Register the workspace
The handler registers a sandbox with a checkpoint policy:DaytonaResource
implements three operations:
create(checkpoint_ref=None)creates a sandbox from the selected snapshot or a fresh checkout, and configures its Git branch.open(binding)gets the sandbox ID recorded for this execution and starts the sandbox if it is stopped.checkpoint(handle)creates a named Daytona snapshot of the sandbox.
rebuno-<id> and stay in the Daytona organization until
deleted.
Each new sandbox gets a unique Git branch, and shell commands push the current
branch. Reopening a workspace preserves its branch.
Daytona stops idle sandboxes and keeps their files, and open starts them
again. Missing sandboxes or selected snapshots fail the execution.
Wrap the tools
shell and write_file declare workspace changes. read_file uses the default
of none:
shell to commit and push the branch. These tools use
safe_to_retry, so an interrupted command can run again. See
idempotency when adding commands with effects
that must not repeat.
Keep credentials out of the sandbox
Cloning and pushing need a GitHub token. The driver stores it as a Daytona secret limited togithub.com
and mounts the secret into each sandbox as GITHUB_AUTH:
GITHUB_AUTH holds a placeholder. Daytona replaces it with
the secret’s value on requests to github.com, so git works as usual and
nothing in the sandbox can read the token. The driver updates the secret when
creating or opening a sandbox, so resumed workspaces use the token the worker
currently holds.
Opening the pull request is a separate tool that calls GitHub’s API from the
agent:
github.com, so the sandbox can push a branch but cannot
use that token to call the API. Protect the default branch with a GitHub ruleset
that requires a pull request.
Stop while waiting
The handler stops the workspace when the model loop finishes or waits for approval:pause() stops the sandbox. Files persist and running processes end. The check
reads execution().suspension because a framework can catch Blocked inside
its loop. After approval, the next dispatch replays up to the held call and the
driver starts the same sandbox. A completion checkpoint briefly starts a stopped
sandbox and stops it again after capture.
Sessions
The handler reads the previous completed turn withprevious() and returns its
conversation in Result.state:
Fork the workspace
Write the policy
Run it
examples/integrations/sandbox/daytona
has the full agent, resource driver, policy, and dev kernel config.
Set DAYTONA_API_KEY, REPO (the repository as owner/name), GITHUB_TOKEN,
LLM_MODEL, LLM_BASE_URL, and LLM_API_KEY. The token needs read and write
access to the repository’s contents and pull requests. Start the kernel and
agent from that directory:
open_pr call appears in rebuno exec watch. See
Approvals to approve it. Continue the same session with:
lease_timeout_seconds sets a shorter lease for the agent.