03 ยท Close the bypass
Single-agent process sandbox
Runs one command with unprivileged process and filesystem restrictions.
Operator surface
Run the command
The release manifest records this command as the capability's operator entry point. Open the pinned source pointer to inspect the declaration and surrounding validation.
Availability
Included tiers
Community
Pro
Enterprise
Deployment boundary
Kernel isolation requires Linux user namespaces. Without them, best-effort network isolation only sets HTTP(S)_PROXY; seccomp adds restrictions only on linux/amd64.
Source records
Open the pinned source
The release manifest names these source pointers. The publication gate confirms their Go files and declarations exist at the same Pipelock commit as this page; the linked code provides the runtime context.
Read next