What you will build
A mountless sandbox that receives one synthetic input file and returns one output. The small transfer manifest becomes your evidence of what data crossed the boundary.
- Create without path
- Private working directory
- Copy selected input
- Export selected output
Conceptual flow. Follow the lesson for prerequisites, exact commands and verification limits.
Read the mechanism
From sbx v0.42.0, omitting workspace paths from sbx create creates a sandbox without a host workspace bind mount. Docker-provided agent templates use /home/agent/workspace as their working directory; custom templates may choose another location.
The similar-looking sbx run shell has a different default: it mounts the current directory. To preserve mountless intent, create first without a path, then reconnect by name. A missing dot is meaningful syntax.
Mountless does not mean “no capabilities.” Network policies, credentials, skills and MCP integrations remain relevant. It specifically removes the workspace passthrough. Explicit transfers are easier to inventory, but an exported output can still contain unsafe code or private information.
Worked lab · controlled transfer
Run on the host in a new teaching directory:
printf 'alpha\nbeta\n' > input.txt
sbx create --name handbook-mountless --skills off shell
sbx exec handbook-mountless pwd
sbx cp ./input.txt handbook-mountless:/home/agent/workspace/input.txt
sbx exec handbook-mountless sh -c 'wc -l input.txt > result.txt'
mkdir mountless-output
sbx cp handbook-mountless:/home/agent/workspace/result.txt ./mountless-output/
cat ./mountless-output/result.txt
The explicit --skills off makes the teaching boundary smaller and avoids relying on a configurable default. If you use a custom template, inspect pwd and replace the absolute copy destinations accordingly.
Create a two-row manifest: input path plus content hash, output path plus content hash. A hash proves byte identity relative to a recorded value; it does not prove the content is correct or safe.
Expected observations
The result should report two input lines. The output appears on the host only after you copy it. Guest files survive a stop/start cycle until removal. If you edit the host input after copying, the guest copy does not automatically update.
That last observation distinguishes a copy from a live mount. Repeat with a third line added on the host, then inspect the guest input without re-copying. Predict the result before running the command.
Troubleshooting
sbx cp requires an absolute sandbox path; sandbox:. is not a reliable shorthand. A path error should lead to a working-directory check, not to broadening workspace mounts. If you accidentally used run with no path, inspect the sandbox and create a differently named mountless environment.
Before deletion, inventory outputs that matter. Use the named remove operation only after reviewing the export; do not use a global cleanup command.
Interview practice
Is mountless always better than clone mode?
It gives a smaller filesystem sharing boundary, but requires explicit transfer and can complicate iterative Git workflows. Choose based on data sensitivity, review needs and the task’s integration costs.
What can still cross a mountless boundary?
Explicit file copies, allowed network requests and configured integrations. Mountless describes workspace sharing, not a complete absence of external authority.
Completion check
Explain the create/run default difference from memory. Demonstrate that host changes after a copy do not automatically update guest input, and preserve a minimal transfer manifest.
Sources and version notes
Checked 6 October 2026; current baseline: sbx v0.46.0. Architecture · Shell integration · sbx create
Make the understanding yours.
Use the completion check above. Mark this chapter when you can explain the mechanism and its limits.
Self-assessed reading progress. This does not certify that a lab ran or a system is secure.