NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #1352 by repository stars
Last release today
07 Oct 2026
Ships fairly regularly
a new release about every 8 days
Nearly every release is documented
notes for 59 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
5 months old
205 releases · first in 2026
One column per month.
Added provider: ascii-box for ASCII Box Ubuntu sandbox SSH leases, using the documented box --json CLI for create/list/status/stop/delete and standard
provider: ascii-box for ASCII Box Ubuntu sandbox SSH leases, using the documented box --json CLI for create/list/status/stop/delete and standard Crabbox SSH sync/run. Thanks @zozo123.--azure-os-disk ephemeral-preview / azure.osDisk: ephemeral-preview for opt-in ephemeral OS disk full caching through Azure Compute API 2025-04-01. Thanks @jwmoss.on-demand-after-* windows bound VM create waits, on-demand retries use separate VM names, and timed-out Spot cleanup is retried from Fleet maintenance.Added --arch arm64 / architecture: arm64 for Linux ARM leases on Azure and AWS, including Azure Dpsv6/Dpdsv6 and AWS Graviton class fallback plus matc
--arch arm64 / architecture: arm64 for Linux ARM leases on Azure and AWS, including Azure Dpsv6/Dpdsv6 and AWS Graviton class fallback plus matching Ubuntu ARM64 image resolution.Nothing published for this version
Added provider: azure-dynamic-sessions for delegated Linux runs through Microsoft Azure Container Apps custom container Dynamic Sessions, including a
provider: azure-dynamic-sessions for delegated Linux runs through Microsoft Azure Container Apps custom container Dynamic Sessions, including a Crabbox runner image, archive sync, streaming commands, local claims, status/list/stop, and provider docs. Thanks @zozo123.crabbox pond peer discovery, bridge, and SSH-mesh support for multi-lease networking, including bridge adapters for Cloudflare, E2B, Islo, Modal, Railway, and Tensorlake.provider: azure can select azure.backend: dynamic-sessions or --azure-backend dynamic-sessions while still reporting the canonical azure-dynamic-sessions provider.crabbox run --provider islo --keep --lease-output <file> returns stable lease metadata and cleanup commands for orchestrators. Thanks @zozo123.crabbox init --detect to scan common Go, Node, Rust, and Makefile project markers and generate a repo-local jobs.detected remote check plus matching preflight tools. Thanks @zozo123.crabbox stop to accept --id <lease> like every other lease command, and updated the stop hint that crabbox run prints so it can be pasted back verbatim. Thanks @edihasaj.run, status, stop, ssh, inspect, screenshot, vnc, webvnc, actions, artifacts, checkpoint, egress) to auto-route --id static_<slug> ids to --provider ssh and restore the original static host from the local lease claim, so static SSH leases no longer require repeating routing flags after crabbox warmup.crabbox init --detect to run nested detected package checks from the package directory and validate generated preflight tools.Nothing published for this version
Nothing published for this version
Added --desktop-env gnome for a GNOME-apps desktop profile on labwc/WayVNC with GNOME Panel taskbars and Xwayland-backed app launches.
--desktop-env gnome for a GNOME-apps desktop profile on labwc/WayVNC with GNOME Panel taskbars and Xwayland-backed app launches.--os/os lease selector with Ubuntu 26.04 as the preferred Linux image where provider catalogs support it, while preserving explicit provider image overrides.capacity.regions fallback with region-scoped managed network names and Azure capacity hints, matching the AWS capacity-routing model.crabbox run --lease-output <file> for reusable delegated-run session JSON, starting with Blacksmith Testbox. Thanks @RomneyDa.&& command chains explain short-circuit behavior, observed phases identify the likely failed phase, and opt-in automatic JUnit discovery can add structured test failures.billingProfile.maxPrice: -1 explicitly in both direct and brokered mode, keeping Crabbox leases on Spot pricing without price-threshold evictions.CRABBOX_AZURE_LOCATION is attempted before the coordinator default.--fresh-pr runs so PR checkout, local patch application, and post-bootstrap SSH port changes work over PowerShell.crabbox run can consume bash-style hydrate env files and reuse hydrated Node/pnpm paths.InvalidInstanceID.NotFound after instance creation and to report parsed AWS XML errors.RunInstances errors are retried instead of failing immediately.Nothing published for this version
Added default artifact manifests for crabbox artifacts publish, plus crabbox artifacts list and crabbox artifacts pull for URL-backed proof handoff wi
crabbox artifacts publish, plus crabbox artifacts list and crabbox artifacts pull for URL-backed proof handoff with size and SHA256 verification.crabbox providers to print the registered provider capability matrix, including targets, backend kind, coordinator mode, aliases, and feature flags.crabbox doctor --from-run <run-id> to load provider, target, class, type, lease, and phase context from recorded run history before diagnostics.crabbox logs --tail, crabbox events --type, crabbox events --phase, and crabbox results --failed-only for faster recorded-run triage.api.cwsandbox.com API host.Nothing published for this version
Added provider: wandb for W&B/CoreWeave Sandbox delegated runs through the native gRPC API. Thanks @zozo123.
