drydock

drydock docs

Operator documentation for drydock: a sandbox for running coding agents (Claude Code, OpenAI Codex, or any OpenAI-compatible model) on your own repos, on macOS, without trusting them. Each task runs in a throwaway VM; the agent never sees your real API key, egress is deny-by-default, and only a diff you approve reaches your code.

New here? Read the Quickstart, install to first task in about a minute.

Pages

Requirements

drydock runs on macOS 26+ on Apple silicon: it's built on Apple's container runtime and won't run anywhere else. It is pre-1.0 alpha software with no third-party security audit; the threat model is the contract.