msb pull
Download an image to the local cache. Shared layers are stored once.msb image pull.
Managed registry settings take precedence over
--insecure, --ca-certs, and supplied credentials. A managed TLS-only entry preserves normal credential lookup.
layered prepares the standard root; flat prepares a complete ext4 base; all prepares both. See flat roots.
Without --materialize, the configured sandbox_defaults.oci.root_disk selects the layout. The built-in default is layered.
msb load
Load a Docker image archive or OCI Image Layout archive into the local microsandbox cache. References are installed and recorded individually; if a later reference fails, earlier completed references remain installed. A cache eviction during a warm import is recovered from the supplied archive.msb image load.
msb save
Save one or more cached images as a Docker-compatible archive or OCI Image Layout archive.msb image save.
Exports preserve image contents, but regenerated layers can change image and layer digests.
msb images
List images in the local cache.msb image ls.
msb image inspect
Show detailed metadata for a cached image (manifest, layers, config).msb rmi
Remove one or more cached images and their layers (layers shared with other images are kept).msb image rm.
msb image prune
Remove cached images that are not used by any sandbox or indexed snapshot, then clean up dangling image artifacts.msb rmi --force can remove a specific reference, but retains backing and cached metadata needed by those dependencies and refuses to remove a reference held by an active operation. Retained metadata files may remain after the last dependency is removed; pruning does not sweep unindexed metadata files.
Prune skips cache entries held by participating pulls, imports, exports, or sandbox creation and continues with unrelated entries. Cleanup commits bounded batches, so an error can leave earlier batches completed. Shared aliases are checked together before removing their metadata file. JSON reports include skipped_in_use, counting busy references, manifests, and layers. Stable lock files remain in the cache. Interrupted cleanup is recovered on a later image prune or removal, with the catalog and exact file identity checked again before deletion.
Concurrent cleanup requires every accessing CLI and SDK to participate in the lease protocol. Older clients can ignore these locks; coordinate a maintenance window when they share the same storage. Ordinary runtime and snapshot formats are unchanged. Pull and sandbox creation report an error if image ownership cannot be persisted in the catalog.