provider: wandb for W&B/CoreWeave Sandbox delegated runs through the native gRPC API. Thanks @zozo123.--desktop-env wayland profile using labwc, WayVNC, Wayland browser launch env, and grim screenshots while keeping XFCE as the default desktop.Nothing published for this version
Added provider: upstash-box for delegated Upstash Box sandbox runs through the Box REST API, including archive sync, run, warmup, list, status, stop,
provider: upstash-box for delegated Upstash Box sandbox runs through the Box REST API, including archive sync, run, warmup, list, status, stop, config/env overrides, and provider docs.prlctl is found on standard Mac install paths, and made snapshot fork dry-runs reject non-forkable power-on snapshots consistently.Nothing published for this version
Added crabbox run --emit-proof support for Blacksmith Testbox delegated runs, including bounded local stdout/stderr, timing, and metadata artifacts fo
crabbox run --emit-proof support for Blacksmith Testbox delegated runs, including bounded local stdout/stderr, timing, and metadata artifacts for successful proof runs.provider: docker leases can run Docker-based test suites through the host daemon.docker.io.crabbox cleanup --provider docker support for stale local-container leases.provider: docker stop/release cleanup so host-visible per-lease work directories created for Docker socket pass-through are removed with the lease.hashFiles, secret-expression rejection, and Node 24.x setup on minimal Debian images.prlctl cannot create a template-side linked-clone snapshot implicitly.Nothing published for this version
Added provider: parallels for local and remote Mac Parallels Desktop fleets, including template and snapshot-backed cloning, direct checkpoints, deskt
provider: parallels for local and remote Mac Parallels Desktop fleets, including template and snapshot-backed cloning, direct checkpoints, desktop/VNC forwarding, and Linux, macOS, and Windows guests.provider: runpod for RunPod public TCP SSH leases through the RunPod REST API, including Crabbox sync/run, crabbox ssh, crabbox doctor, and provider docs. Thanks @zozo123.crabbox image promote --fast-snapshot-restore --fsr-az <az> and the AWS developer-image mint wrapper.crabbox image fsr-status and the coordinator Fast Snapshot Restore status route for checking live AWS snapshot/AZ state after promotion.provider: local-container with docker, container, and local-docker aliases for local Linux container leases and optional desktop/browser/WebVNC smoke boxes through Docker-compatible runtimes such as Docker Desktop, OrbStack, and Colima.maxRunDuration with DELETE for the TTL hard cap, install a guest-side idle expiry guard for expired ready/active leases when possible, and crabbox cleanup --provider gcp removes stale local GCP claim files after provider inventory no longer contains the lease.Nothing published for this version
Added provider: exe-dev for exe.dev VM SSH leases through the exe.dev SSH API, including Crabbox sync/run, crabbox ssh, and provider docs.
provider: exe-dev for exe.dev VM SSH leases through the exe.dev SSH API, including Crabbox sync/run, crabbox ssh, and provider docs.crabbox run, status, stop, and list. Thanks @zozo123.crabbox doctor readiness for all built-in providers without creating provider resources.crabbox doctor --provider exe-dev readiness through the exe.dev inventory API without creating VMs.crabbox doctor --provider cloudflare so runner URL, auth, and container bindings are checked without creating a sandbox. Thanks @altaywtf.crabbox doctor --json, provider error classification and hints, direct-check timeout/API/mutation labels, optional --doctor-probe-ssh, and scripts/live-doctor-smoke.sh for maintainer live coverage checks.--slug for crabbox warmup, fresh crabbox run leases, and crabbox checkpoint fork, plus --label for human-readable run history/timing metadata.summary.json.crabbox run when actions.workflow is configured, and keep GitHub self-hosted runner registration behind --github-runner fallback.mac-m* EC2 Mac leases use macOS 15 images while mac2* and legacy mac1.metal continue using launchable macOS 14 images.mac-m* host families.desktop=true label.crabbox run redeploys to use Railway's deployment redeploy mutation so live Docker-image services return the new deployment ID reliably.DescribeHosts responses are recognized as reusable by macOS lifecycle smoke instead of falling through to a new host allocation path.crabbox run --id ... --target macos defaults the irrelevant capacity market to On-Demand instead of failing Spot validation before reaching the lease.** works on older Bash without crossing unintended path segments.crabbox doctor local tool checks so providers that do not use local SSH/rsync do not fail on those tools.Added crabbox capsule for local GitHub Actions failure replay manifests, including capture, inspect, replay, promotion, and documentation for how caps
crabbox capsule for local GitHub Actions failure replay manifests, including capture, inspect, replay, promotion, and documentation for how capsules compose with actions hydration and checkpoints. Thanks @zozo123.crabbox checkpoint snapshot/image creation and forks, including host-pin metadata and On-Demand fork defaults.crabbox checkpoint create --mode native or --strategy image without a coordinator.--take-control for WebVNC portal handoffs so opened browser viewers can automatically become the keyboard and mouse controller after connecting.scripts/macos-image-lifecycle-smoke.sh for guarded AWS EC2 Mac host allocation, source macOS lease boot, WebVNC bridge proof, AMI creation, candidate-image smoke, promotion, promoted-image smoke, cleanup, and durable summary.json evidence.crabbox admin providers identity --provider aws --json so operators know which role or user needs the macOS image lifecycle policy.crabbox admin providers identity, crabbox admin providers policy, and crabbox admin hosts for host lifecycle operations. Existing admin aws-* and admin mac-hosts commands remain compatibility aliases.CRABBOX_HOST_ID / hostId config for host-pinned leases while keeping CRABBOX_AWS_MAC_HOST_ID / aws.macHostId as AWS compatibility aliases.crabbox admin mac-hosts, crabbox admin aws-identity, crabbox admin aws-policy, and crabbox admin aws-policy --mac-hosts for existing AWS macOS operator workflows.--type is explicitly overridden.mac1.metal fallback.CRABBOX_HOST_ID when pinning leases to an allocated host.blocker.reason alias for automation that expects a short blocker reason.pnpm, npm, node, corepack, yarn, and bun entrypoints before syncing and fails with hydration/setup guidance instead of an empty exit 127 tail.crabbox webvnc --open so opened portal links make the lease visible to authenticated org users instead of showing a misleading 404 when CLI auth and browser auth differ.--take-control handoff links so the portal keeps retrying the automatic control claim until the opened viewer is registered as an observer.crabbox screenshot captures the Screen Sharing/VNC framebuffer instead of relying on screencapture from non-interactive SSH sessions.mac-m* Mac host fallback candidates resolve macOS 15 AMIs instead of reusing the earlier Apple silicon macOS 14 AMI query.run, sync, and image smoke commands use the brokered /Users/ec2-user/crabbox work root instead of Linux's /work/crabbox.azureOSDisk when the user explicitly configures it, preserving the coordinator default while keeping new Azure leases checkpointable by default. Thanks @jwmoss.--desktop is requested, while WSL2 leases keep their Windows core and Linux setup paths separate. Thanks @jwmoss.ReleaseHosts results are surfaced instead of reported as released.crabbox commands and the guarded IAM apply helper instead of embedding local binary paths, checkout paths, or manual account-match snippets.blocker.reason aliases are preserved in evidence.hostId, while hostID remains accepted for compatibility.Nothing published for this version
Added crabbox admin lease-audit so operators can compare expired brokered AWS lease records against live cloud instance state and fail automation when
crabbox admin lease-audit so operators can compare expired brokered AWS lease records against live cloud instance state and fail automation when a record still maps to a live instance.crabbox checkpoint native disk-snapshot checkpoints for brokered AWS, Azure, and GCP Linux leases, optional provider image checkpoints via --strategy image, local workspace archives for generic POSIX SSH leases, inspect/list/delete flows, archive restore, and checkpoint forks into fresh leases.crabbox checkpoint list --verify, inspect --verify, and prune --older-than.provider: cloudflare delegated runs for Cloudflare Containers through a Worker runner, including archive sync, warm containers, local claim cleanup, and deployment docs. Thanks @altaywtf.crabbox config show output for Cloudflare runner auth.crabbox list --refresh so local Cloudflare claims can be checked against live runner state on demand.CRABBOX_AWS_ROOT_GB parsing to valid int32 values.crabbox admin lease-audit --fail-on-live so recently terminated AWS instances returned by DescribeInstances do not fail cleanup automation as live resources./tmp/crabbox-*.tgz archive. Thanks @stainlu.modal, tensorlake, and cf can be selected. Thanks @stainlu.private_net arrays from the API no longer break list, doctor, warmup, or reused-run flows. Thanks @muqsitnawaz.crabbox --version and proof metadata report the Go module build version instead of the development fallback. Thanks @stainlu.crabbox actions hydrate --id tbx_... so Blacksmith Testbox IDs skip owned-cloud runner registration instead of failing on GitHub self-hosted-runner permissions.Nothing published for this version
