Skip to main content

msb pull

Download an image to the local cache. Shared layers are stored once.
Expanded form: msb image pull. Managed registry settings take precedence over --insecure, --ca-certs, and supplied credentials. A managed TLS-only entry preserves normal credential lookup. layered prepares the standard root; flat prepares a complete ext4 base; all prepares both. See flat roots. Without --materialize, the configured sandbox_defaults.oci.root_disk selects the layout. The built-in default is layered.
Pre-pulling is useful when you want sandbox creation to be instant. Without a pre-pull, the first Sandbox.create with a new image will block on the download.

msb load

Load a Docker image archive or OCI Image Layout archive into the local microsandbox cache. References are installed and recorded individually; if a later reference fails, earlier completed references remain installed. A cache eviction during a warm import is recovered from the supplied archive.
Expanded form: msb image load.

msb save

Save one or more cached images as a Docker-compatible archive or OCI Image Layout archive.
Expanded form: msb image save. Exports preserve image contents, but regenerated layers can change image and layer digests.

msb images

List images in the local cache.
Expanded form: msb image ls.

msb image inspect

Show detailed metadata for a cached image (manifest, layers, config).

msb rmi

Remove one or more cached images and their layers (layers shared with other images are kept).
Expanded form: msb image rm.

msb image prune

Remove cached images that are not used by any sandbox or indexed snapshot, then clean up dangling image artifacts.
Images referenced by sandboxes or indexed snapshots are kept. msb rmi --force can remove a specific reference, but retains backing and cached metadata needed by those dependencies and refuses to remove a reference held by an active operation. Retained metadata files may remain after the last dependency is removed; pruning does not sweep unindexed metadata files. Prune skips cache entries held by participating pulls, imports, exports, or sandbox creation and continues with unrelated entries. Cleanup commits bounded batches, so an error can leave earlier batches completed. Shared aliases are checked together before removing their metadata file. JSON reports include skipped_in_use, counting busy references, manifests, and layers. Stable lock files remain in the cache. Interrupted cleanup is recovered on a later image prune or removal, with the catalog and exact file identity checked again before deletion. Concurrent cleanup requires every accessing CLI and SDK to participate in the lease protocol. Older clients can ignore these locks; coordinate a maintenance window when they share the same storage. Ordinary runtime and snapshot formats are unchanged. Pull and sandbox creation report an error if image ownership cannot be persisted in the catalog.

msb registry

See Registry commands for login, logout, and stored credentials.