A single-node sandbox manager for Linux and macOS.
shard creates sandboxes from OCI images, runs commands in them, pauses and resumes their processes, and forks live sandboxes. One binary is both the CLI and the daemon, and it drives five providers: gVisor, Sysbox, runc, Firecracker, and Virtualization.framework.
shard gives an agent a sandbox that outlives its commands. The agent's files stay between commands. You can save its memory while it is idle, or fork its current state to try another path. The same lifecycle commands work on a Linux server and on an Apple silicon Mac, and the host keeps control of secrets and outbound network policy. shard manages one host. It does not schedule a fleet.
Install the CLI, then set up this machine as a sandbox host:
curl -fsSL https://useshards.com/install | sh
shard setupCreate a sandbox, write a file, read it, and remove the sandbox:
sudo shard create --name demo --memory 512MiB alpine:3.20
sudo shard exec demo sh -c 'echo hello from shard > /tmp/hello.txt'
sudo shard exec demo cat /tmp/hello.txt
sudo shard remove --force demoThe third command prints hello from shard. On a Mac the daemon runs as your user, so drop sudo.
To open a shell in the sandbox, run sudo shard shell demo before you remove it.
The docs live at useshards.com/docs: install and setup, providers, the lifecycle, secrets and egress, the TypeScript and Python SDKs, and the CLI and REST API references.
Pre-alpha. The API, CLI, and SDKs can change without compatibility guarantees.
Read AGENTS.md for the code layout and contribution rules. Install the golangci-lint
version that CI pins, then run make check before each commit. It runs
the format check, vet, lint, the unit tests, and the e2e script's own tests. Tests that need a
runtime, namespaces, or KVM carry the integration build tag and run on a host that has them. See
the release guide for the platform checks.
Apache-2.0. See NOTICE for attribution.