Boundlane Sheet D-302 / Enroll machines

D-302 Team

Enroll machines

A developer signs their machine in to the team once. From then on, every sandbox on that machine starts from the team's signed policy, and the machine reports what it runs.

Command: boundlane loginTeam and License

Sign in

boundlane login
Example output
open      http://127.0.0.1:8787/device
code      KQXT-MRWD
waiting   approve it in the browser
signed in li@acme.dev, team acme
machine   li-x1, enrolled
policy    acme r14, verified and cached
  1. Open the page and enter the code. The CLI waits. Nothing is typed into the terminal but the command.

  2. Approve in the browser, signed in as yourself. The code ties this machine to your account.

  3. The CLI receives the team's current policy, checks its signature, and caches it.

The address is your team's console. On one machine, boundlane server runs it at http://127.0.0.1:8787, and boundlane login --server <url> points at another. The machine is named after its host name. On License, sign-in goes through your identity provider. See License plan.

What the machine keeps

One file, ~/.config/boundlane/enrollment.json, readable only by you:

  • The machine's token. It never leaves the machine except to authenticate to the control plane.
  • The control plane's public signing key, received at sign-in. Every later policy is checked against it.
  • The latest signed policy and its revision number.

No model keys, no source, no logs.

What changes after sign-in

FreeEnrolled
Policydeveloper-default plus boundlane.yamlThe team's signed policy
Project fileAdds hostsNot used. run says so.
run --policy <file>Uses that fileRefused
ApprovalsIn the terminalIn the console
DecisionsOn this machineAlso in the console, through the forwarder

If the team has not published a policy yet, run refuses to start a sandbox rather than fall back to the Free default.

Check the machine

boundlane status
Example output
account   li@acme.dev, member, team acme
machine   li-x1
server    http://127.0.0.1:8787
console   http://127.0.0.1:8787/console
policy    r14, verified

If the control plane cannot be reached, status says so, checks the cached policy's signature again, and keeps using it.

What the machine reports

When the machine checks in, it reports the sandbox runtime version, the sandbox driver, and the policy revision it holds. The console lists every machine with those three values and when it last checked in. The machine always makes the call. The control plane never connects to it.

Sign out

boundlane logout

Forgets the sign-in and the cached policy. The machine goes back to the Free plan for the next run. A sandbox that is already running keeps the policy it started with.