Skip to content

feat(docker): add isolated_paths for per-repo container-only dirs like node_modules - #46

Merged
radim10 merged 2 commits into
masterfrom
feat/docker-isolated-paths
Sep 26, 2026
Merged

radim10 merged 2 commits into
masterfrom
feat/docker-isolated-paths

Conversation

@radim10

@radim10 radim10 commented Sep 26, 2026 •

Copy link
Copy Markdown
Member

Overview

On macOS/Windows hosts the Docker sandbox shares the host's node_modules, which only has host-platform native binaries (Nx, esbuild, swc, …), so they fail in the Linux container. An npm ci/bun install inside the sandbox also overwrites the host's install.

This adds an opt-in isolated_paths setting that mounts a per-repo Docker volume over each listed directory, so the container gets its own copy and the host's is never touched:

[sandbox]
backend = "docker"
isolated_paths = ["node_modules"]

Or per run: --docker-isolated-paths node_modules,.venv.

Changes

Notes

  • Policy fingerprints change once for all profiles (audit logs only, same as when memory/cpus were added)
  • Tested end to end on macOS, including a real Nx + Bun monorepo; not tested on Linux/Windows hosts

@radim10 radim10 changed the title feat: add nano text editor to agent-sandbox image for improved editing capabilities feat(docker): add isolated_paths for per-repo container-only dirs like node_modules Sep 26, 2026
@radim10 radim10 self-assigned this Sep 26, 2026
@radim10
radim10 merged commit d0310d7 into master Sep 26, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant