Operations
Use the operational runbook for host setup, runtime installation, isolation prerequisites, and the smoke test:
Runtime selection
Sandbox Loom tries youki first and falls back to runc when Youki is unavailable. An explicitly required runtime does not silently fall back.
Before enabling isolation
- Confirm the workspace path is explicit.
- Confirm resource limits and network mode.
- Confirm no host credential or Docker socket is mounted.
- Confirm the systemd/DBus prerequisites for the intended runtime.
- Run the direct OCI lifecycle smoke test.
Retain audit events and acceptance evidence before destroying expired or failed sandboxes.
Operational readiness is more than starting the runtime. Before enabling a workflow, confirm its authority profile, workspace and network scope, resource limits, credential path, expiry behavior, recovery procedure, and evidence retention. After a failure, preserve the decision and result trail before cleanup so the run can be reviewed without replaying an external side effect.