II.
Sandbox overview
Reference · livesandbox:read-only-air-gapped
Read-only air-gapped sandbox overview
Maximally restrictive sandbox for review-only / dry-run workloads: workspace mounted read-only, no network, env scrubbed, no secrets.
Attributes
displayName
Read-only air-gapped sandbox
filesystemPolicy
read-only
networkPolicy
none
description
Maximally restrictive sandbox for review-only / dry-run workloads:
workspace mounted read-only, no network, env scrubbed, no secrets.
fsAllowList
- /workspace/**
fsDenyList
[]
netAllowList
[]
netDenyList
- *
execAllowedBinaries
- cat
- ls
- grep
- rg
- jq
execDeniedBinaries
- sh
- bash
- zsh
envVarScope
scrub-all-set-by-config
secretAccessScope
none
auditLogPolicy
otel-traced
policyEvaluationPoint
continuous
Outgoing edges
realizes1
- layer:9-sandbox·LayerSandbox
Incoming edges
None.