exec works even when a sandbox has networking fully disabled.
Run the image default workload
Sandbox creation is boot-only: configuring an image, ENTRYPOINT, or CMD does not execute that workload. Use the default-workload methods when you want the SDK to resolve the effective OCIENTRYPOINT + CMD and run it. A configured CMD override replaces the image CMD while preserving the effective entrypoint. If neither field supplies an executable, these methods return the typed NoDefaultCommand error instead of falling back to a shell.
exec_default_stream, execDefaultStream, and ExecDefaultStream. Interactive variants are attach_default, attachDefault, and AttachDefault. Literal exec and attach continue to ignore ENTRYPOINT and CMD.
Execute a command
Run a command and wait for it to complete. You get back the exit code, stdout, and stderr.Execution options
These options apply to a single execution and don’t change the sandbox’s defaults.Shell commands
Run a command through the sandbox’s configured shell (defaults to/bin/sh). Useful for pipelines, redirects, and other shell syntax that exec doesn’t interpret.
Stream output
Ruby currently collects command output with
exec and shell. It does not expose streaming handles, interactive attach, or session IDs.Interactive attach
Bridges your terminal directly to a process inside the sandbox for a fully interactive PTY session. Useful for debugging, running REPLs, or anything that expects a real terminal.Write stdin
TypeScript, Rust, Python, and Ruby can pass input bytes with the command. Ruby does not expose a streaming stdin writer; Go uses the pipe API shown below.stdin_pipe and write bytes to it. Combined with tty: true, this lets you drive interactive processes programmatically.
Session IDs
Each streaming exec creates a session ID that you can use to correlate stream events and persisted log entries.Reference
For exact execution APIs, see TypeScript, Rust, Python, or Go. For command-line execution, seemsb run and msb exec.