Gungnir Hardened Container Sandbox & Isolation Jail

Official Core
@deepseek-ai/dsh-sandbox-gungnir · v2.1.2

A zero-trust hardened container sandbox for executing untrusted AI code. Powered by Linux namespaces, strict seccomp syscall filters, and read-only rootfs with sub-millisecond cold starts.

SandboxZero-TrustContainerSeccomp
GitHub Stars
128 K+
+12.4% this month
Monthly Downloads
512 K+
Monthly registry pulls
Reach Score
99.4/ 100
Top Tier Ecosystem
Runtime
Cordis v3+
Node 18+ / Bun / Deno

Installation & Integration

CLI one-click launch, package managers, and Cordis integration

bash
manager:
$ pnpm add @deepseek-ai/dsh-sandbox-gungnir

Architecture

Gungnir Sandbox provides an impenetrable safety perimeter for autonomous code execution. When LLMs write and test scripts, catastrophic errors—such as recursive file deletions, secret leaks, or accidental port scans—can easily compromise host machines. This plugin leverages Linux namespaces, cgroups v2, and seccomp-BPF filters directly via Cordis. Execution occurs within isolated, ephemeral overlay filesystems where host mounts remain strictly read-only. Network egress can be disabled entirely or restricted to explicit domain whitelists, providing zero-trust isolation with sub-second lifecycle teardowns.

Architectural Principles & Constraints

01
Strict Type Isolation

Guaranteed by TypeScript compile-time contracts, inter-plugin event bus calls enjoy zero-drift safety.

02
Sub-Millisecond Hot Reload

Supports dynamic runtime mounting and graceful unloading without restarting the primary host process.

03
Deterministic State Machine

Embeds multi-phase execution lifecycle guards, preventing context loss during long-horizon reasoning.

04
Zero Native Build Dependencies

Designed for lightweight cross-platform environments, booting instantly across Node.js, Bun, and Deno.

Core Features

01
Complete Linux Namespaces Isolation: Fully partitions net, pid, mount, and ipc domains
02
Seccomp-BPF Syscall Shield: Blacklists dangerous kernel primitives including ptrace and mount
03
Granular Egress Firewall: Allows full offline airgap or strict domain whitelist tunneling
04
Instant Ephemeral Cleanup: All disk writes reside on overlay RAM, vanishing instantly upon exit

Core Workflow

01

Ephemeral Jail Boot

Instantiates an isolated namespace with read-only rootfs and writable OverlayFS.

02

Seccomp Policy Compilation

Applies strict seccomp-BPF filters blocking privileged kernel system calls.

03

Sandboxed Execution

Executes target scripts bounded by strict memory, CPU, and egress quotas.

04

Artifact Extraction & Kill

Collects standard outputs and generated artifacts before destroying the jail.

Configuration Parameters Reference (YAML / JSON)

ParameterTypeDefaultDescription
memoryLimitMbnumber1024Maximum memory limit in megabytes
allowInternetbooleanfalseAllow outbound internet egress
timeoutSecondsnumber120Execution timeout limit before SIGKILL

Use Cases

Enterprise Production Agent

Relies on microkernel lifecycle guards and fault-tolerant state machines for continuous reliability.

SWE-bench Benchmark Evaluation

Native integration with SWE-bench workflows, automatically capturing diffs and verification metrics.

Autonomous Code Refactoring

Separates reasoning from tool actions to independently locate and refactor multi-file codebases.

Cross-Tool Workflow Automation

Safely orchestrates events across sandboxes to seamlessly link enterprise developer tooling.

Best Practices

01
Sandbox Permission Guard

Strictly isolate sub-process calls and network scope; deploy within Docker containers in production.

02
Exponential Backoff Retries

Configure adaptive exponential retries with strict timeouts to mitigate upstream model rate limits.

03
Session State Checkpointing

Persist state machine snapshots to survive hardware interruptions and resume instantly without loss.

04
Full Trajectory Audit Logs

Enable full trace logging, aggregating reasoning thought streams and tool I/O into your observability hub.

FAQ

Q1:How to handle timeouts in long-running autonomous tasks?

Increase the timeout parameter inside your YAML configuration and dispatch periodic heartbeat signals across the Cordis event bus. For long-running tool execution and model reasoning, configure persistent session snapshotting so suspended tasks can safely resume their exact context after interruptions, preventing the kernel from recycling active agent sessions prematurely.

Q2:How to capture and stream the model reasoning thought process?

The harness runtime natively provides end-to-end streaming hooks while its state machine automatically intercepts and strips <think> reasoning tags from model responses. Subscribe directly to the onThink event listener to consume live reasoning token streams in real-time, delivering typewriter animation to the user interface while persisting full trajectories for audit compliance.

Q3:How to resolve dependency conflicts across multiple plugins?

Cordis microkernel uses directed acyclic graph topological sorting to dynamically resolve plugin dependencies. When shared services or runtime versions conflict, assign distinct isolated namespaces at the application entrypoint. Leveraging context injection alongside lazy activation ensures dependencies load strictly on-demand when tools are triggered, maintaining system stability and preventing memory bloat.

Q4:How to enforce permissions and sandbox isolation in production?

Combine isolated container sandboxing with fine-grained capability checks to prevent plugins from accessing sensitive files or unauthorized external networks. Enforce explicit runtime system call whitelisting through the microkernel, executing all third-party tool scripts inside isolated ephemeral containers to block arbitrary code execution and eliminate security privilege escalation risks entirely.

Recommended Ecosystem Plugins

Explore related Cordis extensions designed to work synergistically