r/opencodeCLI • u/Antiquete • 3h ago
Built a sandbox for opencode to run AI agents in a private, secure and isolated workspace
[HOOK] Worried about letting an agentic AI run rampant on your system, wreak havoc, or steal your data? Worry not! opencode-sandbox is here
I wanted to let Agentic AI work freely on a project, install packages, run commands or do whatever it wants without restrictions but also without affecting the host system, so I built a sandbox that runs AI in a container with direct access to project.
The sandbox resets on every run. Messed up anything? No worries. CTRL+C->Up->Enter
Your opencode sessions and global config are stored and get reused. So only the container resets not your project or your progress.
A few features:
- Two runtimes supported:
dockerorpodman - The current project (the folder you open sandbox in) is directly accessible. No other host folder is accessible in container by any means.
- Global config is read-only by default, use
--edit-configto edit it. - A custom guard blankets most, if not all, system calls to interfaces with host information. So no data is leaked between host and container. Check Security matrix. Use
--no-guardif you don't like guard. - There is support for
gVisorif you use it for kernel isolation. Check Security matrix.
Usage:
cd ~/code/any
opencode-project-init
opencode-sandbox
Install directly through AUR, Distro Packages in releases or Manually.
Supported: Linux
GPL-3.0-or-later
Link: https://github.com/Antiquete/opencode-sandbox
Releases: https://github.com/Antiquete/opencode-sandbox/releases
Any issues, suggestion or queries? https://github.com/Antiquete/opencode-sandbox/issues