From 322f21ef9f13609ddc2727b1c274d5b4f56d727c Mon Sep 17 00:00:00 2001 From: Codeman maintainer Date: Thu, 6 Aug 2026 08:46:22 +0200 Subject: [PATCH] docs(extending): scope the "no sandbox" claim, point at Docker cases The bullet read as a blanket "Codeman has no sandbox", which is wrong and undersells a headline feature. Two different axes were conflated: - Integration code cannot be sandboxed by Codeman because Codeman never launches it. It is the reader's own process, started by them. - Agent workloads are sandboxed per case via Docker cases, which is the documented isolation story. Scopes the claim to integration code and links docs/docker-cases.md, noting that an integration driving a Docker-backed session inherits that isolation because it is a property of the session, not the caller. Co-Authored-By: Claude Opus 5 (1M context) --- docs/extending-codeman.md | 13 +++++++++++-- 1 file changed, 11 insertions(+), 2 deletions(-) diff --git a/docs/extending-codeman.md b/docs/extending-codeman.md index 9e2b3dee..5d9de299 100644 --- a/docs/extending-codeman.md +++ b/docs/extending-codeman.md @@ -242,5 +242,14 @@ require nothing of you but HTTP. - **No in-process plugin runtime.** See the reasoning at the top of this page. - **No build or startup hooks** for third-party code. Run your own process. - **No per-plugin config or state directories.** Manage your own files. -- **No sandbox**, because there is nothing to sandbox. Your integration is your - process, with your permissions, talking HTTP. +- **No sandbox for integration code**, because Codeman never launches it. Your + integration is your own process, started by you, with your permissions, + talking HTTP. + +That last point is about integration code specifically, not about Codeman. +Sandboxing lives on a different axis here: the thing worth isolating is the +**agent**, and you isolate it per case with +[Docker cases](docker-cases.md), which run the agent in a hardened container with +a bind-mounted workspace and seeded (not shared) credentials. An integration that +creates or drives a Docker-backed session inherits that isolation for free, since +it is a property of the session rather than of the caller.