Start a warm worker
1
Prepare the baseline
Create the worker verification script that the snapshot will carry into every worker:Create the preparation script that installs the baseline toolchain:When the command exits,
verify-worker.sh
prepare-worker.sh
agent-base is stopped and ready to snapshot.2
Create and verify the snapshot
3
Launch a clean worker
Restore creates an idle detached sandbox with its security, resource, and lifetime controls applied before boot. It requires an unused name; remove a previous stopped worker explicitly before reusing that name. Start each workload separately with Transfer the committed project tree into the worker:Create a credential-free Git baseline and verify the worker boundary:Start OpenCode after those checks pass:Dedicated restore does not accept rootfs patches such as Create more workers by changing the sandbox name:
msb exec.--copy-dir, so the worker boots first and receives the committed tree afterward. git archive excludes .git, checkout credentials, and untracked files such as a local .env; review the committed tree for secrets before sending it. Initializing a new repository inside the worker preserves useful diff workflows without copying host remotes or credentials. Each transferred or interactive workload sets its own process, file-descriptor, and per-file limits.Each launch receives its own writable layer. Changes made by one worker do not modify the snapshot, the host project, or another worker.This worker uses microsandbox’s default public-internet profile so OpenCode can reach a configured provider. For sensitive projects, replace it with a deny-by-default allowlist for the provider and source hosts you need, and use host-held secrets instead of copying credentials into the worker.
4
Clean up
Remove the prepared sandbox and workers:Remove the reusable snapshot only when you no longer need it:
Refresh the baseline
Installed snapshot members are immutable. To update packages, recreateagent-base, then capture a new member name and use its group-qualified selector for future workers: