Skip to content

Graphorin API reference v0.15.1


Graphorin API reference / @graphorin/security / / DockerSandboxOptions

Interface: DockerSandboxOptions

Defined in: packages/security/src/sandbox/docker.ts:105

Stable

Options for createDockerSandbox(...).

Properties

PropertyModifierTypeDescriptionDefined in
cpus?readonlynumberCPU allowance in CPUs (NanoCpus), fractional allowed. Bounds busy-loop burn. Defaults to 1; clamped to [0.1, 8].packages/security/src/sandbox/docker.ts:139
defaultTimeoutMs?readonlynumberDefault wall-clock timeout (ms). Defaults to 30000.packages/security/src/sandbox/docker.ts:117
image?readonlystringContainer image. Defaults to a no-op stub the operator must override; the framework deliberately does not ship an image.packages/security/src/sandbox/docker.ts:110
memoryLimitMb?readonlynumberMemory limit (MB). Defaults to 512.packages/security/src/sandbox/docker.ts:119
peerLoader?readonly() => Promise<DockerodeModule>Override the peer-dep loader. Tests inject a stub here.packages/security/src/sandbox/docker.ts:143
pidsLimit?readonlynumberPID ceiling for the container (PidsLimit) - bounds fork/spawn storms that would otherwise run until the timeout. Defaults to 128; clamped to [16, 4096].packages/security/src/sandbox/docker.ts:134
socketPath?readonlystringHostname for the Docker daemon socket. Forwarded to new Dockerode({ socketPath }). Defaults to the platform default.packages/security/src/sandbox/docker.ts:115
user?readonlystringContainer user as "uid:gid" (the create request's User). Defaults to '10001:10001' so sandboxed code never runs as the image's default user - which is root in most base images (deep-retest 0.13.12 P2). Numeric ids need no passwd entry. Pass '' to keep the image default (NOT recommended; document why in your deployment notes if you do).packages/security/src/sandbox/docker.ts:128