Apache 2.0 at both ends · MCP-native

A real Linux box for Codex CLI.

Codex already sandboxes its commands on your machine. A box goes one step further: the work happens on a different machine, one that keeps its state and holds none of your credentials.

~ / give Codex CLI its own box
# 1. create a box and write its SSH config
$ containarium create codex-box
$ containarium ssh-config sync

# 2a. register the box's MCP server with Codex
$ codex mcp add codex-box -- ssh codex-box agent-box

# 2b. …or run Codex inside the box itself
$ containarium connect codex-box
shell + file tools, scoped to the box

Blast radius

Codex's sandbox guards your laptop. A box moves the work off it.

Codex CLI ships approval modes and an OS-level sandbox, and they're good defaults. But in full-auto the agent is still running on the machine that holds your SSH keys, your cloud credentials, and every other repo you have checked out.

Full-auto on your laptop

Sandboxed, but on your machine: the same disk, the same network, and a sandbox policy you have to get right for every project. Close the lid and the run stops.

Full-auto in a box

A disposable Linux machine holding one repo. Worst case, you delete it and create another. The run keeps going when your laptop sleeps, and the box is still there tomorrow.

Your key, your box

Codex CLI is Apache 2.0 and runs on your own OpenAI credentials. Self-host the box too and no one else sits between the model and your code.

Persistent between sessions

Toolchains, dependency caches and build output survive, so the next session starts where the last one stopped.

Connecting

Two ways to point Codex at a box.

Over MCP, from config.toml

Codex reads MCP servers from ~/.codex/config.toml. Add a [mcp_servers.codex-box] entry with command = "ssh" and args = ["codex-box", "agent-box"] — or run the codex mcp add line above. Codex gets shell and file tools that act on the box, while Codex itself stays local.

Run Codex inside the box

Open a shell with containarium connect codex-box, install Codex there, and run it. Everything it touches lives in the container, and with --session the terminal survives disconnects.

Using another agent? The same box works with Claude Code, Cursor, Cline, Gemini CLI, Aider, Goose, OpenHands, or your own agent. Need a GPU in it? That works too.

FAQ

Common questions

How do I give Codex CLI a remote sandbox?

Create a Containarium box, run containarium ssh-config sync, then register the box's MCP server with codex mcp add codex-box -- ssh codex-box agent-box. Codex then gets shell and file tools that run on the box. Alternatively, SSH into the box and run Codex there.

Doesn't Codex CLI already have a sandbox?

Yes. Codex restricts what its commands can do on your own machine. A Containarium box is a different layer: the commands run on a separate, disposable Linux machine that holds none of your credentials and keeps its state between sessions.

Does the box persist between Codex sessions?

Yes. A box is a long-lived LXC container or Kubernetes pod, so installed tools, caches and files survive until you delete it.

Can I self-host the environment?

Yes. Containarium is Apache 2.0 and installs on any Ubuntu VM, so Codex's work can stay inside your own network.

Let Codex run on full-auto, somewhere safe.

Start free on the hosted cloud, or self-host the open source on your own VM.