modify can resize the VM, update host-side metadata, rotate existing secrets, and change the defaults used by future commands while the sandbox stays up.
Supported changes
When a change takes effect depends on the setting:
The default policy applies only changes that can complete without restarting. If a patch contains one restart-required change, microsandbox rejects the whole patch and the old configuration stays intact.
Apply changes
This patch doubles the running sandbox’s CPU and memory and updates a label in the same operation:Set resize limits
Live growth needs capacity reserved when the VM boots. Setmax_cpus and max_memory above the starting allocation when you create a sandbox that may need to scale:
Preview changes
Use a dry run when a patch mixes settings or you are unsure whether a restart is needed:Update settings
Resize CPU and memory
msb ps to see allocation as effective / max, and msb metrics to check real usage before resizing. The apply result reports applied, converging, guest-refused, or failed for each resource so automation can wait for the guest to settle.
Update labels
Labels are host-side metadata, so adding, changing, or removing one is immediate:Set command defaults
Environment and workdir updates require no restart, but they affect only commands started after the patch:Rotate secrets
Rotating the value of an existing secret is live because substitution happens at the host network boundary. Guest code keeps using the same placeholder while microsandbox begins injecting the new value:tls, which needs the same restart or next start. Existing secrets configured with require_tls_identity(false) continue to rotate live over plain HTTP without enabling interception. Removing a secret does not require recreating the sandbox, and removing every TLS-dependent secret leaves interception on. See Secrets for sources, host allow lists, and storage behavior.
Grow the root disk
Grow an owned managed or flat ext4 root without restarting, including roots backed by checkpoint layers:--next-start to defer growth or --restart to use stopped growth.
If the disk grows but guest filesystem expansion fails, the error reports incomplete growth. Retry the same target, or stop and restart to finish recovery. Microsandbox never truncates the disk to roll back; snapshots and compaction stay blocked until recovery completes.
Restart required
These changes take effect after a restart:--next-start saves the desired configuration without touching the running VM. --restart stops and starts the sandbox only when the patch needs it. The default policy does neither and rejects restart-required changes.
Root disk resizing remains conservative: managed and flat OCI disks grow only, tmpfs can grow or shrink at the next boot, and user-supplied disk images are never resized by microsandbox. Named volume and mount capacity is managed where that storage is defined. See Volumes and Images for the storage model.
Reference
For every CLI flag and result state, seemsb modify. The SDK sandbox references expose the same planner and policies for TypeScript, Rust, Python, and Go.