Managed network and memory
Run a command in an isolated Docker network with explicit egress destinations and bounded automatic memory growth.
On this page
A boundary around the process
leash sandbox run creates a private internal Docker network. The agent has no external network attachment, no Docker socket, no host home mount and no Linux capabilities. A separate broker is its only HTTP/HTTPS exit. DNS, direct IP connections and unapproved destinations cannot bypass that broker.
The allowlist uses exact public hostnames. The broker resolves and pins public addresses, rejects private or reserved destinations, and checks TLS SNI on CONNECT tunnels. An allowed service can still accept data sent to it; this is destination control, not payload inspection or a replacement for trust in the allowed service.
These controls cover only commands inside this managed runtime, not arbitrary processes on the host. Docker administrators and a compromised host remain outside the isolation guarantee.
leash sandbox run --help
leash sandbox run --allow-host registry.npmjs.org -- node -e 'console.log("Protected runtime ready")'Memory grows inside your limit
The supervisor samples container memory pressure and raises the real Docker memory limit in bounded steps, with a cooldown and a maximum configured limit. It does not grow past that maximum, shrink active memory, restart the agent after an OOM, or replay paid calls.
The Docker engine must support the required network isolation and memory controls. Unsupported engines fail with an actionable error instead of reporting protection that is not enforced.
Keep provider secrets outside the agent
With a connected hosted gateway, a secret-bearing virtual credential is mounted only into the broker. The agent receives a local LLM endpoint and a harmless placeholder; it never receives the provider key or gateway credential. The hosted gateway performs workspace admission and provider credential injection.
Explicit --gateway-url and --gateway-key-file support a public HTTPS gateway. Private files must be owned by the current user and mode 0600. Only explicitly selected project directories may be mounted; do not mount a project that contains secrets you do not want the agent to read.