Sandbox CLI
Sandbox and workspace commands in Tachyonic 0.18.0 and later.
Use the same tachyonic binary for sandboxes and security runtimes. These
sandbox and workspace commands require 0.18.0 or later. Run
tachyonic --version and tachyonic <command> --help for your installed version.
Global options
tachyonic [--json] [--api-url <origin>] <command>--jsonselects machine-readable output for sandbox and workspace commands.--api-urloverrides the API origin. The default ishttps://api.tachyonic.sh.TACHYONIC_API_URLsets that origin through the environment.TACHYONIC_API_KEYsupplies a workspace key in-process, ahead of stored login.
Never include a credential in an origin URL or command argument. For interactive
login use tachyonic login; to store an existing key use
tachyonic login --with-key, which reads stdin or a hidden prompt.
Sandbox commands
The alias sb is equivalent to sandbox. Replace sb_example with a sandbox
ID returned by create.
| Command | Purpose |
|---|---|
sandbox create | Create a sandbox and wait for readiness |
sandbox ls | List active sandboxes; --all includes ended ones |
sandbox get sb_example | Read state, placement, digests, and usage |
sandbox resume sb_example | Resume a paused sandbox when matching capacity exists |
sandbox exec sb_example -- command | Stream a command's stdout and stderr |
sandbox shell sb_example | Open an interactive PTY |
sandbox cp ./file sb_example:/workspace/file | Copy a file into the sandbox |
sandbox cp sb_example:/workspace/file ./file | Copy a file out |
sandbox events sb_example | Read lifecycle events; --follow streams them |
sandbox usage sb_example | Read metered quantities, rates, and estimated cost |
sandbox rm sb_example | Stop the sandbox; records and events remain |
Create options
| Flag | Purpose |
|---|---|
--image <image> | Image; defaults to the tachyonic.sh/base alias |
--region <region> | Region returned by tachyonic regions |
--provider <provider> | Pin the provider where supported |
--isolation <value> | container, microvm, or any; explicit requirements are never downgraded |
--cpu <number> | Allocated vCPUs |
--memory <size> | Memory, such as 512m or 1g |
--disk <GiB> | Ephemeral disk size |
--budget <duration> | Wall-clock limit, such as 30m |
--budget-usd <amount> | Dollar limit |
--egress <policy> | allowlist, open, or none |
--allow <host> | Additional permitted host; repeatable |
--name <name> | Job label |
--wait <duration> | Readiness wait; default is ten minutes |
--no-wait | Return after acceptance without waiting for readiness |
--on-interruption <value> | resume or restart where the chosen pool supports it |
An option in the CLI does not establish capacity or support in every pool.
Check the region response and sandbox record. Use --env only for non-secret
configuration; its values are command arguments.
Exec and shell
tachyonic sandbox exec -i sb_example --cwd /workspace --timeout 5m -- python3 script.py
tachyonic sandbox shell sb_example --cwd /workspaceexec --env is repeatable non-secret command configuration. shell --command
selects a command instead of the default shell. Exec and shell return the remote
command's exit code, which can overlap with CLI error codes.
Workspace commands
| Command | Purpose |
|---|---|
whoami | Show the current workspace, organization, and scopes |
regions | List regions and sandbox pools |
keys ls | List accessible key metadata; a key sees only itself |
usage | Show organization usage for the current month |
usage --month YYYY-MM | Read another month |
budget get | Read workspace budget and spend |
budget set --monthly 200 --action stop | Set a monthly limit; requires budget:write |
budget rm | Remove a budget; requires budget:write |
logout | Remove local login and revoke a device-created key |
logout --keep-key | Remove local login while keeping the key valid |
Device-login keys cannot manage budgets. Console-created keys retain their configured scopes; clearing a stored console key does not revoke it remotely.
Exit codes
| Code | Meaning |
|---|---|
0 | Success |
1 | The command failed |
2 | Invalid arguments or request |
69 | API unavailable or unreachable |
75 | Capacity or concurrency unavailable; retry later |
77 | Login, scope, budget, or allowance requires action |
See the complete public CLI reference for runtimes and verification.