Lumen
Security

Isolate research execution

Keep arbitrary code away from canonical state, cloud administration, and other tenants.

Outcome

An attempt can operate only inside its assigned sandbox and scoped product capabilities; it cannot reach canonical database administration, workflow administration, object administration, compute organization, or another workspace.

Prerequisites

Use the exact pinned runtime image, region, provider class, non-root user, resource limits, ownership labels, and product lease. Local Docker and managed compute must pass the same core provider contract.

Steps

  1. Persist creation intent and deterministic labels before calling the provider.
  2. Reconcile ambiguous creation by labels before retry.
  3. Materialize only the accepted workspace snapshot, declared inputs, selected context, upstream artifact handoffs, and exact installed skill bytes; verify their manifest, chmod the .lumen/context and .lumen/skills files 0400, and reject those roots in direct write/edit.
  4. Start one Pi runner with bounded local file/shell tools and one persistent Jupyter-compatible scratch-Python sidecar. Human notebook execution uses a separate document-runtime lease and sandbox.
  5. Give the attempt short-lived inference, trusted-tool, runtime, and staging capabilities for its generation.
  6. Keep inbound access private and mediate any preview with a short-lived ticket.
  7. Revoke capabilities and sweep the provider resource when the lease ends.

The worker selects exactly one attempt sandbox provider: unconfigured, local_docker, or daytona. Local Docker requires an immutable image reference plus resolved image ID, platform, isolated daemon configuration, and build identity. Daytona requires a repository-digest-pinned image, explicit target, and deployment-proven block_all egress. Inactive provider settings are rejected instead of retained as a fallback.

Verify

From the exact image and provider class, run canaries for forbidden credentials, cross-workspace paths, reserved-context mutation through direct write/edit, cloud metadata, database endpoints, and provider control APIs. All must fail while local workspace work and approved product routes succeed. Also prove that a same-UID bash mutation affects only the disposable local context copy: canonical digests remain unchanged and restart rematerializes the exact bytes. Confirm scratch Python output is not canonical until an explicit trusted promotion completes.

Recover

If isolation fails, stop new sandbox creation, revoke affected capabilities and credentials, preserve incident evidence outside hostile compute, and do not resume sensitive work until the same canary suite passes on the fixed image and class.

Next task

Enforce network and tool policy.

On this page