thing that has to be here.

Directories

Path Synopsis
internal
agentbin
Package agentbin finds a linux sbx binary to run inside a sandbox as its agent.
Package agentbin finds a linux sbx binary to run inside a sandbox as its agent.
app
sbx gives every branch, task or agent its own copy of a project's backing services, and charges nothing for the ones nobody is using.
sbx gives every branch, task or agent its own copy of a project's backing services, and charges nothing for the ones nobody is using.
cli
devcontainer
Package devcontainer reads a devcontainer.json and turns it into a service sbx can run.
Package devcontainer reads a devcontainer.json and turns it into a service sbx can run.
execd
Package execd is the daemon that runs inside a sandbox created through the OpenSandbox API.
Package execd is the daemon that runs inside a sandbox created through the OpenSandbox API.
execdctl
Package execdctl is the host's side of execd's control endpoints: seal before a snapshot, re-key after a restore.
Package execdctl is the host's side of execd's control endpoints: seal before a snapshot, re-key after a restore.
fc
Package fc drives Firecracker: its REST API over a unix socket, the firecracker process that serves it, the pinned binary and guest kernel, and the root filesystem a VM boots from.
Package fc drives Firecracker: its REST API over a unix socket, the firecracker process that serves it, the pinned binary and guest kernel, and the root filesystem a VM boots from.
fc/fcfake
Package fcfake is a Firecracker API server that keeps state and never boots anything.
Package fcfake is a Firecracker API server that keeps state and never boots anything.
fc/guestinit
Package guestinit is PID 1 inside a Firecracker VM: `sbx fc-init`.
Package guestinit is PID 1 inside a Firecracker VM: `sbx fc-init`.
fc/hostcap
Package hostcap answers one question before anything microVM-shaped is attempted: on this machine, which way - if any - can a Firecracker VM be run?
Package hostcap answers one question before anything microVM-shaped is attempted: on this machine, which way - if any - can a Firecracker VM be run?
fchost
Package fchost decides where a Firecracker microVM can run from the machine sbx is on, and when that is not this machine, runs one that can.
Package fchost decides where a Firecracker microVM can run from the machine sbx is on, and when that is not this machine, runs one that can.
fcvsock
Package fcvsock dials a port inside a Firecracker microVM from the host.
Package fcvsock dials a port inside a Firecracker microVM from the host.
features
Package features is the gate in front of anything not yet proven.
Package features is the gate in front of anything not yet proven.
history
Package history is the answer to "what happened to this sandbox, and who did it".
Package history is the answer to "what happened to this sandbox, and who did it".
hostinfo
Package hostinfo reports what the machine a person is sitting at has.
Package hostinfo reports what the machine a person is sitting at has.
jupyter
Package jupyter is the code-interpreter engine behind execd's /code routes: it runs code in Jupyter kernels through a Jupyter Server that the sandbox image provides, and turns what the kernel says into execd's server-sent events.
Package jupyter is the code-interpreter engine behind execd's /code routes: it runs code in Jupyter kernels through a Jupyter Server that the sandbox image provides, and turns what the kernel says into execd's server-sent events.
mcp
Package mcp is a Model Context Protocol server over stdio: JSON-RPC 2.0, one message per line, requests in on stdin and answers out on stdout.
Package mcp is a Model Context Protocol server over stdio: JSON-RPC 2.0, one message per line, requests in on stdin and answers out on stdout.
osb
Package osb serves OpenSandbox's lifecycle API from inside `sbx serve`.
Package osb serves OpenSandbox's lifecycle API from inside `sbx serve`.
osbclient
Package osbclient speaks the OpenSandbox HTTP contract: the lifecycle API (`/v1/sandboxes`) and execd, the per-sandbox agent that runs commands and touches files.
Package osbclient speaks the OpenSandbox HTTP contract: the lifecycle API (`/v1/sandboxes`) and execd, the per-sandbox agent that runs commands and touches files.
osbclient/osbtest
Package osbtest is a fake OpenSandbox server - lifecycle API and execd - for tests of anything that speaks the contract.
Package osbtest is a fake OpenSandbox server - lifecycle API and execd - for tests of anything that speaks the contract.
procid
Package procid identifies a process across pid reuse.
Package procid identifies a process across pid reuse.
selfstat
Package selfstat reads the resource usage of the container this process is in, from its own cgroup - no container runtime and no socket required.
Package selfstat reads the resource usage of the container this process is in, from its own cgroup - no container runtime and no socket required.
snapshotpause
Package snapshotpause marks a container as paused by `sbx snapshot`, so the daemon can tell that pause from a freeze.
Package snapshotpause marks a container as paused by `sbx snapshot`, so the daemon can tell that pause from a freeze.
tui
ui
update
Package update answers "is there a newer sbx" without ever making anybody wait for it.
Package update answers "is there a newer sbx" without ever making anybody wait for it.
wsclient
Package wsclient is the client half of RFC 6455, standard library only.
Package wsclient is the client half of RFC 6455, standard library only.
wsclient/wstest
Package wstest is a deliberately literal WebSocket server for tests of clients.
Package wstest is a deliberately literal WebSocket server for tests of clients.
wsserver
Package wsserver is the server half of RFC 6455, standard library only.
Package wsserver is the server half of RFC 6455, standard library only.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL