Repository navigation
docs(sandboxes): add Orca SSH integration page #26282
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Draft
mdelapenya
wants to merge
6
commits into
docker:main
Choose a base branch
from
mdelapenya:docs-sandboxes-orca-integration
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
+112
−33
Draft
Changes from 1 commit
Commits
Show all changes
6 commits
Select commit
Hold shift + click to select a range
1d73ec2
docs(sandboxes): add Orca SSH integration page
mdelapenya 2ccf46d
docs(sandboxes): install build-essential in the Orca prerequisites
mdelapenya 1066e98
docs(sandboxes): install build-essential in the T3 Code prerequisites
mdelapenya 283f953
docs(sandboxes): describe the toolchain as part of the templates
mdelapenya 006b5bb
docs(sandboxes): correct what T3 Code needs from a sandbox
mdelapenya a068a3d
docs(sandboxes): note that the t3code kit installs libatomic1
mdelapenya File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Next
Next commit
docs(sandboxes): add Orca SSH integration page
Orca treats a sandbox as an ordinary SSH host and installs its own relay there. Document the target fields, the C++ compiler its remote terminals need, and how agent selection and credentials work. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Signed-off-by: Manuel de la Peña <manuel.delapena@docker.com>
- Loading branch information
commit 1d73ec2ddb6c2339eb3f7ddec26d6e069ae74c0d
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,90 @@ | ||
| --- | ||
| title: Connect Orca to a sandbox | ||
| linkTitle: Orca | ||
| weight: 60 | ||
| description: Run Orca's coding agents and terminals against a Docker Sandbox over SSH. | ||
| keywords: docker sandboxes, orca, remote ssh, coding agents, remote development, sbx | ||
| --- | ||
|
|
||
| {{< summary-bar feature_name="Docker Sandboxes SSH" >}} | ||
|
|
||
| These connection instructions use a local sandbox. For cloud SSH setup, see | ||
| [Connect with SSH](../cloud/usage.md#connect-with-ssh). | ||
|
|
||
| Orca runs coding agents in parallel, each in its own git worktree. Orca has no | ||
| dedicated Docker Sandboxes integration: it treats the sandbox as an ordinary | ||
| SSH host, installs a small relay inside it, and runs agents, terminals, and git | ||
| there while the editor and diff views stay on your host. | ||
|
|
||
| ## Prerequisites | ||
|
|
||
| - SSH access set up. See [Editor and app integrations](_index.md#enable-ssh-access). | ||
| - Orca installed. | ||
|
|
||
| Orca's remote terminals need `node-pty`, which ships prebuilt binaries only for | ||
| macOS and Windows. On a Linux sandbox it compiles from source, and the build | ||
| needs a C++ compiler. Agent templates ship Node.js, `make`, and `python3`, but | ||
| no compiler, so install one before you connect: | ||
|
|
||
| ```console | ||
| $ sbx exec <sandbox> -- sudo apt-get update | ||
| $ sbx exec <sandbox> -- sudo DEBIAN_FRONTEND=noninteractive apt-get install -y g++ | ||
| ``` | ||
|
|
||
| Verify the compiler is in place: | ||
|
|
||
| ```console | ||
| $ sbx exec <sandbox> -- sh -lc 'command -v g++ && command -v make && command -v python3' | ||
| ``` | ||
|
|
||
| Without a compiler, Orca still connects and you keep files, git, and the | ||
| editor, but remote terminals don't start. A manual install lasts only until the | ||
| sandbox is recreated. For a setup that persists, recreate the sandbox with a | ||
| [kit](../customize/kits-v2.md) or a custom | ||
| [template](/manuals/ai/sandboxes/customize/author/base-images.md). | ||
|
|
||
| ## Connect | ||
|
|
||
| Confirm that you can connect to the sandbox from a terminal: | ||
|
|
||
| ```console | ||
| $ ssh demo.sbx | ||
| ``` | ||
|
|
||
| 1. In Orca, open **Settings → SSH** and select **Add Target**. | ||
| 2. Enter the sandbox hostname, such as `demo.sbx`, as the host, and | ||
| `_default_user_` as the username. Keep the default port and leave the | ||
| identity file empty. | ||
| 3. Select **Test** to check the connection, then **Save**. | ||
| 4. Create a worktree and choose the sandbox under **Run on**. | ||
|
|
||
| The first connection installs Orca's relay inside the sandbox, so it can take a | ||
| moment. Later connections are faster. | ||
|
|
||
| `_default_user_` is the reserved username in the managed SSH configuration that | ||
| `sbx setup ssh` writes. It tells the daemon to run as the sandbox image's | ||
| default user. Any other username is taken literally as an in-sandbox user. | ||
|
|
||
| ## Run an agent | ||
|
|
||
| Orca launches the agent you select for a worktree; a sandbox doesn't start one | ||
| for you. Orca pre-fills each agent's permission-bypass flag for new launches, | ||
| such as `--dangerously-skip-permissions` for Claude Code, which is how | ||
| `sbx run` starts the same agents. | ||
|
|
||
| Orca only offers agents it finds installed on the host it connects to, so | ||
| create the sandbox with the agent you plan to drive: | ||
|
|
||
| ```console | ||
| $ sbx create --name demo claude . | ||
| ``` | ||
|
|
||
| Credentials stay on your host. If you store them as | ||
| [credentials](../configuration/credentials.md), the sandbox proxy injects them | ||
| when the agent makes a request, so the agent authenticates without the value | ||
| ever entering the sandbox. | ||
|
|
||
| ## Related | ||
|
|
||
| - [Editor and app integrations](_index.md) — how SSH access works and how to | ||
| set it up | ||
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.