This workshop will take you from "what is nono?" to running your AI coding agent inside a kernel-enforced sandbox, with credentials it can never see.
It's going to be a lot of fun!
- A Mac, Linux machine, or Windows machine with WSL2
- A terminal (macOS Terminal, Linux shell, or a WSL2 shell on Windows)
- An AI coding agent you'd like to sandbox — e.g. Claude Code, GitHub Copilot CLI, or OpenCode (any CLI-based agent works)
- Nothing else installed yet — exercise 00 covers installing nono itself
Note: nono works natively on macOS and Linux. On Windows, it runs inside WSL2 (Windows Subsystem for Linux) — there is no native Windows support, so exercise 00 includes a dedicated WSL2 setup section.
This tutorial is designed to be self-paced to make the most of your time.
The exercises build on each other, so work through them in order. Each exercise has:
- Learning Goals — what you'll know after completing it
- Introduction — the minimum context you need
- Exercise — an overview for experienced users, with collapsible step-by-step instructions for those who want more guidance
Don't be afraid to experiment — that's how you learn!
| # | Exercise | Description |
|---|---|---|
| 00 | Installing Nono | Install nono on macOS and Linux, set up WSL2 on Windows, and run your first sandboxed command |
| 01 | Setting Up Your Profile | Pull a pre-built profile for your AI agent from the registry, then scaffold and extend your own profile from scratch |
| 02 | Credential Injection | Give your agent access to API keys and tokens it can use but never see, using environment and proxy injection |
| 03 | Audit & Rollback | Review a tamper-evident record of everything your agent did, and snapshot/restore any filesystem changes it made |
Head over to the first exercise to begin.
For a quick reference of the most common nono commands, see CHEATSHEET.md.
nono is an open-source sandboxing runtime for AI agents. It uses kernel-level primitives — Landlock on Linux, Seatbelt on macOS, and Landlock inside WSL2 on Windows — to enforce least-privilege sandboxes with zero setup, no daemon, no container, and no VM. Once applied, a sandbox cannot be widened from the inside, not even by nono itself.
Future exercises we're planning:
- Tool Sandboxing — micro-sandboxing the tools your agent calls, like
git,gh, andcurl - Network Policies — allow-listing domains and filtering API calls at Layer 7
- Publishing Packs — building and signing your own profile packs for the nono registry