promigence fork
fork N sandboxes from a snapshot (--count --cap)
- --snapshot H
- snap_<id> | alias[@commit7] | ./env.promigence (default promigence/base)
- --count Nrequired
- number of sandboxes
- --timeout DUR
- sandbox timeout (15m)
- --cap USDrequired
- spend cap; refused above it (exit 5)
- --allow-partial
- start what the cap allows; the rest not_started
- --secret NAME
- stored secret as an env var
- --verify-each
- verify forks before hand-over
- --network none|egress
- default egress
- --allow HOST
- outbound allow-list
- --optimize-for start|compute
- default start
- --keep-delta
- keep the writable delta
- --label K=V
- run label
- --wait-timeout DUR
- bound (100s); expiry = exit 11, nothing killed
- --no-wait
- return after POST /runs
- --fresh
- skip idempotent replay
- --stream
- live output (auto on a TTY)
- --no-stream
- one envelope even on a TTY
- --idempotency-key K
- a key you pick (24 h)
- --verbose
- text: fork timings and totals too
- --json
- force the JSON envelope
promigence exec -- CMD
run CMD in a sandbox (--sandbox SID) or a run (--run ID --all)
- --sandbox SID
- stdout is the child's own bytes (JSON only with --json or PROMIGENCE_OUTPUT=json); its exit code passes through; not found 127; Promigence's own failures 125
- --run ID
- with --all: every ready sandbox; queued reported skipped unless --wait
- --all
- 0 if every child exits 0, else 4
- --no-passthrough
- return 0–12 instead of the child's code
- --background
- with --sandbox: start it, print its exec_id, return now
- --stdin
- with --background: keep stdin open for
promigence exec stdin - --secret NAME
- stored secret as an env var
- --stream
- live output (auto on a TTY)
- --no-stream
- one envelope even on a TTY
- --max-output BYTES
- per stream (64k; 32m, the most, into a pipe or file); past it the rest is cut, and text exits 12
- --timeout DUR
- child timeout (default 15m)
- --wait
- bounded by --wait-timeout (default 100s)
- --wait-timeout DUR
- bound (100s); expiry = exit 11, nothing killed
- --idempotency-key K
- a key you pick (24 h)
promigence exec output EXEC_ID
an exec's output by id (background x_…: --follow)
- --range A-B
- byte range, 0-based and B inclusive;
A- runs to the end - --sandbox SID
- resolve the exec inside this sandbox (required for x_…)
- --run ID
- resolve the exec inside this run
- --stderr
- the child's stderr instead of its stdout
- --follow
- background exec: stream until it exits, pass its code through
- --json
- force the JSON envelope
promigence exec ps
list a sandbox's background execs
- --sandbox SIDrequired
- the sandbox
- --json
- force the JSON envelope
promigence exec stdin EXEC_ID
write to a background exec's stdin (needs exec --background --stdin)
- --sandbox SIDrequired
- the sandbox it runs in
- --data TEXT
- write this (default: read stdin to EOF)
- --file P
- write this local file's bytes
- --eof
- close stdin after writing (implied when reading a pipe)
- --no-eof
- keep it open after piped input
- --json
- force the JSON envelope
promigence exec kill EXEC_ID
signal a background exec (default SIGKILL)
- --sandbox SIDrequired
- the sandbox it runs in
- --signal SIG
- TERM | INT | HUP | KILL | a number
- --forget
- then drop its handle and buffered output
- --json
- force the JSON envelope
promigence files put SRC DST
copy a local file into a sandbox (--recursive: a directory)
- --sandbox SIDrequired
- target sandbox
- --recursive
- SRC is a local directory; DST is a directory in the sandbox
- --json
- force the JSON envelope
promigence files get SRC DST
copy a file out of a sandbox (--recursive: a directory)
- --sandbox SIDrequired
- source sandbox
- --recursive
- SRC is a directory in the sandbox; DST a local directory
- --exclude GLOB
- with --recursive: leave these out, e.g. .git
- --keep-links
- with --recursive: keep links leaving DST
- --json
- force the JSON envelope
promigence files ls [PATH]
list a directory in a sandbox (lstat per entry)
- --sandbox SIDrequired
- the sandbox
- --recursive
- walk below PATH, not one level
- --depth N
- with --recursive: how many levels
- --limit N
- stop after N entries (truncated is reported)
- --no-hidden
- drop dotfiles (they are listed by default)
- --json
- force the JSON envelope
promigence files search [PATH]
find files by name glob and/or text inside them
- --sandbox SIDrequired
- the sandbox
- --name GLOB
- name glob, e.g. '*.py'
- --contains TEXT
- literal text to find inside matching files
- --ignore-case
- case-insensitive --contains
- --limit N
- stop after N hits (truncated is reported)
- --no-hidden
- skip dotfiles and dot-directories
- --json
- force the JSON envelope
promigence files mkdir PATH
create a directory in a sandbox
- --sandbox SIDrequired
- the sandbox
- --parents
- mkdir -p: intermediate directories, and no error if it exists
- --mode OCTAL
- e.g. 755
- --json
- force the JSON envelope
promigence files mv SRC DST
move or rename a path inside a sandbox
- --sandbox SIDrequired
- the sandbox
- --overwrite
- replace DST if it is already there
- --json
- force the JSON envelope
promigence files cp SRC DST
copy a path inside a sandbox (both ends are in the sandbox)
- --sandbox SIDrequired
- the sandbox
- --recursive
- a directory and everything under it
- --overwrite
- replace DST if it is already there
- --json
- force the JSON envelope
promigence files chmod PATH
change mode and/or owner of a path in a sandbox
- --sandbox SIDrequired
