Skip to content

Releases: Colton-z/AstraBox

AstraBox 0.1.1

Choose a tag to compare

@github-actions github-actions released this 27 Sep 02:38

Upgrading is strongly recommended for every 0.1.0 installation: it fixes
sandbox isolation and access-control vulnerabilities, and engines that could
not complete a first turn on the one-command install. Re-run the installer to
upgrade; settings, secrets and data are kept.

Sandboxes that 0.1.0 started keep their old port bindings until they are
replaced. To close that exposure right away, remove them on the AstraBox host
after upgrading:

docker ps -aq --filter label=opensandbox.io/id | xargs -r docker rm -f
docker ps -aq --filter label=opensandbox.io/egress-sidecar-for | xargs -r docker rm -f

Each conversation continues on a new sandbox with its history. Files in a
removed sandbox's workspace are kept only with the optional persistent
workspace volume.

Security

  • Sandbox services were reachable from the network. Each sandbox's command
    and file services were published on every host interface without
    authentication. They are now bound to the Docker bridge gateway only.
  • A sandbox could reach the management API. With Unrestricted networking,
    code in a sandbox could call the platform API, which in no-login mode acts as
    an administrator. The server no longer publishes its API on the Docker
    bridge; the scoped sandbox edges reach it over a private network.
  • A sandbox could reach another sandbox. Every sandbox now denies the
    Docker bridge subnet, apart from the scoped edges, in every networking mode.
  • Cloud metadata and raw sockets. 169.254.0.0/16 is denied in every
    networking mode, and sandbox containers no longer have NET_RAW (Docker).
  • Agent fields could widen a sandbox's access. Plugin, Skill and MCP hosts
    written by an Agent author are now checked against the Environment's policy.
    Private, loopback, link-local and Docker bridge hosts are refused unless an
    administrator has explicitly admitted them in that Environment.
    deploy_key_secret_name resolves only names listed in
    ASTRABOX_DEPLOY_KEY_SECRET_NAMES, an author's MCP definition cannot select
    the platform's gateway credential, and the Git HTTPS token is sent only to
    ASTRABOX_GIT_HTTPS_TOKEN_HOST. Refusals are 403 with registered codes.
  • Team login: members could become administrators. A member could request
    astrabox:admin in their own token. API scopes now count only on tokens
    issued to the configured API client; a user's token carries the user's role.
  • Team login: bundled Casdoor defaults. The built-in Casdoor administrator's
    default password is replaced with a generated secret at first start, and
    AstraBox accepts only accounts of the configured organization
    (ASTRABOX_CASDOOR_ORGANIZATION, default astrabox).
  • The name-only egress mode is refused. ASTRABOX_SANDBOX_EGRESS_MODE=dns
    enforces no address rule, so the cloud metadata deny, the Docker bridge deny
    and address entries in Limited allow lists would not apply. The server now
    refuses to start with it instead of warning.
  • IPv6 stays off in every sandbox. AstraBox now sets OpenSandbox's
    egress.disable_ipv6 itself instead of relying on its default, so sandboxes
    have no IPv6 route even where the Docker daemon enables IPv6.
  • The server never offers sandboxes its own address. With
    ASTRABOX_MCP_PROXY_BASE_URL unset, the server used its own container
    address as the sandbox callback base, and the protected embedded gateway used
    it as the private gateway address; either let a sandbox reach every port the
    server listens on. Neither is derived any more: an unset callback base fails
    the first sandbox, and the embedded gateway refuses to start without a
    gateway address. The maintained Compose stack sets both to the sandbox edge.
  • Kubernetes sandboxes lose NET_RAW. Sandbox containers on Kubernetes
    could open raw sockets, which Docker sandboxes lost in 0.1.1. The bundled
    lifecycle server now creates every sandbox with NET_RAW dropped, through
    the OpenSandbox BatchSandbox template. With
    ASTRABOX_SANDBOX_SERVER_KUBE_WORKLOAD_PROVIDER=agent-sandbox the server
    logs a warning instead, because that provider reads a template AstraBox does
    not write.
  • Hermes' session token no longer reaches proxy logs. AstraBox sent the
    token that opens an Assistant's Hermes backend in the connection URL, and the
    OpenSandbox ingress gateway and the sandbox's command service log every
    request URL. It now travels in a request header, and the Hermes image moves
    it to where Hermes reads it inside the sandbox. Rebuild or pull the
    sandbox-hermes image together with the server.
  • The Hermes backend credential is no longer computable from a box's
    identity.
    The token that opens an Assistant's Hermes backend was a hash of
    the box's account and home directory, with no deployment secret, so anyone
    who could reach the backend port and knew those identifiers could present it.
    On Kubernetes the sandbox Pod has no ingress firewall, so that port is
    reachable from elsewhere in the cluster. The token is now derived from the
    deployment's own secret and cannot be reproduced from the identity alone.
    Rebuild or pull the sandbox-hermes image together with the server.
  • Claude Code and Codex sandboxes admit only the platform on their engine
    ports.
    A Claude Code sandbox's runner handed its live conversation to any
    connection that named the conversation's id, which the API shows and which
    the runner's own refusal revealed to a peer that named a wrong one. A Codex
    sandbox's app-server port relayed every connection to the server. On
    Kubernetes a sandbox Pod has no ingress firewall of OpenSandbox's making, so
    any pod in the cluster could reach both, and in an Agent-shared sandbox every
    other conversation could. Both now require a credential derived from the
    deployment's own secret and the sandbox's identity, and refuse a connection
    without it before naming or relaying anything. A new Claude Code sandbox's
    runner also refuses to be prepared until AstraBox has written that
    credential into the sandbox, so the first connection to reach it cannot
    claim it. Rebuild or pull the
    sandbox-claude-code and sandbox-codex images together with the server;
    sandboxes started before the upgrade keep the old behaviour until they are
    replaced.
  • The sandbox's :8080 services were open to any caller that reached the
    port.
    The agent-infra base image serves a file and shell API, a terminal,
    JupyterLab, a VNC desktop, code-server and an MCP hub on :8080 and left them
    unauthenticated, so an unauthenticated request ran arbitrary commands in the
    box. On Kubernetes every Pod in the cluster can reach that port, and on Docker
    every container on the default bridge can, including through the address the
    egress sidecar publishes on the bridge gateway — cross-tenant code execution.
    AstraBox now sets the base image's own SANDBOX_API_KEY per box, derived from
    the deployment secret and the box's identity, so the port refuses a caller
    without it. Exposed-port links never carry that credential: port 8080 cannot
    be exposed, and previews use the agent's own web server port. The
    services AstraBox does not use — JupyterLab, code-server, the VNC desktop, the
    browser and the Node REPLs — no longer run at all. Rebuild or pull the
    sandbox-* images together with the server.

