Skip to main content
Choose an OCI image with the tools and dependencies your workload needs. Archil supports public and private Linux images built for amd64.

Public images

For a public image, pass baseImage in TypeScript, or base_image in Python and REST, when creating a sandbox:
You can use Docker Hub shorthand, as above, or a full reference such as ghcr.io/acme/agent-runtime:v2. If you omit the image, the sandbox starts from ubuntu:26.04.

Private images

For a private image, build it with your registry credentials first. The SDK waits until the image is ready, then you can pass its ID when creating a sandbox:
Use a registry username and a password or token with pull access. Archil does not store these credentials, so supply them each time you build. Once built, the image is available to sandboxes in your account without registry credentials. See Build Image and Get Image for request options and build failures.

Reusing and updating images

Archil prepares each image for use as a sandbox filesystem. To finish this work before creating sandboxes, build once and reuse the returned image ID. You can also prebuild public images by omitting the registry credentials. If you publish a new version under the same tag, build it again to pick up the change. New sandboxes using that image ID get the latest successful build. While a rebuild is in progress, they can still use the previous successful build. Existing sandboxes keep their original image, including after a restart. To pin an image to a specific version, use a digest reference such as repository@sha256:... instead of a tag.