Isolate research execution
Keep arbitrary code away from canonical state, cloud administration, and other tenants.
Outcome
An attempt can operate only inside its assigned sandbox and scoped product capabilities; it cannot reach canonical database administration, workflow administration, object administration, compute organization, or another workspace.
Prerequisites
Use the exact pinned runtime image, region, provider class, non-root user, resource limits, ownership labels, and product lease. Local Docker and managed compute must pass the same core provider contract.
Steps
- Persist creation intent and deterministic labels before calling the provider.
- Reconcile ambiguous creation by labels before retry.
- Materialize only the accepted workspace snapshot, declared inputs, selected context, upstream
artifact handoffs, and exact installed skill bytes; verify their manifest, chmod the
.lumen/contextand.lumen/skillsfiles0400, and reject those roots in directwrite/edit. - Start one Pi runner with bounded local file/shell tools and one persistent Jupyter-compatible scratch-Python sidecar. Human notebook execution uses a separate document-runtime lease and sandbox.
- Give the attempt short-lived inference, trusted-tool, runtime, and staging capabilities for its generation.
- Keep inbound access private and mediate any preview with a short-lived ticket.
- Revoke capabilities and sweep the provider resource when the lease ends.
The worker selects exactly one attempt sandbox provider: unconfigured, local_docker, or daytona.
Local Docker requires an immutable image reference plus resolved image ID, platform, isolated daemon
configuration, and build identity. Daytona requires a repository-digest-pinned image, explicit target,
and deployment-proven block_all egress. Inactive provider settings are rejected instead of retained
as a fallback.
Verify
From the exact image and provider class, run canaries for forbidden credentials, cross-workspace paths,
reserved-context mutation through direct write/edit, cloud metadata, database endpoints, and
provider control APIs. All must fail while local workspace work and approved product routes succeed.
Also prove that a same-UID bash mutation affects only the disposable local context copy: canonical
digests remain unchanged and restart rematerializes the exact bytes. Confirm scratch Python output is
not canonical until an explicit trusted promotion completes.
Recover
If isolation fails, stop new sandbox creation, revoke affected capabilities and credentials, preserve incident evidence outside hostile compute, and do not resume sensitive work until the same canary suite passes on the fixed image and class.