Dispatching Sandboxed Execution to Outrigger via KPP RPC

Living Document Notice
Published 2026-09-15. The evolving architecture and connected notes for this dispatch live in the Stax Digital Garden.

Dispatching Sandboxed Execution to Outrigger via KPP RPC

Dispatching Sandboxed Execution to Outrigger via KPP RPC: Monochromatic ice blue phosphor P7 vector CRT macro showing protocol dispatch node firing an isolated bridge vector into a fortified hexagonal containment jail

Executing untrusted code or complex file conversions directly within application processes introduces severe instability. Granting applications unrestricted access to shell execution invites command injection and data corruption.

Harbormaster exposes a dedicated KPP method to delegate long-running or untrusted jobs to the Outrigger sandbox daemon. Workloads execute inside restricted process boundaries without host privilege escalation.

The Outrigger Dispatch Handshake

Modules submit a task descriptor specifying execution constraints, input paths, and timeout ceilings. Harbormaster checks permissions and invokes the Outrigger runner:

{
  "jsonrpc": "2.0",
  "id": "outrigger-501",
  "method": "kpp.execute_sandbox",
  "params": {
    "task_id": "task-clean-markdown-92",
    "tool": "outrigger.extract",
    "timeout_seconds": 30,
    "max_memory_mb": 256,
    "input_path": "/var/lib/bosun/scratch/input.html",
    "output_path": "/var/lib/bosun/scratch/output.md"
  }

Structured Result Delivery

Outrigger isolates the subprocess, intercepts standard output, and returns a structured status envelope back through Harbormaster:

{
  "jsonrpc": "2.0",
  "id": "outrigger-501",
  "result": {
    "status": "PASS",
    "exit_code": 0,
    "duration_ms": 412,
    "peak_memory_mb": 42,
    "output_bytes": 1842
  }
← Back to Harbormaster API - Blog