Skip to main content
A Sandbox Provider starts a managed Runtime by handing it one bootstrap file. This document owns that Provider-to-Runtime startup input. The type and validator live in internal/runtimebootstrap; Go providers build it with sandbox.Bootstrap.RuntimeConnection() in runtime_bootstrap.go, and SDK helpers forward the serialized object unchanged. A provider never reads or writes the Runtime’s private authentication store.

Launch input

Deliver one JSON object in a regular file that only the Runtime account and trusted provisioning processes can read (mode 0600 on managed Linux), and pass its absolute path:
The decoder rejects unknown, duplicate, missing and case-aliased fields, other versions and documents larger than runtimebootstrap.MaxBytes (16 KiB). Errors never include submitted values. A missing or malformed file fails before the daemon connects. The file is the only authentication input for this launch: the daemon refuses to combine it with pairing or self-hosted enrollment options, and reads the credential into memory without saving it to a stored profile. Credentials never go in command arguments, environment variables or receipts. The provider keeps the file for process restarts and removes it only during explicit cleanup of the resources it owns.

Responsibilities and readiness

The provider creates the account, mounts and workspace, delivers this file, sets the Runtime’s resource and Environment binding settings, and starts the daemon as the unprivileged Runtime account. Docker writes the file into the Runtime’s owned home volume; microsandbox and E2B deliver it before launching the same command. The Runtime validates the input and owns authentication and connection. A successful launch proves only the handoff: an authenticated connection, prepared capabilities and execution readiness are separate observations under the Core–Runtime protocol, and the Sandbox Provider guide lists what each one proves. Self-hosted executors and operator-provisioned devices get their daemon identity in other ways; the machine connection API lists every credential source. All of them enter the same Runtime execution loop.

Hosted suspension control

The private hosted park/wake control-file path is authored as SuspendControlFile in internal/runtimebootstrap/bootstrap.go. Core recovery and native Go adapters read that value; the E2B helper contract generator projects it into the template builder. Managed startup prepares its private directory and supplies OAC_RUNTIME_DAEMON_SUSPEND_PID_FILE to enable Runtime suspension. This is a packaged protocol setting. The shared Sandbox Provider registration owns idle and retention defaults; the adapter owns its native lease timeout.

Verification

go test ./internal/runtimebootstrap ./apps/daemon/internal/cli covers the input contract, the exclusivity of credential sources and restart behavior. Provider tests verify delivery and file permissions without relying on the Runtime’s private storage.