Nothing published for this version
Added provider: modal delegated runs for Modal Sandboxes through the local Modal Python client, including archive sync, env allowlist forwarding, docs
provider: modal delegated runs for Modal Sandboxes through the local Modal Python client, including archive sync, env allowlist forwarding, docs, and no-live-credential tests.crabbox run --full-resync / --fresh-sync to reset stale remote workdirs before syncing, plus --env-helper for reusable profile-backed env wrappers on POSIX SSH leases.crabbox run --script / --script-stdin and a real native Windows --preflight probe.crabbox run --preflight tool probes via --preflight-tools, CRABBOX_PREFLIGHT_TOOLS, and run.preflightTools.--type requests so instance families without nested virtualization fail before leasing with a targeted repair hint.crabbox code on leases that fall back from SSH port 2222 to 22, and improved foreground tunnel startup errors to include SSH failure details.crabbox run --preflight --preflight-tools none so it prints only the workspace summary without running remote probes.crabbox run --preflight so user and cwd diagnostics are always printed alongside configurable tool probes.--script and --env-from-profile uploads so non-ASCII PowerShell source and profile values stay UTF-8 under Windows PowerShell.--env-from-profile uploads so allowed profile values are written relative to the synced workdir and failures include the remote PowerShell error.Added Azure native Windows desktop/VNC and Windows WSL2 lease support, matching the AWS Windows capability boundary. Thanks @jwmoss.
provider: proxmox for direct Proxmox VE Linux QEMU VM leases, including template clone, cloud-init SSH key injection, guest-agent bootstrap, docs, and cleanup support.provider: tensorlake delegated runs for Tensorlake Firecracker sandboxes through the tensorlake CLI, including archive sync, env allowlist forwarding, docs, and live-provider coverage. Thanks @zozo123.crabbox run --preflight, --capture-stderr, automatic failure bundles, env-forwarding summaries, and CRABBOX_PHASE:<name> timing markers for easier live/provider run debugging.crabbox run --keep-on-failure so failed one-shot runs can leave the exact lease available for SSH inspection until idle/TTL expiry.crabbox run --script <file> and --script-stdin so larger remote commands can be uploaded and executed as files instead of quoted shell strings.crabbox run --env-from-profile <file> and repeatable --allow-env <name> for redacted, first-class live-secret forwarding from local profile files.crabbox run --fresh-pr <owner/repo#number> for fresh remote GitHub PR checkouts, with optional --apply-local-patch.crabbox azure login so direct Azure users can persist the active az login subscription, tenant, and location without manually exporting service-principal environment variables. Thanks @galiniliev.azure.network / CRABBOX_AZURE_NETWORK so Azure direct leases can SSH through private VNet addresses when using VPN/private-network access. Thanks @galiniliev.scripts/proxmox-build-template.sh to build a Crabbox-ready Ubuntu 24.04 Proxmox template from a public cloud image. Thanks @VACInc..ignored, .vite, playwright-report, test-results, and local .crabbox log/capture directories, and added top-directory hints for large sync candidates.--capture-stdout / --capture-stderr files for full local streams.--fresh-pr ... --apply-local-patch as the preferred fast path for PR iteration from noisy local checkouts.--env-from-profile values and should use workflow-side secrets.islo ssh --setup host-alias flow for ad-hoc SSH access to Islo sandboxes. Thanks @zozo123.X-Crabbox-Owner and X-Crabbox-Org headers cannot select the authenticated owner/org. Thanks @Hinotoi-agent.use-shared lease users cannot mint lease-side bridge-agent tickets without manage access. Thanks @Hinotoi-agent.env.allow: ["*"] so it no longer forwards every local environment variable to remote commands. Thanks @Hinotoi-agent.Nothing published for this version
Added crabbox job list/run and repo-local jobs: config for named warmup → Actions hydrate → run → cleanup workflows.
