Runtime
Booting sandbox...
jiki’s sandboxing system for running untrusted code with resource limits. The container in this demo allows a maximum of 10 files, 1 MB memory, and writes only to /app and /tmp.
How it works
- Creating more than 10 files triggers the file count limit
- Writing to
/etc/secretor other paths outside/appis blocked - Sandbox violations produce clear error messages with fix suggestions
- Limits are configurable per-container so each use case gets appropriate restrictions
Try it yourself
- Run
node /app/index.js— works fine within the sandbox - Try
echo secret > /etc/passwd— blocked by path restriction - Run
node /app/fill-test.js— hits the file count limit - Create files in
/tmp— allowed by the sandbox configuration