---
url: https://bishop.agentdeployment.co/running/sandbox.md
description: >-
  Running the agent under nono so it can't read Bishop's credentials, database
  or other threads' files.
---

# Sandbox

Turning the sandbox on runs the agent, and everything it starts, under [nono](https://nono.sh/os-sandbox), which removes its access to `.bishop/` entirely. Bishop therefore has to run from a directory outside the agent repo.

Under Codex, Bishop also switches Codex's own sandbox off (`sandboxMode` becomes `danger-full-access`) and logs that it did, because nono replaces it and Codex's own failed to start inside nono when tested on Linux.

## Install nono

On Debian or Ubuntu:

```sh
VERSION=$(curl -sIL https://github.com/nolabs-ai/nono/releases/latest | grep -i location | grep -oP 'v\K[0-9a-zA-Z.-]+')
ARCH=$(dpkg --print-architecture)
wget https://github.com/nolabs-ai/nono/releases/download/v${VERSION}/nono-cli_${VERSION}_${ARCH}.deb
sudo dpkg -i nono-cli_${VERSION}_${ARCH}.deb
```

On macOS, or Linux with Homebrew, `brew install nono`. Other distributions are covered in [nono's install guide](https://nono.sh/docs/cli/getting_started/installation). Then check that this machine can enforce it:

```sh
nono setup --check-only
```

Linux needs kernel 5.13 or later, and macOS 10.15 or later. nono has to be on the `PATH` Bishop runs with, which for a systemd unit is the unit's own `Environment=PATH=…`.

## Turn it on

Bishop's own directory can't be the agent directory with the sandbox on, because the kernel can't grant a directory while hiding part of it. Run Bishop from a directory of its own and point [`--agent`](/running/agent) at the agent, either a path or a git URL:

```sh
mkdir ~/bishop-home && cd ~/bishop-home
bishop --agent ~/agents/salesforce-guy
```

Move `.env` and `.bishop/` from the old directory into the new one first, or run setup there again. Then turn it on in `.bishop/config.json`:

```json
{
  "agent": {
    "sandbox": true
  }
}
```

Bishop checks nono works before it starts, and refuses to start rather than run the agent unconfined. The log says `sandbox is on` when it is, and warns when `agent.sandbox` names no profile, since the agent then can't reach toolchains under your home directory or push. An agent that needs neither can ignore the warning.

## What the agent can reach

Each turn can read and write its working directory (the thread's worktree in [worktree mode](/running/worktrees)), the repository's git directory so it can commit, the temp directory, and Claude Code's own `~/.claude`. It can read the files shared in its own thread, and your git config. Network access is unchanged. Everything else under your home directory is out of reach, and a command that tries gets "Permission denied", which the agent can report like any other error.

That includes tools installed under your home directory, like `nvm`, `pyenv` or `~/.cargo`. Grant them with a nono profile, which adds to Bishop's grants rather than replacing them. Save one as `~/.config/nono/profiles/toolchain.json`:

```json
{
  "meta": { "name": "toolchain" },
  "filesystem": {
    "read": ["$HOME/.nvm", "$HOME/.cargo"]
  }
}
```

and name it:

```json
{
  "agent": {
    "sandbox": { "profile": "toolchain" }
  }
}
```

`nono profile guide` explains the format. Don't add a `filesystem.deny` for anything Bishop grants: on Linux nono refuses to start with one, and so does Bishop.

## Letting the agent push

The sandbox keeps the agent out of `~/.ssh` and the `gh` CLI's login, so it can't push. Run this from Bishop's own directory:

```sh
bishop nono setup
```

It writes a nono profile named `bishop` (or whatever `--name` says) to `~/.config/nono/profiles/` that grants both, plus nono's `node-dev` toolchain and `~/.npm`, and names it in `agent.sandbox`, turning the sandbox on if it was off. A profile already at that path isn't replaced, and if `agent.sandbox` already names another profile the command leaves it and explains how to combine the two. The profile lets the agent read your SSH private keys, so give Bishop's user keys meant for the agent.

## Notes

* `file_share` sends only files the agent could read itself. A file somewhere else has to be copied into its working directory first.
* Leave Claude Code's own `sandbox` setting off under nono. One sandbox is easier to reason about, and Claude's has an escape hatch that retries a blocked command outside it.
* The container image doesn't include nono, and the sandbox isn't supported there yet.
* macOS is supported by nono but hasn't been tested with Bishop.
* `nono why --path <path> --op read` says which rule decided a "Permission denied".