crabbox job list/run and repo-local jobs: config for named warmup → Actions hydrate → run → cleanup workflows.scripts/live-smoke.sh so delegated live smoke coverage can run through the shared harness.provider: gcp for Google Cloud Compute Engine Linux SSH leases, including direct ADC auth, brokered service-account auth, class fallback, Spot/on-demand fallback, docs, and cleanup support.crabbox cleanup --provider namespace-devbox to remove Crabbox-owned Namespace SSH snippets and keys.scripts/openclaw-wsl2-tests.sh for one-command OpenClaw full-suite runs on AWS Windows WSL2 Crabbox leases.cloud.google.com/go/compute/apiv1) and project-wide aggregated instance discovery.crabbox media preview and artifacts collect --gif defaults to generate higher-quality 1000px/24fps GIFs with Floyd-Steinberg palette dithering and optional gifsicle optimization. Thanks @obviyus.blacksmith CLI sync start and completion messages.--type requests still use configured zone and Spot-to-on-demand fallback, aliases derive GCP class defaults, explicit brokered tags replace Worker default tags, custom networks and ingress policies get separate SSH firewall rules, and brokered pool views include instances outside the Worker's default zone.crabbox actions hydrate/register so AWS Windows WSL2 leases can use Linux GitHub Actions hydration instead of being rejected as Windows targets, including root-runner and stale apt-list handling.scripts/openclaw-wsl2-tests.sh so follow-up hydrate/run/cleanup commands keep the AWS Windows WSL2 target configuration and warmup failures print captured output.scripts/openclaw-wsl2-tests.sh so dirty-sync package graph changes refresh workspace dependencies before the full OpenClaw test command runs.crabbox run syncs after GitHub Actions hydration so tracked checkout files are not treated as stale remote files before the initial dirty-worktree sync.crabbox run history finish recording to allow large final log payloads enough time to reach the coordinator.crabbox stop --provider namespace-devbox --namespace-delete-on-release <name> deletes without re-preparing SSH.~/.namespace/ssh/crabbox-* snippet and key files.crabbox webvnc daemon start so it starts with a fresh bridge log and waits briefly for the bridge-ready marker before returning.Nothing published for this version
Added crabbox run --capture-stdout and repeatable --download remote=local for binary-safe proof capture without streaming arbitrary bytes into the ter
crabbox run --capture-stdout <path> and repeatable --download remote=local for binary-safe proof capture without streaming arbitrary bytes into the terminal or run-log previews.crabbox desktop terminal for visible terminal smokes, including Sixel-friendly Git-for-Windows mintty launch defaults on native Windows.crabbox desktop record plus desktop terminal --screenshot/--record for one-command visual proof capture, including native Windows MP4 recording through interactive desktop frames.crabbox desktop proof for one-shot visual proof bundles, recorder diagnostics, and direct PR publishing from terminal/proof captures.--capture-stdout and --download requests fail instead of streaming stdout and skipping downloads.crabbox run output capture validation so malformed --download specs, bad download destinations, and bad --capture-stdout paths fail before leasing, syncing, or running remotely.Ctrl-C can terminate slow cleanup after the first signal starts graceful cancellation.crabbox doctor --provider ... so coordinator secret readiness checks only run for managed brokered providers.crabbox desktop terminal --provider ssh -- ... so static SSH command arguments are not consumed as lease IDs.crabbox run --capture-stdout so local capture write failures report as capture errors instead of remote command exits.crabbox doctor --provider azure reports missing Worker secrets and lease creation returns provider_not_configured instead of a coordinator 500.SIGINT/SIGTERM cancel through the CLI context and still run best-effort lease cleanup.desktop launch argument handling so terminal commands such as bash -lc '...' and other quoted GUI launches are passed losslessly.Removed the vulnerable transitive fast-xml-builder Worker dependency by updating fast-xml-parser.
provider: sprites for Sprites microVM SSH leases through the sprite CLI/API, including Crabbox sync/run, crabbox ssh, and live smoke docs.provider: namespace-devbox for Namespace Devbox SSH leases through the devbox CLI, with Crabbox sync/run layered on the returned SSH endpoint.500 responses./home/user./, /home, and /tmp are rejected before sync creates, deletes, or extracts files.crabbox desktop paste for terminal windows so symbol-heavy text falls back to direct typing instead of sending a literal Ctrl+V into xterm-like sessions.fast-xml-builder Worker dependency by updating fast-xml-parser.Nothing published for this version
Nothing published for this version
Added provider: azure for managed Azure Linux and native Windows SSH leases, including direct and brokered provisioning, shared Azure networking, SKU
provider: azure for managed Azure Linux and native Windows SSH leases, including direct and brokered provisioning, shared Azure networking, SKU fallback, Azure docs, and cleanup support. Thanks @jwmoss.provider: e2b for delegated E2B sandbox runs using E2B sandbox REST/envd APIs. Thanks @zozo123.provider: semaphore for direct Semaphore CI testbox leases over SSH. Thanks @loadez.rescue: or native VNC fallback commands when bridges, viewers, browser launches, VNC targets, or input stacks hang.crabbox artifacts commands for desktop screenshots, MP4 recordings, trimmed GIFs, logs, metadata, Mantis/OpenClaw QA templates, and PR-ready publishing through broker-owned artifact storage, AWS S3, or Cloudflare R2.crabbox attach to prefer the coordinator control WebSocket, drain retained backlog pages, and then stream live run output with less polling latency.crabbox run transport chatter by keeping SSH multiplexers alive longer, retrying fallback SSH ports for streaming commands, and batching stdout/stderr preview events into larger coordinator chunks. Thanks @vincentkoc.pipefail before Screen Sharing readiness is installed.crabbox list so a stale admin token no longer blocks normal logged-in users; the CLI now falls back to active user-visible leases instead of failing with 401 unauthorized.--shell payloads with trailing blank whitespace do not produce a spurious shell syntax failure after the remote command succeeds.Added mediated egress commands and browser wiring so Linux desktop leases can proxy selected app traffic through the operator machine via the coordina
