NOIR
Integrations

Sandbox drivers

Bring a local, container, microVM, or remote sandbox by implementing one bounded file-and-execution contract.

SandboxDriver combines SandboxStore and SandboxExecutor. This is the extension point for a user-owned execution environment.

Driver operations

The store lists, reads, writes, deletes, and snapshots files under a verified SandboxOwner. Writes support expected-version conflict detection and idempotency keys. The executor receives a complete request with owner, file snapshot, argv, working directory, environment, deadline, abort signal, and output byte limits.

const driver: SandboxDriver = {
  list: (request) => workspaces.list(request),
  read: (request) => workspaces.read(request),
  write: (request) => workspaces.write(request),
  delete: (request) => workspaces.delete(request),
  snapshot: (owner) => workspaces.snapshot(owner),
  execute: (request) => containers.execute(request),
  close: () => containers.close(),
}

Local executor

LocalSandboxExecutor accepts an allowlist of named commands. Each command has a fixed executable, optional fixed arguments, and argument validation. Only environment keys in allowedEnvironment are forwarded. This is safer than passing arbitrary shell source.

Remote providers

createManagedSandboxProvider models instance creation, leases, command execution, daemons, snapshots, and cleanup. Map the verified Noir owner to one provider instance or workspace, persist the mapping, and renew leases before expiry.

Required controls

  • Normalize and contain every path.
  • Reject absolute paths and traversal.
  • Bound file size, total workspace size, list size, stdout, stderr, and duration.
  • Forward abort signals.
  • Return explicit timed-out, aborted, failed, or exited status.
  • Restrict network and credentials outside Noir when the provider supports it.
  • Verify resulting files before claiming success.

The driver is ordinary application code. Noir supplies semantics and tooling, not the compute account.

On this page