Skip to content

Operations

Use the operational runbook for host setup, runtime installation, isolation prerequisites, and the smoke test:

Runtime selection

Sandbox Loom tries youki first and falls back to runc when Youki is unavailable. An explicitly required runtime does not silently fall back.

Before enabling isolation

  1. Confirm the workspace path is explicit.
  2. Confirm resource limits and network mode.
  3. Confirm no host credential or Docker socket is mounted.
  4. Confirm the systemd/DBus prerequisites for the intended runtime.
  5. Run the direct OCI lifecycle smoke test.

Retain audit events and acceptance evidence before destroying expired or failed sandboxes.

Operational readiness is more than starting the runtime. Before enabling a workflow, confirm its authority profile, workspace and network scope, resource limits, credential path, expiry behavior, recovery procedure, and evidence retention. After a failure, preserve the decision and result trail before cleanup so the run can be reviewed without replaying an external side effect.