Repository navigation
v0.1.5
Coding-agent internet access
Add --allow-network when launching an agent that needs package downloads,
remote repositories, documentation or APIs:
sparkplane dgx-spark launch codex --allow-network -- --sandbox workspace-write
sparkplane dgx-spark launch claude --allow-networkThe environment equivalent is SPARKPLANE_LAUNCH_ALLOW_NETWORK=true.
The setting is invocation-only; default permissions, filesystem protections,
approval policies and managed restrictions remain in force. OpenCode already
has direct network access and retains its tool permissions.
Codex now receives its private inference CA through CODEX_CA_CERTIFICATE
instead of a launcher-supplied SSL_CERT_FILE, keeping public HTTPS trust intact
for development subprocesses. Neither change weakens inference-token scope,
TLS verification, or appliance engine networking.
See network controls and limitations.
Upgrade scope
Upgrade the workstation client to use these fixes. An existing v0.1.4 appliance
can remain running; no model restart, engine rebuild or context change is needed.
The release also includes the normal ARM64 appliance package for new installs.
Provenance and verification
- Source: 2690203db432ad0802efbfdd642295798d431834, PR #8.
- Build and signing: Release workflow.
- Clients:
sparkplane-x86_64-unknown-linux-gnu,sparkplane-aarch64-unknown-linux-gnu. - Appliance:
sparkplane-appliance-aarch64.tar.gz. - Signed inventory:
SHA256SUMSand its detachedSHA256SUMS.minisig. - The established release signing authority is unchanged. Verify against your
existing trusted public key, not a newly downloaded key alone.
Lint, appliance/client-only tests, dependency audit, and warning-denying
documentation checks passed. The native Codex sandbox regression also verified
public HTTPS access with opt-in and denied writes outside the workspace.