Apache 2.0 at both ends · MCP-native

A real Linux box for Gemini CLI.

Gemini CLI can already sandbox itself locally. Give it a box instead and YOLO mode runs on a machine you can throw away — one that keeps its state and stays up when your laptop doesn't.

~ / give Gemini CLI its own box
# 1. create a box and write its SSH config
$ containarium create gemini-box
$ containarium ssh-config sync

# 2a. register the box's MCP server with Gemini CLI
$ gemini mcp add gemini-box ssh gemini-box agent-box

# 2b. …or run Gemini CLI inside the box itself
$ containarium connect gemini-box
shell + file tools, scoped to the box

YOLO mode

Local sandboxes protect the laptop. A box replaces it.

Gemini CLI can sandbox tool calls with Seatbelt, Docker, Podman, gVisor or LXC on your machine. That's the right instinct. A remote box takes the same idea further: the agent's whole working environment lives somewhere that isn't your laptop.

YOLO on your laptop

Even sandboxed, the agent's work lives on your machine, stops when you close the lid, and depends on a sandbox profile you maintain per project.

YOLO in a box

A long-lived Linux machine that holds one repo and none of your credentials. It keeps running when you disconnect, and if it goes wrong you delete it.

Open at both ends

Gemini CLI is Apache 2.0. So is Containarium. Self-host the box and the only third party left is the model you chose.

Persistent between sessions

Installed tools, caches and files survive, so the agent doesn't rebuild its environment every time.

GPU when you need it

Working on ML code? Put the box on a GPU host you own — NVIDIA passthrough into the same kind of box.

Connecting

Two ways to point Gemini CLI at a box.

Over MCP

Run the gemini mcp add line above, or add an entry under mcpServers in settings.json with "command": "ssh" and "args": ["gemini-box", "agent-box"]. Gemini CLI gets shell and file tools that act on the box.

Run Gemini CLI inside the box

Open a shell with containarium connect gemini-box, install Gemini CLI with npm, and run it there. Everything it touches stays in the container.

Using another agent? The same box works with Claude Code, Cursor, Cline, Codex CLI, Aider, Goose, OpenHands, or your own agent. Need a GPU in it? That works too.

FAQ

Common questions

How do I run Gemini CLI in a remote sandbox?

Create a Containarium box, run containarium ssh-config sync, then run gemini mcp add gemini-box ssh gemini-box agent-box. Gemini CLI then gets shell and file tools that run on the box. Or SSH into the box and run Gemini CLI there.

Isn't Gemini CLI's built-in sandbox enough?

It isolates tool calls on your own machine, which is valuable. A Containarium box moves the whole environment to a separate machine that keeps its state and holds none of your credentials.

Is it safe to use YOLO mode in a box?

Much safer than on your laptop: the worst case is a broken box you delete. The box still has network access, so use egress allowlists if the agent shouldn't reach arbitrary hosts.

Turn on YOLO mode, somewhere disposable.

Start free on the hosted cloud, or self-host the open source on your own VM.