-
Notifications
You must be signed in to change notification settings - Fork 3
native_workspace_mode
github-actions[bot] edited this page Sep 20, 2026
·
1 revision
The system supports two deployment modes for the workspace server:
-
Docker mode (default): Workspace runs inside a Docker container at
/app/workspace-docs. Shell commands execute inside the container and needhost.docker.internalto reach the Go agent server on the host. -
Native mode: Workspace runs directly on the host filesystem. Shell commands execute on the host and use
localhost/127.0.0.1for all connectivity.
A single environment variable controls mode detection:
NATIVE_WORKSPACE=true
Set automatically by run_server_with_logging.sh --with-workspace. All runtime code checks this via:
common.IsNativeWorkspace() // pkg/common/types.goDo not infer the mode from WORKSPACE_DOCS_PATH, WORKSPACE_API_URL, or any other env var. Those are used for path resolution and connectivity, not mode detection.
| Concern | Docker | Native |
|---|---|---|
MCP_API_URL seen by shell commands |
http://host.docker.internal:<port> |
http://127.0.0.1:<port> |
| CDP URL for agent-browser | http://host.docker.internal:9222 |
http://localhost:9222 |
| CDP instructions shown to LLM | Uses host.docker.internal
|
Uses localhost
|
blockAbsoluteHostPaths guard |
Active (VirtioFS can leak /Users/) |
Skipped (sandbox-exec handles it) |
| Sandbox isolation (Folder Guard) | Linux mount namespaces (unshare -m) |
macOS sandbox-exec profiles |
-
agent_go/pkg/common/types.go—IsNativeWorkspace()checksNATIVE_WORKSPACE=true
| File | Function | What it decides |
|---|---|---|
agent_go/cmd/server/server.go |
GetCodeExecAPIURL() |
MCP_API_URL for shell commands |
agent_go/pkg/browser/executor.go |
resolveCdpURL() |
CDP connection URL |
agent_go/pkg/instructions/browser.go |
cdpHost() |
Host in LLM CDP instructions |
agent_go/pkg/workspace/execute_shell_command.go |
blockAbsoluteHostPaths caller |
Whether to block /Users/ etc. in commands |
These use WORKSPACE_DOCS_PATH for the actual filesystem path, not to detect Docker vs native:
-
agent_go/pkg/fsutil/atomic.go—WorkspaceDocsRoot(),WorkspaceShellRoot() -
agent_go/pkg/orchestrator/base_orchestrator_folder_guard.go— strips absolute prefixes -
agent_go/pkg/workspace/diff_patch_workspace_file.go— strips absolute prefixes
-
workspace/security/isolator.go—generateSandboxProfile()converts relativeReadPaths/WritePathsto absolute usingbaseDir(works in both modes sincebaseDircomes from--docs-dir)
-
agent_go/run_server_with_logging.sh— setsNATIVE_WORKSPACE=truewhen--with-workspaceis used
-
CDP_HOSTenv var overrides CDP URL detection (highest priority, checked beforeIsNativeWorkspace()) -
WORKSPACE_DOCS_PATHcan be set manually to point workspace at any directory
When adding code that behaves differently in Docker vs native:
- Import
coding-agent-loop/agent_go/pkg/common - Use
common.IsNativeWorkspace()— do not check other env vars for mode detection - Add an entry to the table above
Auto-synced from docs/ on main. Edit there, not here.