Skip to main content
boxd.sh and Crabbox, the crab mark and wordmark on a black boxd frame Crabbox runs your repository’s commands on a machine that is not your laptop: keep editing locally, send your working tree to a box, stream the output, and get the command’s exit code back. One CLI speaks to eighty providers, and the boxd provider gives every lease an isolated KVM microVM:

doctor, warmup, run, stop against boxd. The waits are cut short; the took markers in the prompt are the real clock.

warmup creates the machine with isolated: true, confirms isolation from inventory before touching the guest, installs a fresh SSH key for that lease over boxd’s authenticated exec stream, starts a dedicated sshd on guest port 2222 behind a boxd TCP forward, and pins the guest’s host key before the first connection. run rsyncs your checkout into /home/boxd/crabbox/<lease>/ and runs the command there. stop destroys the machine and removes the local claim; pass --boxd-delete-on-release=false to stop it instead, so the next run restarts the same disk. Every boxd API key is fenced to one org, so set CRABBOX_BOXD_ORG to that org: without it crabbox refuses machines billed to an org it was not told about, and warmup fails closed.
boxd publishes guest port 8000 through a public HTTPS proxy, isolated or not. Keep secrets and private services off that port.
The provider landed in Crabbox 0.64 on the gRPC API. Releases up to 0.65 fail warmup with SSH host-key verification failed, because the readiness check falls back to port 22 while the forward comes up; the fix is awaiting merge upstream. You don’t have to wait for it: build Crabbox from the pull request’s branch and everything above works today.
Crabbox’s own provider reference covers configuration, ownership fences, and recovery in depth.