Self-hosting
Previews and shells on a server
How project previews and shells are served securely when OneDrop runs on a server.
How project previews and shells are served securely when OneDrop runs on a server.
On a laptop, the browser reaches each sandbox directly on 127.0.0.1. On a server, sandboxes still listen only on 127.0.0.1, and Caddy serves them at public HTTPS addresses:
| Address | Goes to |
|---|---|
preview-<sandbox id>.<domain> | The project’s app, through the sandbox’s host proxy |
shell-<sandbox id>.<domain> | The project’s web terminal |
Turn this on by setting SANDBOX_GATEWAY_DOMAIN to your domain. The install script does this for you.
laravel-session, say) can’t clash with it/projects/<id>/open/<kind>, which hands the browser a short-lived token for that one address. The address trades it for its own zap_gateway cookie, valid for 12 hoursX-Zap-Upstream header sent by the browser, so a client can’t choose where requests gopreview-<id> and shell-<id> hosts of sandboxes that exist/sandbox-gateway/* endpoints are blocked on the public site; only Caddy calls them| Variable | Description |
|---|---|
SANDBOX_GATEWAY_DOMAIN | Domain for preview and shell addresses. Empty on a laptop. |
SANDBOX_CALLBACK_URL | How sandboxes report agent events. On a server, the public APP_URL. |
SANDBOX_DOCKER_RUNTIME | Optional container runtime, such as runsc for gVisor isolation. |
AUTH_VERIFY_EMAIL | Set to false when the server can’t send email; new accounts are marked verified. |