Skip to content
Merged
Show file tree
Hide file tree
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 3 additions & 3 deletions docs/get-started/tutorials/first-network-policy.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -38,10 +38,10 @@ bash examples/sandbox-policy-quickstart/demo.sh
Start by creating a sandbox with no network policies. This gives you a clean environment to observe default-deny behavior.

```shell
openshell sandbox create --name demo --keep --no-auto-providers
openshell sandbox create --name demo --no-auto-providers
```

`--keep` keeps the sandbox running after you exit so you can reconnect later. `--no-auto-providers` skips the provider setup prompt since this tutorial uses `curl` instead of an AI agent.
`--no-auto-providers` skips the provider setup prompt since this tutorial uses `curl` instead of an AI agent.

You land in an interactive shell inside the sandbox:

Expand All @@ -65,7 +65,7 @@ The request fails. By default, all outbound network traffic is denied. The sandb
curl: (56) Received HTTP code 403 from proxy after CONNECT
```

Exit the sandbox. The `--keep` flag keeps it running:
Exit the sandbox. Sandboxes are kept running by default, so you can reconnect later. Use `--no-keep` at creation time if you want the sandbox deleted after exit:

```shell
exit
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -160,7 +160,6 @@ Launch a sandbox with the Microsoft Graph provider attached:
```shell
openshell sandbox create \
--name microsoft-graph-mail \
--keep \
--provider microsoft-mail \
--no-auto-providers \
-- /bin/sh
Expand Down
6 changes: 2 additions & 4 deletions examples/policy-advisor/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -90,14 +90,12 @@ openshell sandbox create \
--name advisor-ctf \
--policy examples/policy-advisor/sandbox-policy.yaml \
--upload examples/policy-advisor/ctf.py \
--keep \
-- python3 -u /sandbox/ctf.py
```

> **For agents running this CTF:** use the command above exactly. The
> `--upload` flag copies the script into `/sandbox/` before the command runs,
> `--keep` prevents the sandbox from being torn down on exit, and `-u` gives
> unbuffered output so you can see logs in real time.
> `--upload` flag copies the script into `/sandbox/` before the command runs
> and `-u` gives unbuffered output so you can see logs in real time.

The script prints a banner and immediately tries Gate 1 (`httpbin.org:443`).
It will fail with **"blocked by sandbox proxy"** and begin retrying every 10
Expand Down
7 changes: 3 additions & 4 deletions examples/sandbox-policy-quickstart/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -22,11 +22,10 @@ while writes are blocked — all without restarting anything.
### 1. Create a sandbox

```bash
openshell sandbox create --name demo --keep --no-auto-providers
openshell sandbox create --name demo --no-auto-providers
```

`--keep` keeps the sandbox running after you exit so you can reconnect
later. `--no-auto-providers` skips the provider setup prompt since this
`--no-auto-providers` skips the provider setup prompt since this
demo doesn't use an AI agent.

You'll land in an interactive shell inside the sandbox:
Expand All @@ -50,7 +49,7 @@ The sandbox proxy intercepted the HTTPS CONNECT request to
curl: (56) Received HTTP code 403 from proxy after CONNECT
```

Exit the sandbox (the sandbox stays alive thanks to `--keep`):
Exit the sandbox (sandboxes are kept running by default; pass `--no-keep` at creation time to delete on exit):

```bash
exit
Expand Down
1 change: 0 additions & 1 deletion examples/spiffe-token-grant-demo/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -74,7 +74,6 @@ openshell --gateway-endpoint "$GATEWAY" provider create \
openshell --gateway-endpoint "$GATEWAY" sandbox create \
--name spiffe-token-demo \
--provider spiffe-token-demo \
--keep \
--no-tty \
-- echo "sandbox ready"

Expand Down
2 changes: 0 additions & 2 deletions scripts/agents/gator/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -42,8 +42,6 @@ The launcher:
- For `--harness codex`, optionally bakes a host Codex executable as `/etc/openshell/agent-payload/runtime/harnesses/codex/codex`.
- Starts the selected harness without a TTY.
- Runs gator in `watch` mode by default. The sandbox stays alive while the supervisor sleeps between bounded Codex cycles, so Codex is not connected during passive PR waits. The supervisor prints periodic heartbeat lines during active cycles and passive sleeps.
- Deletes the sandbox automatically after the supervisor exits. Pass `--keep` to preserve it for debugging.

The GitHub provider profile allows read-only GraphQL queries on `api.github.com/graphql` so `gh` read paths can use GraphQL when needed. Write operations remain REST-only and scoped to the two allowed repositories.

Set `GATOR_CODEX_ACCESS_CREDENTIAL_KEY` or pass `--codex-access-key` if the gator Codex profile uses a credential key other than `CODEX_AUTH_ACCESS_TOKEN` for the short-lived access token.
Expand Down
Loading