Skip to content

feat: let agents ask for software, which their pod keeps for its sandbox - #304

Draft
tjholm wants to merge 1 commit into
sandbox-desktopfrom
sandbox-software
Draft

tjholm wants to merge 1 commit into
sandbox-desktopfrom
sandbox-software

Conversation

@tjholm

@tjholm tjholm commented Oct 6, 2026

Copy link
Copy Markdown
Member

request_software asks for a package from nixpkgs, stable or unstable, and the turn waits for whoever manages the pod's sandbox to allow it. Allowed, it is installed into the pod's shared Nix profile, on every command's PATH, and recorded at the nixpkgs commit it came from; each turn's first use of the sandbox gives it exactly the pod's recorded packages, so a new or upgraded sandbox gets them back. The pod's settings list its software, which its admins can remove.


Stack created with GitHub Stacks CLI • Give Feedback 💬

@tjholm
tjholm added this pull request to stack #305 October 6, 2026 03:35
@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Updated (UTC)
✅ Deployment successful!
View logs
sugabots-website cf55817 Oct 06 2026, 05:09 AM

@github-actions

github-actions Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Sandbox image preview, built from cf55817:

ghcr.io/nitrictech/sugabots-sandbox:pr-304

To try it, set a sandbox provider's image to that under Sandboxes in the workspace's settings, then Upgrade the pod's sandbox; on E2B, prepare the template again first. The tag moves with each push to this pull request, so a machine that pulled it before may need docker pull again; for this exact build, use ghcr.io/nitrictech/sugabots-sandbox@sha256:ea9d2adc637e19255735fcb10d74d5f7a52d95d4d127c286f7243f723ea7aad2.

It's deleted when the pull request closes.

request_software asks for a package from nixpkgs, stable or unstable, and the turn waits for whoever manages the pod's sandbox to allow it. Allowed, it is installed into the pod's shared Nix profile, on every command's PATH, and recorded at the nixpkgs commit it came from; each turn's first use of the sandbox gives it exactly the pod's recorded packages, so a new or upgraded sandbox gets them back. The pod's settings list its software, which its admins can remove.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant