container workflow · openai/codex

Secure customer devcontainer

Runs Codex in a project container with bubblewrap and allowlist-based outbound controls.

Type
container workflow
Repository
openai/codex
Readiness
Ready for direct end-user installation and application embedding according to first-party documentation, with authentication required and sandbox, permissions, network policy, and telemetry configuration needing environment-specific review.
Keywords
5

Location

Repository path

.devcontainer/README.md

Invocation

devcontainer up --workspace-folder . --config .devcontainer/devcontainer.secure.json

Setup

Installation / activation

Start explicitly for the stricter customer runtime profile.

Keywords

devcontainersandboxbubblewrapfirewallDocker

Repository context

openai/codex

Apache-2.0 OpenAI coding-agent platform centered on the standalone Codex CLI, with desktop and IDE entry points, Python and TypeScript SDKs, structured and streaming turns, persistent sessions, model-visible tools, and OS-specific sandbox enforcement; it is an alternative or companion to Claude Code rather than a Claude Code extension.

software engineeringcoding agentsdeveloper toolscommand-line interfacesagent SDKssandboxingtool executionobservabilityIDE toolingdesktop applications

Open full repository research