Granting and withdrawing access

On this page

All commands run in your computer's terminal, from the project folder. A change applies to the next launch: stop the capsule, change, resolve, launch.

~/.local/bin/devcapsule project config show

The listing shows every authorization with its state, authorized, recommended-but-missing, required-but-missing or stale, and a SOURCE column naming the document each row comes from: the project's manifest, the lock, or your own checkout record. The review below the listing names the pending decisions, their reasons, and the exact commands for each choice. A recorded refusal is shown as a decision you can keep.

Grant one thing

~/.local/bin/devcapsule project config authorize network host
~/.local/bin/devcapsule project config resolve
~/.local/bin/devcapsule project run

authorize records the exact value and a digest of the recommendation it answers. If the project later changes its recommendation, the record is stale and you are asked again: a committed change never widens access on its own. To review every recommendation and accept all of them at once, interactively:

~/.local/bin/devcapsule project config authorize --all-recommended

It prints every value and reason first and writes only when you press y.

Grant for one run only

~/.local/bin/devcapsule project run --authorize network host

Run-once answers use the same grammar and are never recorded. Everything after -- goes verbatim to docker run; the options the launcher composes itself, such as --network and --memory, are refused with the sanctioned alternative named.

Withdraw

~/.local/bin/devcapsule project config authorize host-x11 false
~/.local/bin/devcapsule project config resolve

A refusal is a recorded decision, kept until you change it. To forget a decision and let the recommendation ask again, config unset its name. Withdrawing does not reconfigure a running capsule; the next launch runs without the access.

The values, in one place

Authorization Values
network host; omitted means the ordinary bridge
docker-daemon host-socket; omitted means no daemon
development-sudo true, false
host-browser true, false
host-x11 true, false; never recommended by a project
claude-code-download, antigravity-download true, false
base-image default for the project's current recommendation, or an exact @sha256: digest

What each opens is on The boundary; the full node list is in Configuration nodes.

Read the source on GitHub Back to top ↑