sand-boxer/docs/integrations/glas-harness.md
tegwick cf490220f4
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Add local reachability descriptor for same-host extensions (SAND-WP-0013-T04)
Reachability gains pid/workspace_dir, populated by enrich_reachability
whenever a backend's wait_ready() returns a pid: endpoint (currently
just ext.bwrap). build_reachability_report() now also returns a
local_exec_hint (nsenter into the pid's namespaces) alongside the
existing ssh_one_liner, so glas-harness can branch on which is
populated instead of assuming every sandbox is SSH-reachable.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-26 12:58:32 +02:00

2.3 KiB

glas-harness integration

glas-harness owns the agent gateway, tools, memory, and channels. sand-boxer delivers an isolated execution environment; the harness executes tools inside it.

Example request

sandboxer create \
  --profile profile.agent-dev \
  --input repo=/path/to/workspace \
  --actor agt \
  --project glas-harness

Response fields (ready state)

Field Owner Description
sandbox_id sand-boxer Stable instance identifier
reachability.ssh sand-boxer SSH target for harness exec channel
reachability.remote_dir sand-boxer Workspace root on remote host
state sand-boxer Lifecycle state (ready, etc.)

Two reachability modes

Not every sandbox has an SSH hop. ext.compose-ssh / ext.vm-packer always run remote and populate reachability.ssh + reachability. remote_dir; glas-harness execs tools over that SSH channel. ext.bwrap (SAND-WP-0013) runs same-host and never populates reachability.ssh — instead it populates reachability.pid (the placeholder process holding the bwrap namespaces) and reachability.workspace_dir. glas-harness execs tools by entering that pid's namespaces directly (nsenter --target <pid> --mount --pid --net --uts --ipc -- <cmd>, no tunnel needed) rather than opening an SSH channel. reachability/enrich. build_reachability_report() returns both an ssh_one_liner and a local_exec_hint; exactly one is non-null depending on which mode the resolved extension uses. Consumers should branch on which field is populated, not on profile id, since routing can fall back between extensions.

Ownership

Concern Owner
Sandbox provision / teardown sand-boxer
Tool call parsing and policies glas-harness
SSH / tunnel reachability setup glas-harness + ops-bridge
Agent memory and session state glas-harness

Smoke test

# Requires sandboxer CLI and SANDBOXER_HOST (or profile placement fallback)
SANDBOXER_HOST=coulombcore ./scripts/smoke-agent-dev.sh

Creates profile.agent-dev, prints reachability (tunnel metadata + SSH one-liner), then destroys.

Out of scope for sand-boxer

  • Tool schemas and approval flows
  • Channel bridges (Slack, email, etc.)
  • Subagent orchestration