Trying OpenCode with Docker Sandboxes
I usually use OpenCode, but I tried it after hearing there’s an application that can run OpenCode in a sandbox environment from Docker.
Docker Sandboxes
This is an environment that starts a very small virtual environment and runs OpenCode or Codex within it.
It has a separate file system from your own environment, and by default, all network connections are blocked, allowing only explicitly permitted destinations.
Although Docker is involved, it’s not a container. It’s a virtual environment, so the kernel is also separate, which is reassuring.
My environment is WSL (Ubuntu) on Windows.
I thought I might need to install it on Windows, but it worked normally when installed in WSL.
Installation
Installation on WSL can be done using the Linux installation method.
curl -fsSL https://get.docker.com | sudo REPO_ONLY=1 sh
sudo apt-get install docker-sbx
When copying from the official source, it has REPO_ONLY= 1 with a space between = and 1, which causes an error.
After fixing it, the installation is complete.
Preparation
It didn’t work right away.
First, you need to add yourself to the kvm group.
sudo usermod -aG kvm [your username]
Restart WSL at this point.
Log out of WSL and
$ exit
Stop WSL from PowerShell
wsl --shutdown
Log back into WSL
$ wsl
Check that you’re in the kvm group using the id command on WSL.
$ id
groups=...,1001(docker),XXX(kvm)
Network Permissions
In Docker Sandboxes, you must explicitly allow network destinations.
Since we’re using OpenCode, allow communication with the OpenCode API.
$ sbx policy allow network opencode.ai:443
Since I also use GPT-5.6 from OpenCode, allow that as well.
$ sbx policy allow network api.openai.com:443
It seems GitHub is allowed by default, but I also set it up including APIs.
$ sbx policy allow network "github.com:22"
$ sbx policy allow network github.com:443
$ sbx policy allow network api.github.com:443
$ sbx policy allow network "*.githubusercontent.com:443"
$ sbx policy allow network raw.githubusercontent.com:443
$ sbx policy allow network objects.githubusercontent.com:443
$ sbx policy allow network "models.opencode.ai:443"
For Using GPT-5.6
Make sure to complete OpenAI authentication.
$ sbx secret set openai --oauth
Log in to OpenAI in advance and open the displayed URL.
Launch
The launch command is as follows.
Note that CPU cores and memory allocation cannot be changed later, so it’s recommended to specify them here.
(Default is all CPU cores and half the memory allocated)
$ sbx run --cpus 10 -m 20g opencode
If you want to use codex or ClaudeCode, replace opencode in the above command.
Settings
Since I use OpenCode Go, set the API key.
This needs to be set again in the sandbox environment.
/connect
I use DeepSeekV4 Flash, but change to your preferred model (via /models) and test it.
Bonus: Debugging Method
If it doesn’t work, run the following to check the results.
$ sbx diagnose
The results will be displayed as follows.
sbx diagnose
─────────────────────────────────────────
Installation
✓ CLI binary — found
/usr/bin/sbx
✓ Binary version — v0.39.0
✓ Daemon — healthy
version v0.39.0
✓ Daemon diagnostics — collected (78761 bytes)
Platform
✓ Virtualization — supported
/dev/kvm is accessible
Storage
✓ Storage directories — all 1 paths present
✓ Directory permissions — all writable
✓ Disk space — 865.4GiB free
865.4GiB free of 1007GiB on the state directory's volume
Connection
✓ Version match — v0.39.0
✓ Socket — responsive
✓ SSH client config — not configured
✓ Authentication — authenticated
─────────────────────────────────────────
12 passed
If any part fails, that’s the cause. Resolve it by asking ChatGPT and it will work.
Updates
If you’re on an Ubuntu environment including WSL, simply run
sudo apt update
sudo apt install --only-upgrade docker-sbx
If you’re already running a specific project, delete the template and rebuild it.
Use the following command to check the sandbox list
$ sbx ls
Delete the one you want to update and install again
$ sbx rm [sandbox name]
$ sbx run opencode
Global network policies remain even after deleting and re-creating the sandbox, so you usually don’t need to reconfigure them.
Want to enter the sandbox shell and do various things
$ sbx exec -it [sandbox name] bash
Check the sandbox name with sbx ls. If you want to create an SSH key for GitHub, create it normally while inside and register it with GitHub.
Launch with a specific session
$ sbx run opencode -- -s ses_xxxxxxxxxxxxxxxxxxxxxxxxxx
Comments
No comments yet.