exec_sandbox

Isolates command execution using sandbox engine (commonly bwrap).


What it mitigates


Profilerequired
localtrue
standardfalse
unboundedoptional / omitted

Minimal config

moduleConfig:
  exec_sandbox:
    engine: bwrap
    required: false
    childPolicy:
      network: deny  # inherit | deny

Set required: true for environments with strict containment requirements.


Operational checks