D-302 Team
Enroll machines
A developer signs their machine in to the team once. From then on, every sandbox on that machine starts from the team's signed policy, and the machine reports what it runs.
Sign in
boundlane loginopen http://127.0.0.1:8787/device
code KQXT-MRWD
waiting approve it in the browser
signed in li@acme.dev, team acme
machine li-x1, enrolled
policy acme r14, verified and cachedOpen the page and enter the code. The CLI waits. Nothing is typed into the terminal but the command.
Approve in the browser, signed in as yourself. The code ties this machine to your account.
The CLI receives the team's current policy, checks its signature, and caches it.
The address is your team's console. On one machine, boundlane server runs it at http://127.0.0.1:8787, and boundlane login --server <url> points at another. The machine is named after its host name. On License, sign-in goes through your identity provider. See License plan.
What the machine keeps
One file, ~/.config/boundlane/enrollment.json, readable only by you:
- The machine's token. It never leaves the machine except to authenticate to the control plane.
- The control plane's public signing key, received at sign-in. Every later policy is checked against it.
- The latest signed policy and its revision number.
No model keys, no source, no logs.
What changes after sign-in
| Free | Enrolled | |
|---|---|---|
| Policy | developer-default plus boundlane.yaml | The team's signed policy |
| Project file | Adds hosts | Not used. run says so. |
run --policy <file> | Uses that file | Refused |
| Approvals | In the terminal | In the console |
| Decisions | On this machine | Also in the console, through the forwarder |
If the team has not published a policy yet, run refuses to start a sandbox rather than fall back to the Free default.
Check the machine
boundlane statusaccount li@acme.dev, member, team acme
machine li-x1
server http://127.0.0.1:8787
console http://127.0.0.1:8787/console
policy r14, verifiedIf the control plane cannot be reached, status says so, checks the cached policy's signature again, and keeps using it.
What the machine reports
When the machine checks in, it reports the sandbox runtime version, the sandbox driver, and the policy revision it holds. The console lists every machine with those three values and when it last checked in. The machine always makes the call. The control plane never connects to it.
Sign out
boundlane logoutForgets the sign-in and the cached policy. The machine goes back to the Free plan for the next run. A sandbox that is already running keeps the policy it started with.