Sandboxed executionSandboxed AI automation, powered by systemd-run.
Gumpbox runs commands inside the systemd-run sandbox already on every major Linux distro — no extra agents, no third-party daemons, nothing to install.
That makes AI-assisted ops safe, repeatable, and predictable: the right access for each task, with hard lines between read-only inspection, controlled updates, and trusted execution.
Preset
Minimal
No network. Read-only disk. The safe default for inspection, diagnostics, and read-only automation.
Preset
Write
Local writes, no network. For file updates, patches, and controlled maintenance.
Preset
Trusted
Full power, no limits. Reserved for the workflows you explicitly trust.