crabbox share, crabbox unshare, API access checks, and a portal share control on lease detail pages.egress start --coordinator so live public-route egress starts work when the local default coordinator is Cloudflare Access-protected.run --no-sync timing summaries so they report sync_skipped=true.crabbox run --provider islo uploads the local workspace, uses the correct /workspace/<workdir>, and falls back to chunked exec upload while the archive API returns server errors.Authorization header instead of logging them in URL query strings, while preserving query fallback for older brokers.ec2-user work root, call crabbox-ready by absolute path, and read the generated Screen Sharing password via sudo.Added provider: daytona for Daytona sandbox leases using Daytona's SDK/toolbox for sync and command execution, with short-lived SSH access available t
provider: daytona for Daytona sandbox leases using Daytona's SDK/toolbox for sync and command execution, with short-lived SSH access available through crabbox ssh.daytona login --api-key ... can satisfy Crabbox Daytona auth without duplicating DAYTONA_API_KEY.provider: islo for delegated Islo sandbox runs using the Islo Go SDK.--tailscale-exit-node and --tailscale-exit-node-allow-lan-access so managed Linux leases can route egress through an approved tailnet exit node.crabbox code and per-lease /code/ portal URLs for authenticated code-server access on --code Linux leases.status --json and the portal detail view.crabbox list --provider blacksmith-testbox, with owner-scoped runner rows, stale markers, GitHub Actions links, status badges, stuck filters, detail pages, and copyable local stop commands.mine/system filters and matching detail/code/VNC drilldowns for operator sessions.crabbox desktop launch --webvnc --open to launch a desktop browser/app and immediately bridge the same lease into the WebVNC portal.crabbox webvnc --daemon/--background plus --status/--stop for background WebVNC bridges without tmux.crabbox media preview for creating motion-trimmed GIF previews and optional trimmed MP4 clips from desktop recordings.CRABBOX_CAPACITY_REGIONS across both brokered and direct AWS launches, with the deployed coordinator defaulting to a wider multi-region pool for better headroom.internal/providers/<name> packages while keeping command orchestration and rendering core-owned.--class and --type flags instead of accepting no-op compute settings.&& are present.crabbox webvnc --stop so daemon shutdown terminates the active child bridge, not only the supervisor.win and win (wsl2) labels instead of windows / normal.Added .crabboxignore for repo-local sync-only exclude patterns shared by run and sync-plan.
.crabboxignore for repo-local sync-only exclude patterns shared by run and sync-plan.curl.exe, and retrying empty or partial rootfs downloads instead of reusing a poisoned tarball. Thanks @vincentkoc./work/crabbox while keeping WSL2 sync on the fast rsync path..git worktree that makes sync sanity report every tracked file as deleted.Added --desktop, --browser, and crabbox vnc for optional Linux UI/browser leases, including loopback-only VNC with per-lease passwords and headless br
--desktop, --browser, and crabbox vnc for optional Linux UI/browser leases, including loopback-only VNC with per-lease passwords and headless browser support without a desktop.crabbox webvnc, which bridges a desktop lease into the coordinator portal with short-lived bridge tickets and without exposing the remote VNC port.crabbox vnc.crabbox vnc --open to start the SSH tunnel and launch the local VNC client for managed desktop leases.crabbox desktop launch to open a browser or app inside a visible desktop lease, including native Windows scheduled-task launch for the logged-in console session.crabbox screenshot to save a PNG from a desktop lease without opening a VNC client.--tailscale, --network auto|tailscale|public, brokered OAuth auth-key minting, and non-secret tailnet metadata in status/inspect output.host:5900.crabbox actions --help, crabbox cache --help, crabbox desktop --help, and similar entrypoints exit cleanly.--open no longer launches an OS credential prompt unless --host-managed is passed.crabbox run --help so it prints local usage instead of provisioning a remote lease.crabbox desktop launch --browser on freshly warmed desktop leases by creating the remote workdir before launching the app.tbx_... boxes are stopped instead of being left queued after an upstream workflow error.crabbox run --junit so all-passing JUnit files record results instead of leaving the coordinator run stuck when the failure list is empty.--shell runs so multi-statement PowerShell scripts keep their quotes instead of being re-parsed by a nested PowerShell process.._* sidecar files from default sync manifests so native Windows archives do not transfer invalid TypeScript/package sidecars.crabbox vnc tunnel key paths so macOS Application Support lease keys can be pasted directly into a shell.Added static SSH macOS and Windows targets with --target macos|windows, --windows-mode normal|wsl2, and config/env support for reusable hosts.
