exec_sandbox

Isolates command execution using sandbox engine (commonly bwrap).


What it mitigates


Profilerequired
localtrue
standardfalse
unboundedoptional / omitted

Minimal config

moduleConfig:
  exec_sandbox:
    engine: bwrap
    required: false

Set required: true for environments with strict containment requirements.


Operational checks