- the sandbox
- --mode OCTAL
- e.g. 755
- --uid N
- owner
- --gid N
- group
- --recursive
- the directory and everything under it
- --json
- force the JSON envelope
promigence agent start claude|codex|opencode
a coding agent in a new sandbox
- --key-secret NAME[=VAR]
- stored secret with the model key (default ANTHROPIC_API_KEY; codex: OPENAI_API_KEY)
- --key-from-env VAR
- store the key from this variable first (never argv)
- --snapshot H
- start from this snapshot (default promigence/base; the agent is installed if missing)
- --image REF@sha256:D
- instead of --snapshot
- --repo URL
- clone this public repository and start the agent in it
- --prompt TEXT
- work on this task headless, in the background
- --attach
- open the agent's terminal now
- --timeout DUR
- sandbox lifetime (default 1h)
- --cap USD
- spend cap (else PROMIGENCE_SPEND_CAP, else the org default)
- --wait-timeout DUR
- bound (100s); expiry = exit 11, nothing killed
- --json
- force the JSON envelope
promigence sandbox kill SID
kill one sandbox
- --json
- force the JSON envelope
promigence sandbox network SID
what this sandbox may reach, and every host it was refused
- --cut
- cut this sandbox's egress now; it cannot be turned back on
- --json
- force the JSON envelope
promigence sandbox shell SID [-- CMD]
interactive terminal (raw TTY, follows window size)
- --cmd CMD
- run this instead of the login shell (sh -c)
- --cwd DIR
- start in this directory
- --env K=V
- environment variable
- --secret NAME[=VAR]
- stored secret in the terminal's environment; NAME=VAR binds it to VAR
promigence sandbox ssh SID [-- CMD]
log in over SSH (scp, sftp and -L work too)
- --config
- print an ssh config block instead of logging in
- --print
- print the connection details instead of logging in
- --key PATH
- use this key pair instead of making one
- --ttl S
- how long the access lasts (default 3600, max 3600)
- --idle S
- close a session after this long with no activity
- --proxy
- carry one connection on stdin/stdout (used by ssh itself)
- --list
- the keys that have access, then exit
- --revoke KEY_ID
- end one key's access (and its tunnel credential), then exit
- --json
- force the JSON envelope
promigence port expose PORT
publish a port as a preview URL (anyone with it can reach it)
- --sandbox SIDrequired
- the sandbox
- --json
- force the JSON envelope
promigence port list
list a sandbox's preview URLs
- --sandbox SIDrequired
- the sandbox
- --json
- force the JSON envelope
promigence port revoke TOKEN|PORT
take a preview URL down (a token, or every URL for a port)
- --sandbox SIDrequired
- the sandbox
- --json
- force the JSON envelope
promigence secrets set NAME
store secret NAME (env/file/stdin, never argv)
- --from-env VAR
- read the value from an environment variable
- --from-file P
- read the value from a file
- --host HOST
- bind it to a host: sandboxes get a placeholder, replaced by the value only in requests sent to the address this command prints for HOST
- --header NAME
- with --host: the request header the key is sent in (default: the usual key headers)
- --no-raw
- with --host: the value itself can never be given to a sandbox
- --list
- list stored secret names (no values, ever)
- --delete
- remove NAME
- --json
- force the JSON envelope
promigence sandbox list
your sandboxes, newest first
- --limit N
- how many (default 50)
- --state S
- only these states, e.g. running,ready
- --label K=V
- only sandboxes whose run carries every label given
- --cursor C
- the next_cursor of an earlier page
- --json
- force the JSON envelope
promigence sandbox pause SID
park a sandbox: it holds no capacity and bills no seconds
- --json
- force the JSON envelope
promigence sandbox resume SID
bring a paused sandbox back and restart its clock
- --optimize-for start|compute
- default: as created
- --json
- force the JSON envelope
promigence sandbox snapshot SID
snapshot it without stopping it
- --json
- force the JSON envelope
- --alias NAME
- name it
- --move-alias
- take the alias from the snapshot that has it
- --force
- take it even though the sandbox was given a secret; the snapshot, and what starts from it, can then contain that value
promigence secrets list
stored secret names (never a value)
- --json
- force the JSON envelope
promigence secrets delete NAME
remove a stored secret
- --json
- force the JSON envelope
promigence sandbox info SID
one sandbox: state, tier, time left, cost so far, and its execs
- --json
- force the JSON envelope
promigence sandbox extend SID
give a live sandbox more time, within its run's quote and --cap (exit 5 past them)
- --timeout DURrequired
- the new total timeout
- --json
- force the JSON envelope
promigence sandbox autopause SID
pause it once it has sat idle, or read the rule it is under
- --after DUR
- idle this long and it pauses itself (2s or more)
- --off
- never pause it on idle; only its timeout ends it
- --mode MODE
- requests (default) | activity: also no CPU, no bytes, no open connection inside
- --json
- force the JSON envelope
promigence sandbox probe SID
is this still the verified environment? (its recorded paths, or --path)
- --path P
- check these paths instead; PATH=blake3:<hex> where the snapshot recorded none (base, --image)
- --json
- force the JSON envelope
promigence files rm PATH
delete a path in a sandbox
- --sandbox SIDrequired
- the sandbox
- --recursive
- a directory and everything under it
- --json
- force the JSON envelope