03 ยท Close the bypass

Single-agent process sandbox

Runs one command with unprivileged process and filesystem restrictions.

Free single-agent-sandbox
Document source v3.5.0 release Manifest commit ca05ed06 Open manifest

Operator surface

Run the command

The release manifest records this command as the capability's operator entry point. Open the pinned source pointer to inspect the declaration and surrounding validation.

Command pipelock sandbox Read SandboxCmd

Availability

Included tiers

Community Pro Enterprise
Deployment boundary

Kernel isolation requires Linux user namespaces. Without them, best-effort network isolation only sets HTTP(S)_PROXY; seccomp adds restrictions only on linux/amd64.

Source records

Open the pinned source

The release manifest names these source pointers. The publication gate confirms their Go files and declarations exist at the same Pipelock commit as this page; the linked code provides the runtime context.

Read next

Guides and references