Sandboxed opencode environment with code intelligence, running via Nix with Bubblewrap isolation.
- Overview -- High-level architecture and components
- Sandbox -- Bubblewrap sandbox CLI flags and bind mounts
- Commands -- Custom
/commit,/docs,/tuicrcommands - Skills -- GitNexus and tuicr skills available to the agent
- Prompts -- Agent instruction files (general, gitnexus, karpathy)
- Configuration -- opencode.jsonc, Herdr config, tuicr config, Nix flake
- Bubblewrap sandbox (
sandbox.sh) -- Isolates opencode from the host filesystem to reduce secret exposure risk (opt out with--no-sandboxto run directly on the host) - Herdr terminal workspace -- Agent-native session that auto-launches opencode
- GitNexus -- Local knowledge graph for code intelligence (call chains, execution flows, impact analysis)
- tuicr -- TUI code review tool with vim keybindings, launched via
/tuicrcommand in a Herdr tab - Custom opencode commands --
/commit(conventional commits),/docs(documentation generation),/tuicr(code review) - Custom agent prompts -- General guidelines, GitNexus rules, and Karpathy-style coding rules loaded into every session
- GitNexus skill set -- 7 skills for exploring, debugging, impact analysis, PR review, refactoring, CLI, and guidance
- Version-pinned -- All tools and dependencies pinned via the Nix flake lockfile
In your repository root run:
nix run github:nix-dba/opencode --refresh --accept-flake-configor via backup repository:
nix run git+https://codeberg.org/nix-dba/opencode --refresh --accept-flake-configOr from the cloned repo directly:
nix run . --refreshPress ctrl+b q to quit. This detaches the Herdr client; because the Herdr
server runs inside the bubblewrap sandbox, quitting also tears down the sandbox
and all its processes. Re-run nix run . for a fresh session.
The flake provides two sandbox apps:
nix run .-- Light (default) with bare minimum dependencies, no GitNexusnix run .#full-- Full with all dependencies, GitNexus enabled by default
See docs/sandbox.md for available CLI flags (--no-net, --ssh-keys, --no-sandbox, etc.).