Run agents
noset run starts a command, usually an AI agent, inside the gate’s sandbox and streams its output. When the command ends, the sandbox is torn down.
noset run [flags] -- COMMAND [ARGS...]The sandbox
Section titled “The sandbox”Each run gets a fresh microVM:
- No network device. No network card, no route, no DNS, no cloud metadata address. Every connection goes to the gate’s proxy (
HTTP_PROXY,HTTPS_PROXYare set), which is the only way out. A program that ignores the proxy has no way out at all. - Your folder at
/workspace. The workspace is the current directory, or--workspace DIR; never$HOMEor/. Files the agent writes there appear on the host at once, owned by you. - Everything else is read-only or temporary. The root file system never changes.
/tmp,/home/agentand the other writable places are in memory and gone after the run. - Tools at
/opt/tools. Claude Code comes on a read-only tools disk the installer built from Anthropic’s own download. - The agent user is
agent(uid 1000), or root with--user root. Even root in the sandbox cannot get past the gate.
The host environment is never passed in. Give the agent variables with -e KEY=VALUE, and keys with --credential.
| Flag | |
|---|---|
--credential NAME[@HOST,...] |
A key from the gate’s environment, given to the agent as a placeholder. |
-e KEY=VALUE, --env KEY=VALUE |
An environment variable inside the sandbox. Repeatable. |
--workspace DIR |
The folder shared at /workspace (default: the current directory). |
--agent NAME |
The agent’s name in approvals and evidence (default: the command’s name). |
--hold DURATION |
How long a request waits for approval before the agent gets “try again later” (default 60s). |
--user agent|root |
The user inside the sandbox (default agent). |
--tty auto|yes|no |
Give the command a terminal (default auto). |
--cpus N, --memory MIB |
The sandbox’s size (default 2 CPUs, 2048 MiB). |
--quiet |
Print only approvals, denials and errors. |
--rules FILE |
A local rules file, for a gate that is not logged in. |
--map HOST=URL |
Send a host to a local upstream, for tests. |
Who starts the agent
Section titled “Who starts the agent”On a logged-in gate every session belongs to a person. The first noset run of a Linux user on a gate shows a link and a code; a person opens it and clicks Confirm. The confirmation lasts 12 hours for that Linux user on that gate, and only lets that user start agents.
The session is recorded with who confirmed it, the Linux user, the command and the rules in force. Approvers see Started by on each request, and four eyes (on by default) keeps that person from approving their own agent’s requests.
Where the rules come from
Section titled “Where the rules come from”- A logged-in gate gets its rules from Noset and checks for changes every 10 seconds. A new rule set applies at once, also to agents already running.
--rulesis refused there. - A gate that is not logged in uses
--rules FILE(see Rule format). Without rules every request is allowed and nothing is recorded; requests wait fornoset approveornoset denyon the same server.
Holds and retries
Section titled “Holds and retries”An ask request is held for 60 seconds (--hold) while approvers decide.
- Approved in time: the request goes on, once.
- No decision in time: the agent gets
403andNoset: waiting for approval (id …), try again later.The request keeps waiting. - The agent retries: while the request waits, the retry joins it; after the approval, the retry uses it.
- Denied:
403with the approver and their reason.
An approval covers exactly one request, as it was sent, and only in the session that asked for it. It expires after 15 minutes.
When the gate cannot reach Noset
Section titled “When the gate cannot reach Noset”| Rule | While the gate is offline |
|---|---|
| Deny | keeps denying, with the last rules the gate has |
| Allow, and requests that match no rule | keep running |
| Ask | no new approvals: the agent gets Noset cannot reach the approval service, try again later. Approvals that arrived before still work, once each |
The gate keeps writing evidence and uploads it when Noset is back. If it cannot write evidence at all (a full disk), requests that match a rule do not run. After 24 hours without an answer from Noset, every request gets 503 until the gate syncs again.