
doctor, warmup, run, stop against boxd. The waits are cut short; the took markers in the prompt are the real clock.
warmup creates the machine with isolated: true, confirms isolation from inventory before touching the guest, installs a fresh SSH key for that lease over boxd’s authenticated exec stream, starts a dedicated sshd on guest port 2222 behind a boxd TCP forward, and pins the guest’s host key before the first connection. run rsyncs your checkout into /home/boxd/crabbox/<lease>/ and runs the command there. stop destroys the machine and removes the local claim; pass --boxd-delete-on-release=false to stop it instead, so the next run restarts the same disk.
Every boxd API key is fenced to one org, so set CRABBOX_BOXD_ORG to that org: without it crabbox refuses machines billed to an org it was not told about, and warmup fails closed.
boxd publishes guest port 8000 through a public HTTPS proxy, isolated or not. Keep secrets and private services off that port.
warmup with SSH host-key verification failed, because the readiness check falls back to port 22 while the forward comes up; the fix is awaiting merge upstream. You don’t have to wait for it: build Crabbox from the pull request’s branch and everything above works today.