paperclip/packages/plugins/sandbox-providers
Nicky Leach c4f62644b0
docs(daytona): document operator enablement for the advisory bwrap wrapper (#10560)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work
> - The Daytona sandbox provider now uses an advisory bwrap wrapper
> - Operators need clear host and image setup for bubblewrap, sudo, and
user namespaces
> - The repo should document that setup, but it should not own
provisioning
> - This pull request adds the operator guidance to the shared sandbox
requirements and the Daytona README
> - The benefit is that operators can enable the wrapper with the same
steps the code expects

## Linked Issues or Issue Description

Refs #10554 and #10541.

## What Changed

- Added an advisory bwrap prerequisites section to
`packages/plugins/sandbox-providers/SANDBOX-REQUIREMENTS.md`.
- Added an operator enablement section to
`packages/plugins/sandbox-providers/daytona/README.md`.
- Documented the install commands, the sudoers rule, the user namespace
setting, and the verification command.
- Kept provisioning out of the repo and left it to the image or snapshot
layer.

## Verification

- `git diff --check origin/master...HEAD`
- `gh pr checks 10560`

## Risks

- Low risk. This change updates documentation only.
- The docs can drift if the host setup changes later.
- Provisioning still lives outside the repo.

## Model Used

- OpenAI Codex, GPT-5, tool use enabled.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used with version and capability
details
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either linked existing issues with `Fixes: #` / `Closes: #`
/ `Refs #` OR described the issue in-PR following the relevant issue
template
- [x] I have not referenced internal or instance-local Paperclip issues
or links
- [x] My branch name describes the change and contains no internal
Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-07-31 11:50:11 -07:00
..
cloudflare perf(sandbox-providers): drop nvm sourcing from exec wrappers (#10443) 2026-07-29 12:40:16 -07:00
daytona docs(daytona): document operator enablement for the advisory bwrap wrapper (#10560) 2026-07-31 11:50:11 -07:00
e2b perf(sandbox-providers): drop nvm sourcing from exec wrappers (#10443) 2026-07-29 12:40:16 -07:00
exe-dev perf(sandbox-providers): drop nvm sourcing from exec wrappers (#10443) 2026-07-29 12:40:16 -07:00
kubernetes feat(sandbox-providers): native providers honor postUploadCommands (Daytona executes; Kubernetes executes) (#10347) 2026-07-27 21:17:16 -07:00
modal perf(sandbox-providers): drop nvm sourcing from exec wrappers (#10443) 2026-07-29 12:40:16 -07:00
novita refactor(environments): make execution environments instance-scoped (#8375) 2026-06-20 09:42:53 -07:00
SANDBOX-REQUIREMENTS.md docs(daytona): document operator enablement for the advisory bwrap wrapper (#10560) 2026-07-31 11:50:11 -07:00