Skip to lesson
supraj.dev THE ENGINEERING HANDBOOKS
LEARN / BUILD / VERIFY2026 edition · checked 06 Oct

CHAPTER 07 / 30 · Foundations

Start with no host workspace

Use mountless sandboxes and explicit file transfer to make the data boundary easier to review.

4 min readWorked exerciseInterview practice

What you will build

A mountless sandbox that receives one synthetic input file and returns one output. The small transfer manifest becomes your evidence of what data crossed the boundary.

The mechanism at a glance
  1. Create without path
  2. Private working directory
  3. Copy selected input
  4. Export selected output

Conceptual flow. Follow the lesson for prerequisites, exact commands and verification limits.

Read the mechanism

From sbx v0.42.0, omitting workspace paths from sbx create creates a sandbox without a host workspace bind mount. Docker-provided agent templates use /home/agent/workspace as their working directory; custom templates may choose another location.

The similar-looking sbx run shell has a different default: it mounts the current directory. To preserve mountless intent, create first without a path, then reconnect by name. A missing dot is meaningful syntax.

Mountless does not mean “no capabilities.” Network policies, credentials, skills and MCP integrations remain relevant. It specifically removes the workspace passthrough. Explicit transfers are easier to inventory, but an exported output can still contain unsafe code or private information.

Worked lab · controlled transfer

Run on the host in a new teaching directory:

printf 'alpha\nbeta\n' > input.txt
sbx create --name handbook-mountless --skills off shell
sbx exec handbook-mountless pwd
sbx cp ./input.txt handbook-mountless:/home/agent/workspace/input.txt
sbx exec handbook-mountless sh -c 'wc -l input.txt > result.txt'
mkdir mountless-output
sbx cp handbook-mountless:/home/agent/workspace/result.txt ./mountless-output/
cat ./mountless-output/result.txt

The explicit --skills off makes the teaching boundary smaller and avoids relying on a configurable default. If you use a custom template, inspect pwd and replace the absolute copy destinations accordingly.

Create a two-row manifest: input path plus content hash, output path plus content hash. A hash proves byte identity relative to a recorded value; it does not prove the content is correct or safe.

Expected observations

The result should report two input lines. The output appears on the host only after you copy it. Guest files survive a stop/start cycle until removal. If you edit the host input after copying, the guest copy does not automatically update.

That last observation distinguishes a copy from a live mount. Repeat with a third line added on the host, then inspect the guest input without re-copying. Predict the result before running the command.

Troubleshooting

sbx cp requires an absolute sandbox path; sandbox:. is not a reliable shorthand. A path error should lead to a working-directory check, not to broadening workspace mounts. If you accidentally used run with no path, inspect the sandbox and create a differently named mountless environment.

Before deletion, inventory outputs that matter. Use the named remove operation only after reviewing the export; do not use a global cleanup command.

Interview practice

Is mountless always better than clone mode?

It gives a smaller filesystem sharing boundary, but requires explicit transfer and can complicate iterative Git workflows. Choose based on data sensitivity, review needs and the task’s integration costs.

What can still cross a mountless boundary?

Explicit file copies, allowed network requests and configured integrations. Mountless describes workspace sharing, not a complete absence of external authority.

Completion check

Explain the create/run default difference from memory. Demonstrate that host changes after a copy do not automatically update guest input, and preserve a minimal transfer manifest.

Sources and version notes

Checked 6 October 2026; current baseline: sbx v0.46.0. Architecture · Shell integration · sbx create

YOUR NEXT STEP

Make the understanding yours.

Use the completion check above. Mark this chapter when you can explain the mechanism and its limits.

Self-assessed reading progress. This does not certify that a lab ran or a system is secure.