--target macos|windows, --windows-mode normal|wsl2, and config/env support for reusable hosts.provider: ssh for macOS or Windows hosts.Added actions.fields config support so repository-specific workflow inputs are sent on every Actions hydration, with CLI -f key=value overrides. Thank
actions.fields config support so repository-specific workflow inputs are sent on every Actions hydration, with CLI -f key=value overrides. Thanks @vincentkoc.npm run docs:check so every top-level CLI command has a matching command page and index entry. Thanks @stainlu.invalid_lease_id failures before command execution. Thanks @vincentkoc.Crabbox 0.3.0 makes brokered runs much easier to observe and debug, adds trusted AWS image lifecycle commands, improves AWS and Blacksmith reliability
Crabbox 0.3.0 makes brokered runs much easier to observe and debug, adds trusted AWS image lifecycle commands, improves AWS and Blacksmith reliability, and tightens coordinator auth boundaries.
crabbox events <run-id> for inspecting the coordinator event log.crabbox attach <run-id> for following recorded events from active runs, plus --after and --limit pagination for crabbox events. Thanks @stainlu.--timing-json for warmup, actions hydrate, and run so provider comparisons can read stable sync, command, total, exit-code, and Actions run timing from one JSON record.--market spot|on-demand to warmup and run so AWS capacity market choice no longer requires environment-only overrides.crabbox image create --id <cbx_id> --name <ami-name> [--wait] for trusted operators to create AWS AMIs from active brokered AWS leases.crabbox image promote <ami-id> for trusted operators to promote an available AMI as the coordinator default for future brokered AWS leases.--wait-timeout and --no-reboot controls.crabbox list output when provider machines carry no active coordinator lease.https://broker-access.example.com for service-token proof and hardened automation.CRABBOX_GITHUB_ALLOWED_TEAMS. Thanks @stainlu.POST /v1/images, GET /v1/images/{ami-id}, and POST /v1/images/{ami-id}/promote.CreateImage and DescribeImages, with Crabbox-owned AMI tags.docs/commands/image.md and linked the image command from the CLI docs, command index, docs site, and source map.npm run docs:check with internal Markdown link validation plus docs-site generation, and wired it into CI.scripts/live-smoke.sh for opt-in AWS, Hetzner, and Blacksmith Testbox live smoke coverage from a real repository checkout.scripts/live-auth-smoke.sh for opt-in live proof that shared tokens cannot call admin routes, admin tokens can, Access edge auth works, and raw Access identity headers are ignored.scripts/deploy-worker-smoke.sh to run the Worker gate, deploy the coordinator, verify public health routes, and optionally include a short AWS lease smoke.RunInstances, while preserving explicit --type failure semantics.awsAMI or CRABBOX_AWS_AMI override is supplied.https://broker.example.com and scoped default broker org/auth settings to openclaw.0600 permissions, and crabbox doctor reports overly broad config permissions.available.run.failed events reliably for coordinator-backed pre-command failures such as lease claim, bootstrap, sync, and remote workdir errors.crabbox logs does not drop lines while run events are being recorded.crabbox run --timing-json output when an Actions-hydrated workspace marker carries a run ID.--type requests as exact instance-type requests; Crabbox now fails clearly instead of silently falling back when the user asked for a specific type.GroupDescription parameter, restoring first-run AWS provisioning in fresh accounts.Library/Application Support.crabbox list --provider blacksmith-testbox --json to return parsed JSON instead of rejecting the shared --json flag.Invalid redirect_uri login failures.Crabbox 0.2.0 hardens the brokered runner path after real AWS and Blacksmith Testbox use: browser login is safer, AWS SSH ingress is no longer world-o
Crabbox 0.2.0 hardens the brokered runner path after real AWS and Blacksmith Testbox use: browser login is safer, AWS SSH ingress is no longer world-open by default, SSH readiness waits for the Crabbox bootstrap marker, and fallback SSH ports are configurable instead of being hidden port-22 magic.
