Sandboxed nodes
Run each agent session on a Linux node in its own sandbox, with your network rules enforced and API keys out of the agent's reach.
On Linux, a node can run each agent session in its own sandbox instead of as an ordinary process. The sandbox is built on NVIDIA OpenShell. Inside it:
- the agent can reach only what your policy's network rules allow;
- API keys are held outside the sandbox: the agent sees a stand-in, never the key;
- the repository is mounted at its own path, so the agent's worktrees mean the same thing inside and out;
- when the agent stops, the sandbox and everything staged for it are removed.
New
Sandboxed nodes are new. Try them on a native Linux node before you rely on them.
What the machine needs
The node checks at every start whether it can sandbox agents, and says why not in one sentence when it cannot. It needs:
- Linux. Sandboxes are not available on Windows or macOS nodes.
- Landlock at ABI 3 or later, and seccomp with user notification, in the kernel.
- Docker, running.
- OpenShell: its command-line tool and gateway installed.
Under WSL in mirrored networking mode the check fails, because that mode already holds the one seccomp listener Linux allows.
See the verdict with:
mojoup-node doctor
mojoup-node statusThe console's node page shows it too: Agents run in a sandbox, or This machine cannot sandbox agents with the reason.
Turn it on
The node runs its sandbox service when it can and is asked to. Either:
-
set the node to offer sandboxes:
Terminal mojoup-node config set node.sandbox.engine dockerand, in the setup wizard, tick the sandbox role (run agents in per-session containers); or
-
open a repository whose policy asks for sandboxes, with
agents.sandboxset topreferredorrequired.
| Policy value | What happens |
|---|---|
preferred | An agent runs in a sandbox when the node can provide one, and as an ordinary process when it cannot. |
required | An agent runs only in a sandbox. Where the node cannot provide one, the agent does not start, and says why. |
The policy comes from the repository's .mojoup/policy.json, or from your organisation or team hub. See Policies.
What you see
mojoup-node status lists the sessions running in a sandbox. In the console, an administrator can assign who may run agents in a node's sandboxes (Sandboxes, "Run agents in its sandboxes") under Who may use it.
Subscription sign-ins in a sandbox
If an agent tool uses a subscription sign-in (Claude Code, Copilot CLI, Codex, OpenCode or Kilo Code), its sign-in files are copied into the sandbox for that session only and removed with it. The network rule that lets the tool reach its own service is still subject to your policy.
Related settings
| Setting | What it does |
|---|---|
node.sandbox.engine | off (default), docker or podman: the engine the node offers sandboxes on. |
node.sandbox.maxConcurrent | The most sandboxes at once that the node offers (0 means not stated). |
node.sandbox.egress | policy (network through the node's policy, the default) or none. |
node.sandbox.images | The sandbox images the node offers. |