Probe
CRUD
sandbox-docker. Secret bindings reference company secrets rather than embedding secret material in the environment record.
An environment may carry a nullable executionTargetId. A UUID pins runs to one registered execution target; null leaves routing automatic and lets the server choose from the resolved credential kind. The runtime resolver rejects unavailable explicit pins rather than silently changing execution destinations.
For a gVisor-backed sandbox, set driver to sandbox and use a validated config such as:
cloud_auth, a gVisor config does not provision or prove a worker pool: local Docker execution fails closed until the separate worker plane and Gate-B validation exist. See Execution Targets and the deployment guide for the Gate-B worker requirements.
Use project-level GET/PATCH /api/projects/{projectId}/environment only for legacy project environment variables documented in Goals and Projects.