Skip to content

Run agents

noset run starts a command, usually an AI agent, inside the gate’s sandbox and streams its output. When the command ends, the sandbox is torn down.

Terminal window
noset run [flags] -- COMMAND [ARGS...]

Each run gets a fresh microVM:

  • No network device. No network card, no route, no DNS, no cloud metadata address. Every connection goes to the gate’s proxy (HTTP_PROXY, HTTPS_PROXY are set), which is the only way out. A program that ignores the proxy has no way out at all.
  • Your folder at /workspace. The workspace is the current directory, or --workspace DIR; never $HOME or /. Files the agent writes there appear on the host at once, owned by you.
  • Everything else is read-only or temporary. The root file system never changes. /tmp, /home/agent and the other writable places are in memory and gone after the run.
  • Tools at /opt/tools. Claude Code comes on a read-only tools disk the installer built from Anthropic’s own download.
  • The agent user is agent (uid 1000), or root with --user root. Even root in the sandbox cannot get past the gate.

The host environment is never passed in. Give the agent variables with -e KEY=VALUE, and keys with --credential.

Flag
--credential NAME[@HOST,...] A key from the gate’s environment, given to the agent as a placeholder.
-e KEY=VALUE, --env KEY=VALUE An environment variable inside the sandbox. Repeatable.
--workspace DIR The folder shared at /workspace (default: the current directory).
--agent NAME The agent’s name in approvals and evidence (default: the command’s name).
--hold DURATION How long a request waits for approval before the agent gets “try again later” (default 60s).
--user agent|root The user inside the sandbox (default agent).
--tty auto|yes|no Give the command a terminal (default auto).
--cpus N, --memory MIB The sandbox’s size (default 2 CPUs, 2048 MiB).
--quiet Print only approvals, denials and errors.
--rules FILE A local rules file, for a gate that is not logged in.
--map HOST=URL Send a host to a local upstream, for tests.

On a logged-in gate every session belongs to a person. The first noset run of a Linux user on a gate shows a link and a code; a person opens it and clicks Confirm. The confirmation lasts 12 hours for that Linux user on that gate, and only lets that user start agents.

The session is recorded with who confirmed it, the Linux user, the command and the rules in force. Approvers see Started by on each request, and four eyes (on by default) keeps that person from approving their own agent’s requests.

  • A logged-in gate gets its rules from Noset and checks for changes every 10 seconds. A new rule set applies at once, also to agents already running. --rules is refused there.
  • A gate that is not logged in uses --rules FILE (see Rule format). Without rules every request is allowed and nothing is recorded; requests wait for noset approve or noset deny on the same server.

An ask request is held for 60 seconds (--hold) while approvers decide.

  • Approved in time: the request goes on, once.
  • No decision in time: the agent gets 403 and Noset: waiting for approval (id …), try again later. The request keeps waiting.
  • The agent retries: while the request waits, the retry joins it; after the approval, the retry uses it.
  • Denied: 403 with the approver and their reason.

An approval covers exactly one request, as it was sent, and only in the session that asked for it. It expires after 15 minutes.

Rule While the gate is offline
Deny keeps denying, with the last rules the gate has
Allow, and requests that match no rule keep running
Ask no new approvals: the agent gets Noset cannot reach the approval service, try again later. Approvals that arrived before still work, once each

The gate keeps writing evidence and uploads it when Noset is back. If it cannot write evidence at all (a full disk), requests that match a rule do not run. After 24 hours without an answer from Noset, every request gets 503 until the gate syncs again.