plimsoll / architecture

THE ARCHITECTURE, IN MOTION

Follow what crosses the boundary.

Code goes in. Data comes back. Permissions and credentials take their own path.
Walk one connection at a time, or click a component to explore everything it sends and receives.

  • The guest is the untrusted code plimsoll runs inside the sandbox; the caller is the program that sends it.
  • The provider is the backend that runs the guest, one per daemon. The menu offers four: docker with runc, docker’s default runtime; docker with gVisor, a stand-in kernel that runs as an ordinary program; WASM (WebAssembly, a portable bytecode that runs inside a host program), where QuickJS, a small JavaScript engine, runs inside the daemon; and E2B, a hosted service that starts a small virtual machine for each run with Firecracker, AWS’s open-source virtual machine monitor.
  • A guest calls your API through the broker, the part of plimsoll that checks each call and adds the credential. From an E2B virtual machine the only way to the broker is the guard, an address on the daemon.
  • Two more appear only in the path built for each: NVIDIA’s OpenShell, whose gateway server creates sandboxes on request, in the path for a session (one sandbox kept open for many calls, which docker keeps too, with the same steps), and Disabled, the default, which runs nothing. Docker Cloud Sandboxes, Docker’s hosted service that runs each sandbox as a small virtual machine, is listed but not drawn.
Interactive walkthroughInvented examples. Nothing is executed.
No API, model, or cloud sandbox calls.

← → to step · Space to play / pause

ONE MAP, DIFFERENT PATHS

Where does my code go?

Click a component to inspect its connections.Arrows show direction · dot marks the current hop
Request / controlPermission / setupAPI callResponseFailure / refusalObservation
Reported isolation tiers (how strong the wall around a run is) rest on the provider, its configuration and behavioural checks; they are never runtime attestation, cryptographic proof from the hardware of what is running.
    01

    Caller ≠ guest

    The caller is the program that submits the RPC. The guest is the untrusted code that plimsoll runs. A model can write that code without being either end of the network connection.

    02

    A pipe ≠ a permission

    The adapter, a provider’s own channel between the guest and the broker, only carries an API call. The shared broker checks whether the call is allowed and makes the outgoing HTTP request. The API then applies its own authorization.

    03

    A result ≠ a guarantee

    Guest code that failed still comes back in a successful RPC response. The isolation tier is evidence the daemon reports. If the client’s own check finds the reported tier missing or weaker than it demanded, the code may already have run.