crabbox login, including signed user tokens, polling-based CLI completion, --no-browser, and JSON output support./v1/auth/github/start, /v1/auth/github/callback, and /v1/auth/github/poll.crabbox warmup and crabbox run, enabling one-command Testbox runs without repo YAML or environment variables.ssh.fallbackPorts and CRABBOX_SSH_FALLBACK_PORTS.https://broker.example.com.status and inspect readiness reporting so active leases with a host are not marked ready until SSH and crabbox-ready actually respond.exit status 66.whoami reporting for GitHub browser-login tokens.cbx_... lookups bypassing owner-scoped slug authorization checks.Crabbox 0.1.0 is the first public release: a Go CLI, Cloudflare Worker coordinator, and OpenClaw plugin for leasing fast remote Linux machines, syncin
Crabbox 0.1.0 is the first public release: a Go CLI, Cloudflare Worker coordinator, and OpenClaw plugin for leasing fast remote Linux machines, syncing dirty worktrees, running commands, and releasing or reusing warm boxes safely.
cbx_... for APIs, scripts, paths, SSH keys, provider labels, and compatibility.blue-lobster, swift-hermit, and amber-krill anywhere a lease ID is accepted.30m, while --ttl remains a maximum wall-clock cap./work/crabbox, and cache directories only. Go, Node, pnpm, Docker, databases, and services belong to the repo setup layer.brew install openclaw/tap/crabbox, or download GoReleaser archives for macOS, Linux, and Windows.crabbox run for one-shot remote command execution with automatic acquire, sync, heartbeat, command streaming, result collection, and release.crabbox warmup for reusable kept leases.crabbox status, inspect, list, ssh, stop, and compatibility aliases release, pool list, and machine cleanup.crabbox cleanup for direct-provider cleanup of expired machines.crabbox init to generate .crabbox.yaml, .github/workflows/crabbox.yml, and .agents/skills/crabbox/SKILL.md.crabbox doctor, config, login, logout, and whoami for local setup, broker auth, and identity checks.crabbox admin leases, admin release, and admin delete for trusted operator control of coordinator leases.crabbox usage for estimated runtime and cost reporting by user, org, fleet, or JSON output.crabbox history and logs for coordinator-recorded runs and retained log tails.crabbox results plus run --junit for JUnit summaries.crabbox cache stats, cache warm, and cache purge.crabbox sync-plan to inspect sync candidates, largest files, and largest directories without leasing a machine.--json output on inspection/status/history-style commands where machines or runs need scriptable output.cbx_... lookup precedence.lastTouchedAt, idleTimeoutSeconds, and recomputed expiresAt metadata.run, ssh, cache commands, Actions hydration, and status --wait.status read-only so status polling does not extend a lease forever.--reclaim for intentionally moving a local lease claim between repositories.curl fallback for coordinator transport failures..git, dependency folders, build caches, and other local-only directories..git/crabbox when the remote directory is a Git worktree, keeping the working tree clean.--no-sync runs.known_hosts files to avoid host-key conflicts when cloud providers reuse ephemeral IPs.crabbox actions register to register leased machines as ephemeral GitHub Actions runners.crabbox actions dispatch to dispatch repository workflows.crabbox actions hydrate to register, dispatch, wait for readiness, and capture the hydrated workspace.crabbox run --id <slug> syncs into $GITHUB_WORKSPACE.crabbox stop can ask the waiting Actions job to exit cleanly.crabbox, canonical lease labels, readable slug labels, and profile/class labels.crabbox_run, crabbox_warmup, crabbox_status, crabbox_list, and crabbox_stop tools.crabbox.yaml or .crabbox.yaml.lease.ttl and lease.idleTimeout config.docs/commands/.openclaw/homebrew-tap.go vet, race tests, build, Worker formatting/lint/typecheck/tests/build, and snapshot release checks.toolchain go1.26.2, GOTOOLCHAIN=local in CI, and readonly trimmed builds.85%; current coverage is above that threshold.last_touched_at, expires_at, and idle timeout labels.lease labels shadow real slug labels.crabbox-ready now waits for a Crabbox bootstrap marker and writable work root so base-image tools cannot make machines look ready too early.CRABBOX_CONFIG, keeping isolated login/logout tests out of the normal user config.logs and admin lease actions work after positional IDs, such as crabbox logs run_... --json.actions hydrate retries without optional crabbox_job when an older workflow ref rejects the input.cache warm uses the hydrated GitHub Actions workspace and env handoff when a lease was prepared by actions hydrate.doctor accepts per-lease SSH keys as the default posture and validates explicit CRABBOX_SSH_KEY only when set.Your coding agent can read these notes before it upgrades. Set up the MCP server →