mirror of
https://github.com/tiennm99/DocsGPT.git
synced 2026-10-03 11:11:58 +00:00
Run each kernel under a scrubbed environment so untrusted code can never read the host's secrets. A custom 'docsgpt-python' kernelspec launches ipykernel through a wrapper that keeps only what the kernel needs (PATH, HOME, LANG, and the Jupyter runtime/data dirs), dropping API keys, tokens, the database URL, and the gateway token. The app selects this kernel by name via SANDBOX_KERNEL_NAME, so the distinct name is never shadowed by the stock python3 spec. Per-session workspaces are created mode 0700 (defense in depth under the shared uid). The README documents the runner as a single trust domain and points to the Daytona backend for per-tenant isolation.
13 lines
219 B
JSON
13 lines
219 B
JSON
{
|
|
"argv": [
|
|
"/opt/docsgpt/kernel-launch.sh",
|
|
"-f",
|
|
"{connection_file}"
|
|
],
|
|
"display_name": "Python 3 (docsgpt-sandbox, scrubbed env)",
|
|
"language": "python",
|
|
"metadata": {
|
|
"debugger": true
|
|
}
|
|
}
|