Changelog
All notable changes, one line each, newest first. Format follows Keep a Changelog; versions follow VERSION. Add entries under Unreleased; the release process turns that heading into the version being cut, and the release workflow publishes that section as the release notes.
[Unreleased]#
Changed#
- The project moved to https://github.com/runoverlabs/sandbox-manager and its documentation to https://sandbox-manager.runoverlabs.dev/; old GitHub links and existing installs keep working through GitHub's redirects, but the old github.io docs address does not.
[0.2.0] - 2026-10-07#
Added#
- Documentation site at https://naerymdan.github.io/sandbox-manager/: install, getting started, guides, command and configuration reference, with search and light/dark themes; agents can read it through
llms.txt,llms-full.txtor the Markdown copy beside each page. - Sandboxes get
EDITOR=nano(and nano itself), so Claude Code's/memory,git commitand friends open an editor instead of silently doing nothing; override it under[env]. Existing sandboxes need a rebuild. - Inside a project folder msbctl knows which sandbox you mean: leave the name out where it is the only argument (
msbctl shell,msbctl stop), use.where more follows (msbctl exec . make,msbctl allow . example.com), ormsbctl exec -- cmd;shellandexecstart in the matching subfolder of/work. msbctl rename <name> <new>andmsbctl move <name> <dir>(alsoedit→ Name & folder) rename a sandbox or point it at another project folder; a rename recreates the VM and keeps settings, secrets, Claude state, caches and container images, a move needs a rebuild.- A git identity can name an ssh key to sign commits with (
setup→ Git identities); sandboxes using it sign through the filtered agent (and can verify their own signatures) while the key stays ticked inmsbctl keys, which flags it and warns before you drop it. Existing sandboxes need a rebuild foropenssh-clientifssh-keygenis missing.
[0.1.1] - 2026-10-06#
First release. msb-manager runs coding agents against real repositories in microsandbox microVMs, without giving them your network or your tokens.
Isolation#
- Deny-by-default egress, per host and per port. Named rule groups (
github,npm,python,go,claude,bun, …) compose per project, and plain HTTP is refused outright. - Tokens never enter the VM.
--secretbindings put an opaque placeholder in the guest and substitute the real value host-side, into request headers only, for the hosts you name.GH_TOKENand Claude's own credential work this way, andmsbctl secretadds more. - A filtered SSH agent per sandbox, forwarded over vsock: only identity-list and sign requests, limited to the keys you pick (
msbctl keys). The private key never crosses. - A central
CLAUDE.md(shipped text plus your own additions) copied into every sandbox on each start from a read-only mount; each sandbox gets its own~/.claude.
Managing sandboxes#
- One CLI and an fzf picker (with a desktop entry) to register, start, stop, rebuild, purge, resize, shell into and run commands in sandboxes:
msbctl add,start,stop,rebuild,purge,shell,exec,resize,reclaim,ls,status,show. - A setup wizard that asks for features (bun, python, podman, gitleaks, …) rather than raw rule groups, preselects them from your repo's languages, and sizes the disks and package caches;
msbctl editandmsbctl setuprevisit any section later, and a first-run walk-through covers a new machine. - Per-project config that travels with the repo (
.msb/sandbox.toml, egress groups, packages, limits), with machine-local paths and tokens kept in~/.config/msb/and never committed.msbctl configshows the merged result and where each value came from. - Extra folders, package-cache disks and secrets added after the fact (
msbctl mount,cache,secret), andmsbctl allowfor one more egress rule. - Egress observe mode (
msbctl observe <name> on): when an allowlist is too tight to work in, stop blocking, record every host reached, then read it back with the exactmsbctl allowlines for the hosts no rule covers. It leaves that sandbox's egress unrestricted until you switch it off. - Secret placeholders pass through to agent hosts, so a coding agent that has read
$MSB_GH_TOKENno longer breaks its own API calls. - In-place updates of claude, gh, gitleaks, bun and apt (
msbctl update), with the versions recorded so a rebuild reproduces them, and a version display in the picker.
Install and supply chain#
curl | shinstaller (get.sh) andmsbctl self-update, with sha256 verification of the release tarball.- Signed build-provenance attestations on every release tarball and
get.sh, verified byget.shandself-updatewhen an authenticatedghis installed (MSB_MANAGER_SKIP_ATTEST=1skips it; otherwise only the checksum is checked). See the README's "Verifying a release". - Verified toolchain installs inside the guest: bun and gh are pinned release assets checked against their published checksums, and node comes from NodeSource's apt repository with a pinned signing-key fingerprint, instead of
curl | bash. - CI, CodeQL, zizmor and OpenSSF Scorecard, a tag-driven release workflow, Dependabot, issue forms, a security policy and a contributing guide.
Upgrading from a checkout#
- Rule groups changed: the Claude hosts now come only from the
claudegroup,bunallowsgithub.cominstead ofbun.sh, andgithuballows the Actions log host, Sigstore's trust root and GitHub's attestation storage (sogh attestation verifyworks from a sandbox). Existing sandboxes pick these up, along with the secret pass-through and the new installers, at their nextmsbctl rebuild.