Skip to main content
Manage saved snapshots with msb snap. See the snapshot guide for workflows. Local selectors accept a group head, group:member, an unambiguous ID or digest, or an artifact path. On cloud, use the snapshot reference returned by the command.

msb snap create

Capture disk state. Add --full to include memory and running processes.
Local disk capture accepts running, paused, stopped, or crashed sources. Cloud requires a stopped persistent source.
Guest flushing is shared by the CLI and SDKs. See guest flushing for policies and examples.

msb snap restore

Restore a saved snapshot into a new sandbox. Disk snapshots boot fresh; full snapshots resume captured execution.
--name is required. See restore options for memory sharing, disk-only restore, and resource bindings. Existing top-level restore commands remain supported.

msb snap ls

List snapshots. Use --group to filter a local group; it is unavailable on cloud.

msb snap inspect

Show snapshot metadata. Add --verify to check recorded content hashes.

msb snap verify

Check recorded content integrity. Local-only; capture with --integrity to record disk hashes.
Without disk hashes, size and structure checks cannot detect same-size corruption. Full snapshots also validate their memory and execution objects. See integrity.

msb snap rm

Delete one or more snapshots.
If other group members remain, select another head before removing the current one. --force does not bypass this rule. Removal also refuses an installed copy held by an active restore, export, verification, or import dependency read. --force does not bypass active readers. Independent copies of the same snapshot have independent leases. On Unix, copies sharing a hardlinked descriptor conservatively share reader protection; Windows normally protects each installed directory entry independently. Metadata handles alone do not keep snapshots busy. Saving or removing through a retained SDK handle rejects a replacement artifact at the same path. Deletion atomically retires the artifact directory before removing its contents. A later snapshot listing or removal can recover interrupted cleanup without deleting a new artifact at the original path. Unix readers lock the existing descriptor. Windows readers normally lock an entry-side coordination file outside the removable directory and fall back to the descriptor when an external parent is read-only. Publication and deletion require writable destinations for their coordination records. Concurrent cleanup requires participating SDKs and CLIs; coordinate maintenance when older clients share the storage.

msb snap head

Read a local group’s head, or select a member as its head.
Use --format json for structured output. The first capture sets the head; later captures advance it only when ancestry proves they descend from it. See snapshot groups.

msb snap export

Export a local snapshot to a compressed .msb archive. The save alias remains supported.
--since, --last-layers, and --with-parents are mutually exclusive. Export preserves recorded hashes but does not verify them. See incremental exports for base requirements.

msb snap import

Import one or more local archives. The load alias remains supported. Dependencies resolve regardless of input order; all members are validated before publication. Snapshot publication records image ownership before exposing the installed artifact and reports catalog failures. Pending publication and deletion recovery runs during snapshot listing; image pruning also reconciles pending publication.
Dependencies come from the batch, matching members in the named group, or --base. Import preserves recorded hashes; run verify to check them.

msb snap reindex

Rebuild the local snapshot index from artifacts on disk. An omitted directory uses the configured snapshot store.