pypi · llm-sandbox
BACKEND — Container backend to use. Must match the installed extra: mcp-docker, mcp-podman, or mcp-k8s.
DOCKER_HOST — Docker or Podman socket URL, e.g. unix:///var/run/docker.sock
KUBECONFIG — Path to kubeconfig file when BACKEND=kubernetes.
NAMESPACE — Kubernetes namespace used for sandbox pods when BACKEND=kubernetes.
COMMIT_CONTAINER — Commit the container after a run so installed libraries persist between sessions.
KEEP_TEMPLATE — Keep the base image after the session ends to avoid re-pulling it on the next run.
SANDBOX_NETWORK_MODE — Network mode for the sandbox container. Set to 'none' for hardened isolation. Docker and Podman backends only.
SANDBOX_READ_ONLY — Mount the sandbox root filesystem read-only. Recommended: true. Docker and Podman backends only.
SANDBOX_CAP_DROP — Comma-separated Linux capabilities to drop. Recommended: ALL. Docker and Podman backends only.
SANDBOX_SECURITY_OPT — Comma-separated container security options, e.g. no-new-privileges. Docker and Podman backends only.
SANDBOX_MEMORY — Memory limit for the sandbox container, e.g. 4g. Docker and Podman backends only.
SANDBOX_CPUS — Fractional CPU allocation for the sandbox container, e.g. 1.5. Docker and Podman backends only.