Runtime

Booting sandbox...

jiki’s sandboxing system for running untrusted code with resource limits. The container in this demo allows a maximum of 10 files, 1 MB memory, and writes only to /app and /tmp.

How it works

Try it yourself

  1. Run node /app/index.js — works fine within the sandbox
  2. Try echo secret > /etc/passwd — blocked by path restriction
  3. Run node /app/fill-test.js — hits the file count limit
  4. Create files in /tmp — allowed by the sandbox configuration