Bubblewrap namespaces
Commands run through Bubblewrap with separate namespaces. System binaries and certificate directories are mounted read-only.
Identity checks protect account changes while sandbox controls keep project commands scoped. Each layer has one clear job and a visible recovery path.
Implementation, not promises
These statements describe the current Beta implementation. Limits are explicit, including the protections Datanode does not yet provide.
Commands run through Bubblewrap with separate namespaces. System binaries and certificate directories are mounted read-only.
The terminal runs as the service account and does not grant root access to the host operating system.
Project files are writable in /workspace. Temporary files and tool caches use isolated runtime directories.
The current sandbox keeps network access available. It is not a separate VM network boundary, so abuse controls and command limits still apply.
Terminal commands and output exist only in the active browser view. Datanode does not persist them in local browser storage or an application command-history table.
Each account can create and restore up to five snapshots. They are not scheduled backups; dependencies, caches and secret environment files are excluded.
Clearing storage removes non-protected project contents. Recovery is possible only from a snapshot created before the clear operation.
Terminal commands have time and resource limits. One persistent worker per workspace is available with restart policies and isolated logs.
Current architecture
Telegram establishes identity. The panel authorizes the account. Commands enter a Bubblewrap sandbox, while project files stay in the account workspace.
Architecture and project details →Security in detail
Inspect each layer to understand what it protects and what state confirms it is working.
One Datanode account remains attached to one Telegram identity.
SelectedUse time-based codes as the primary second confirmation method.
AvailableRequest a six-digit code in the bot when you need another confirmation path.
AvailableRuntime commands and files remain inside the scope assigned to the account.
AvailableContinue exploring
The five product pages describe one system. Move to the next layer or open the real console.