Reference
Troubleshooting Sessionboxer: Docker, certificates, macOS
Docker permission errors, a Sandbox image that will not pull, self-signed certificate errors behind a proxy, unreachable private addresses, and what differs on macOS.
- "docker: permission denied" when starting: add your user to the
dockergroup (sudo usermod -aG docker $USER, then log out and in). - Session goes to error with "cannot pull ghcr.io/…": the Sandbox image for this version is still downloading (watch the Control Plane log) or the machine cannot reach ghcr.io;
npm run build:imagebuilds it locally instead. "sandbox image … not found; runnpm run build:image" appears only with a customSESSIONBOXER_IMAGE. - "method not found: _sessionboxer/…" after updating Sessionboxer: the box still runs the previous version's internals. Stop and Resume the session; the current build is copied into the box on every start, so
npm run build:imageis only needed when the image itself changes (system packages, agent CLIs). - Code pane says "openvscode-server is not installed in this Sandbox image": run
npm run build:image, then Stop → Resume the session. - Devin session fails right after creation: Devin occasionally times out while loading team settings on a cold start. Sessionboxer retries a few times; if it still fails, Resume the session.
cannot fetch https://github.com/…: self-signed certificate in certificate chainin the Control Plane log (downloadingfrpc,cloudflaredorgh): the same proxy, and the Control Plane did not find its CA — see Global settings → Environment → TLS certificates, paste the PEM there (applies at once, no restart), or put the binary in~/.sessionboxer/bin/yourself.- "self signed certificate in certificate chain" from an MCP server or the agent inside a box: your machine goes through a TLS-inspecting proxy (Cloudflare WARP, Zscaler…). Check Global settings → Environment → TLS certificates lists its CA (paste the PEM there if not), then Stop → Resume the session. The same error from
curlornpmduringnpm run build:imagemeans that CA was not found on this machine:build:imageprints the ones it uses; paste the PEM in that Settings section and build again. - Docker inside the box can't pull images: Docker Hub rate-limits anonymous pulls per IP; log in with
docker loginin the box's Terminal or pull from another registry. - "No route to host" / "Host is unreachable" for a private address from a Docker-enabled session while public sites work and your machine reaches it: the address falls inside a network the box's own Docker daemon owns (
192.168.240.0/20by default,172.17.0.0/16when the setting is empty). Check withdocker exec sbx-<session id> docker network inspect bridge -f '{{range .IPAM.Config}}{{.Subnet}}{{end}}'(anddocker network lsinside the box forcomposenetworks), then set Global settings → Addresses for Docker inside Sandboxes to a block outside anything you reach and create the session again — see Docker inside sessions. If the outersessionboxernetwork overlaps instead (docker network inspect sessionboxer), move Docker's own pools in/etc/docker/daemon.json(bip,default-address-pools) and restart Docker. A reply that gets as far as certificate verify failed is not this problem but the CA one above. With Cloudflare WARP on Linux, Cloudflare also documents lowering the Docker bridge MTU (1500 → 1420) when large transfers hang.
macOS
Sessionboxer talks to each box over the private sessionboxer Docker network. On macOS the Docker daemon runs in a VM, and only OrbStack routes container addresses to the host. Sessionboxer checks which daemon it is talking to at startup (the sandbox reach: ip|localhost line in the log):
- OrbStack: boxes are reached by container address, exactly as on Linux.
- Docker Desktop, Colima, …: each box additionally publishes its two internal ports (daemon and desktop) on
127.0.0.1with random host ports, and the server dials those. Nothing is exposed beyond your machine.SESSIONBOXER_SANDBOX_REACH=ipor=localhostoverrides the detection (for exampleipwith Docker Desktop + docker-mac-net-connect).
Other notes: Colima does not create /var/run/docker.sock, so export DOCKER_HOST=unix://$HOME/.colima/default/docker.sock before npm start. Sysbox is Linux-only, so Docker inside the Sandbox always uses the privileged mode on macOS (the box is still inside the Docker VM, not your Mac). The sandbox image builds natively on Apple Silicon (arm64).
This chapter is generated from docs/GUIDE.md in the Sessionboxer repository. Found a mistake? Open an issue.