Skip to main content
By default the tools run in a git worktree on the worker. Set SANDBOX to a sandbox module’s index.ts to run them in a sandbox instead:
The workspace is a resource, so later turns and subagents reopen the same sandbox. Each execution works on its own branch, rebuno/<execution id>. The GitHub token never enters the sandbox: the provider adds it to the sandbox’s requests to github.com. Sandboxes stop or pause when a turn ends or waits for approval. Modal sandboxes cannot pause and run until their one-hour timeout.

Checkpoints

Checkpoints are off by default. CHECKPOINT_STEPS=5 checkpoints the workspace after every fifth tool call that may change it, and a fork starts from the newest checkpoint before its fork point. Without checkpoints, a fork starts from a fresh clone.

On the worker

Without SANDBOX, each workspace is a git worktree under WORKSPACE_DIR. A checkpoint commits the worktree, uncommitted files included, to a ref of its own. Commands run beside the agent’s process and can reach its credentials. Use a sandbox for repositories you do not trust.

Write a sandbox module

A module exports workdir, where the checkout appears to pi, and a function that returns the workspace’s resource driver:
A Workspace reads files, writes files, and runs commands. The token is valid for an hour, so open applies the current one; never put it in the binding. workdir must be readable on the worker, outside /root, since pi’s edit and write tools resolve paths there. Node runs index.ts by stripping its types, so use only erasable TypeScript: no enums, namespaces, or parameter properties.