Runtime

What is SSH?

SSH (Secure Shell) is the protocol for logging in to a remote computer and running commands over an encrypted connection.

runtime sandbox ssh <id> opens a shell in a Runtime sandbox with no port open to the internet and no key to copy: the CLI makes a key on first use, sends only its public half, and carries the session over Runtime's authenticated API. The same sandbox opens in VS Code or a JetBrains IDE as the host <id>.runtime (SSH and editors).

What the protocol is

RFC 4251, published in January 2006, opens: "The Secure Shell (SSH) Protocol is a protocol for secure remote login and other secure network services over an insecure network." It has three layers:

Layer What it does
Transport Authenticates the server, encrypts and checks every byte
User authentication Proves who the client is: a key, a password, a certificate
Connection Splits the one encrypted tunnel into channels: shells, commands, forwarded ports

The connection layer is why one SSH session can carry a terminal, a file copy and a forwarded port at the same time.

SSH and a sandbox

A server on the internet has to listen on port 22 and defend it. A sandbox does not: Runtime's API authenticates you with your key, then joins your SSH client to the sandbox over one WebSocket, so nothing in the sandbox is reachable from outside. Each login gets a fresh host key, so the entry the CLI writes skips host-key checks on purpose; the connection already goes to the sandbox you named.

  • runtime sandbox ssh <id> -- make test runs one command and exits with its code.
  • runtime sandbox ssh config --install makes ssh, scp and rsync work with <id>.runtime.
  • A sandbox from a custom image gets openssh-server installed on first use.

Sources

Checked 27 September 2026.