Added

  • Team login from the installer. ASTRABOX_INSTALL_TEAM_LOGIN=casdoor turns
    on the bundled Casdoor login; set ASTRABOX_CONSOLE_ORIGIN and
    ASTRABOX_OIDC_ISSUER for a deployment behind a reverse proxy. The release
    bundle now contains the login overlay.
  • Langfuse tracing through OpenTelemetry. The bundled gateway sends traces
    with LiteLLM's OTel integration when LANGFUSE_PUBLIC_KEY and
    LANGFUSE_SECRET_KEY are set, and sends nothing otherwise.
  • Single-container deployment. ghcr.io/colton-z/astrabox:0.1.1 runs the
    platform with docker run; it keeps its data in a Docker volume and creates
    separate sandbox containers from the matching sandbox-* images. See the
    all-in-one guide.

Fixed

  • Assistant workspaces on persistent volumes prepare their private directory
    ownership before startup checks. Replacement sandboxes reuse the same numeric
    account so the existing workspace and Hermes profile remain writable.

  • A conversation replacing a lost sandbox could fail its next message because
    background cleanup deleted the replacement during startup. Cleanup now
    preserves the replacement while the conversation's accepted turn is active.

  • Prepared-runtime status keeps the existing pool identity while an Agent
    configuration change prepares a replacement.

  • The first model request of the bundled gateway failed with
    400 Invalid request format for Pi, Hermes, DeepSeek Harness and Codex.

  • DeepSeek Harness and Hermes could not start on the one-command install; the
    server now connects to sandboxes directly instead of through the lifecycle
    server's relay.

  • Sandboxes could not be created on hosts with fewer than four CPUs.

  • The server restarted once during a fresh install while the model gateway
    finished its first boot.

  • docker stop now stops AstraBox before the services it depends on.

  • Claude Code ran without its own system prompt when an Agent had no
    instructions (including the seeded Agent) and its sandbox started cold. It
    now always runs on Claude Code's preset, with Agent instructions appended.

  • DeepSeek Harness failed every turn on models other than DeepSeek's (it asked
    for a 256,000-token output). Other models now use the harness's generic
    gateway route with its standard limits.

  • Conversation titles and process summaries were never generated on the
    one-command install. Every turn logged session title generation failed
    and the conversation kept the Agent's name, because the server sent these
    requests to the sandbox-only gateway name gateway.astrabox.test. The
    se...

Read more

AstraBox 0.1.0

Choose a tag to compare

@github-actions github-actions released this 23 Sep 01:22