> ## Documentation Index
> Fetch the complete documentation index at: https://docs.boxd.sh/llms.txt
> Use this file to discover all available pages before exploring further.

# Crabbox

> Run your repository's commands on a remote machine. One command leases an isolated boxd microVM, syncs your checkout, and runs the command inside it.

<img src="https://mintcdn.com/azin/lnfhEuANMoyG_Hvt/images/boxd-x-crabbox.png?fit=max&auto=format&n=lnfhEuANMoyG_Hvt&q=85&s=dfb7f34ed918866205c7596099e5e93e" alt="boxd.sh and Crabbox, the crab mark and wordmark on a black boxd frame" width="2400" height="1640" data-path="images/boxd-x-crabbox.png" />

[Crabbox](https://crabbox.sh) runs your repository's commands on a machine that is not your laptop: keep editing locally, send your working tree to a box, stream the output, and get the command's exit code back. One CLI speaks to eighty providers, and the boxd provider gives every lease an isolated KVM microVM:

```bash theme={"theme":"github-dark"}
export BOXD_API_KEY=bxd_...            # boxd auth keys create crabbox
export CRABBOX_BOXD_ORG=<your-org>     # the org that key is fenced to

crabbox doctor --provider boxd
crabbox warmup --provider boxd --slug testbox
crabbox run --provider boxd --id testbox -- bash -lc 'git --version'
crabbox stop --provider boxd testbox
```

<Frame caption="doctor, warmup, run, stop against boxd. The waits are cut short; the took markers in the prompt are the real clock.">
  <video autoPlay muted loop playsInline src="https://mintcdn.com/azin/iAchAaw8j7tp1Uoy/videos/crabbox-boxd.mp4?fit=max&auto=format&n=iAchAaw8j7tp1Uoy&q=85&s=bf3b77a0921347fecae31907f02ca0b9" data-path="videos/crabbox-boxd.mp4" />
</Frame>

`warmup` creates the machine with `isolated: true`, confirms isolation from inventory before touching the guest, installs a fresh SSH key for that lease over boxd's authenticated exec stream, starts a dedicated sshd on guest port 2222 behind a boxd TCP forward, and pins the guest's host key before the first connection. `run` rsyncs your checkout into `/home/boxd/crabbox/<lease>/` and runs the command there. `stop` destroys the machine and removes the local claim; pass `--boxd-delete-on-release=false` to stop it instead, so the next run restarts the same disk.

Every boxd API key is fenced to one org, so set `CRABBOX_BOXD_ORG` to that org: without it crabbox refuses machines billed to an org it was not told about, and `warmup` fails closed.

<Note>
  boxd publishes guest port 8000 through a public HTTPS proxy, isolated or not. Keep secrets and private services off that port.
</Note>

The provider landed in Crabbox 0.64 on the gRPC API. Releases up to 0.65 fail `warmup` with `SSH host-key verification failed`, because the readiness check falls back to port 22 while the forward comes up; the fix is [awaiting merge upstream](https://github.com/openclaw/crabbox/pull/2519). You don't have to wait for it: build Crabbox from the pull request's branch and everything above works today.

```bash theme={"theme":"github-dark"}
git clone --branch boxd-no-port-22-fallback https://github.com/MichielMAnalytics/crabbox.git
cd crabbox && go build -o ~/.local/bin/crabbox ./cmd/crabbox
```

Crabbox's own [provider reference](https://crabbox.sh/providers/boxd.html) covers configuration, ownership fences, and recovery in depth.
