Codex CLI¶
pvisor run --safe -- codex
pvisor status --review last
pvisor apply last --path src # 或:pvisor drop last
What --safe does for Codex¶
- Network: the preset matches the
codexexecutable and allows only port 443 onapi.openai.com,chatgpt.com, andab.chatgpt.com. - Workspace: changes go to the stage and are applied after review.
- HOME and
CODEX_HOME: separate private stages; Codex state changes are discarded when the Run ends and never enter the workspace Run Bundle. - Sensitive paths:
.ssh,.gnupg, and private-key files within the view are denied.
Without --safe¶
When you run Codex directly (without --safe), pVisor keeps host environment inheritance to preserve account and routing configuration. Codex state and project writes reach the host directly and cannot be undone with drop. Use --safe or --stage PATH when you need reviewable changes.
Credentials¶
Under --safe, deliver credentials explicitly with --pass-env OPENAI_API_KEY, or configure a Gateway so the trusted side holds the key; see credentials and environment.
In a VM¶
For mandatory networking or fixed Linux userspace:
The image must contain Codex. See libkrun VM for prerequisites and limits.
Fork¶
To keep a stopped run's file state but try a different continuation: