D-103 Start
Install and platforms
Boundlane is one command, boundlane. It runs on Apple Silicon Macs and Linux, and on Windows through WSL 2. The sandbox itself needs a container runtime or a VM, and a Linux kernel that can enforce filesystem rules.
Install the CLI
curl -fsSL https://boundlane.dev/install.sh | shThis installs the latest release. It checks the download's sha256 and puts boundlane in /usr/local/bin when it can write there, or in ~/.local/bin. If that folder is not on your PATH, it adds one line to the profile of your shell: ~/.zshrc for zsh, ~/.bash_profile for bash on a Mac or ~/.bashrc on Linux, or ~/.config/fish/conf.d/boundlane.fish. The line ends with # added by the boundlane installer, is written once, and says which file it went to. Open a new terminal after that. Then it starts boundlane setup, which asks before it installs or changes anything. It does not change your editor or your agent's settings.
| Set this | To |
|---|---|
BOUNDLANE_VERSION=0.1.1 | Install that release instead of the latest. |
BOUNDLANE_INSTALL_DIR=<folder> | Install into that folder. |
BOUNDLANE_NO_MODIFY_PATH=1 | Leave every shell profile alone. The installer prints the export PATH line instead. |
BOUNDLANE_NO_SETUP=1 | Install the command and stop. |
Put them before sh, as in curl -fsSL https://boundlane.dev/install.sh | BOUNDLANE_NO_SETUP=1 sh. Check what you got:
boundlane version ■ Version
✓ Boundlane <version>That is this Boundlane release. The runtime release line it was built against is what boundlane doctor checks. See Versions and upgrades.
The sandbox runtime
The sandbox is OpenShell, an open source runtime. Boundlane drives it and does not replace any part of it. boundlane setup offers to install the pinned release, 0.1.2, with the upstream installer, and shows the command first. On a Mac that installer needs Homebrew, which also keeps the gateway running. Without Homebrew, setup says so and offers Homebrew's official installer first, showing its command; it asks for your password. On Linux the installer runs the gateway as a systemd user service, and setup restarts it there. To install it yourself, use the upstream packages for that release, then check the machine:
boundlane doctordoctor checks the runtime version, the gateway connection, the sandbox driver, the image builder, the policy prover, and the settings that would weaken a sandbox. With --fix it removes those settings. It changes nothing else, and only after it says what it will change. It does not configure colima. When the gateway is down because Docker Desktop, colima, or another container runtime is stopped, doctor names it and boundlane setup starts it; see Container runtimes. Each failure and what to do about it is in Troubleshooting.
Platforms
| Machine | Sandbox runs in | Where isolation happens |
|---|---|---|
| Mac with Apple Silicon | Docker Desktop, colima, or the MicroVM driver | Inside the Linux VM that runtime starts. macOS has no Landlock, so the rules apply to the VM's kernel. |
| Linux | Docker Engine 28 or later, or Podman 5 | On the host kernel, in a separate network namespace. |
| Windows | WSL 2, with one of the Linux runtimes inside it | Inside WSL 2. Upstream marks Windows experimental, and so do we. |
Intel Macs are not on the list. Native Windows enforcement is not on the list. No special hardware is needed anywhere.
Kernel requirement
Filesystem rules are enforced with Landlock, which needs ABI version 3 or later. Boundlane sets the policy so that a sandbox does not start without it. The upstream default would start the sandbox anyway and log a warning; we prefer a clear failure to a quiet hole.
On a Mac, this is about the Linux VM's kernel, not macOS. If a runtime's kernel cannot enforce the rules, the sandbox does not start, and boundlane run stops before the agent does.
Image builder
Each agent runs from an image built on your machine. Boundlane uses Docker if it is installed, then Podman. It needs one of them even when sandboxes run on the MicroVM driver. See Agent images.
Notes for Macs
- Docker Desktop is the path the upstream instructions describe.
- colima works once the gateway is told where colima's socket is. Sandboxes run inside colima's VM, so they reach the gateway through
host.docker.internal. Both are gateway settings you add once. See Troubleshooting. - The MicroVM driver runs each sandbox in its own lightweight VM through Hypervisor.framework. It looks for the agent image in your local Docker or Podman before it pulls one.
What the install writes
The binary, and two folders the first time you run it: ~/.config/boundlane for state and a team sign-in, and ~/.cache/boundlane for compiled policies, saved logs, and staged changes. Model keys are not in either. They live in the runtime's own credential store. The full list is in the CLI reference.
Remove it
Stop any running sandboxes with boundlane stop, remove stored keys with boundlane key remove <agent>, then delete the binary and the two folders above. Your repositories are not touched; Boundlane never writes to them except through boundlane apply.