[{"data":1,"prerenderedAt":790},["ShallowReactive",2],{"navigation_docs":3,"-reference-configuration-sandbox":270,"-reference-configuration-sandbox-surround":785},[4,28,51,110,243],{"title":5,"path":6,"stem":7,"children":8},"Get started","\u002Fget-started","1.get-started",[9,12,16,20,24],{"title":10,"path":6,"stem":11},"Overview","1.get-started\u002Findex",{"title":13,"path":14,"stem":15},"Why Kraft","\u002Fget-started\u002Fwhy-kraft","1.get-started\u002F0.why-kraft",{"title":17,"path":18,"stem":19},"Install","\u002Fget-started\u002Finstall","1.get-started\u002F1.install",{"title":21,"path":22,"stem":23},"Your first work item","\u002Fget-started\u002Ffirst-work-item","1.get-started\u002F2.first-work-item",{"title":25,"path":26,"stem":27},"Troubleshooting and FAQ","\u002Fget-started\u002Ftroubleshooting","1.get-started\u002F3.troubleshooting",{"title":29,"path":30,"stem":31,"children":32},"Concepts","\u002Fconcepts","2.concepts",[33,35,39,43,47],{"title":10,"path":30,"stem":34},"2.concepts\u002Findex",{"title":36,"path":37,"stem":38},"Vocabulary","\u002Fconcepts\u002Fvocabulary","2.concepts\u002F1.vocabulary",{"title":40,"path":41,"stem":42},"How a work item runs","\u002Fconcepts\u002Fhow-a-work-item-runs","2.concepts\u002F2.how-a-work-item-runs",{"title":44,"path":45,"stem":46},"Caps and budgets","\u002Fconcepts\u002Fcaps-and-budgets","2.concepts\u002F3.caps-and-budgets",{"title":48,"path":49,"stem":50},"Why a permission gate","\u002Fconcepts\u002Fpermission-gate","2.concepts\u002F4.permission-gate",{"title":52,"path":53,"stem":54,"children":55},"Guides","\u002Fguides","3.guides",[56,58,62,66,70,74,78,82,86,90,94,98,102,106],{"title":10,"path":53,"stem":57},"3.guides\u002Findex",{"title":59,"path":60,"stem":61},"Use Kraft from your agent","\u002Fguides\u002Fagent-integration","3.guides\u002F01.agent-integration",{"title":63,"path":64,"stem":65},"Kraft Lite","\u002Fguides\u002Fkraft-lite","3.guides\u002F02.kraft-lite",{"title":67,"path":68,"stem":69},"Remote access","\u002Fguides\u002Fremote-access","3.guides\u002F03.remote-access",{"title":71,"path":72,"stem":73},"Add or override a harness","\u002Fguides\u002Fadding-a-harness","3.guides\u002F04.adding-a-harness",{"title":75,"path":76,"stem":77},"Schedule or webhook work","\u002Fguides\u002Fschedule-and-webhook-work","3.guides\u002F05.schedule-and-webhook-work",{"title":79,"path":80,"stem":81},"Add a security review or a gate reviewer","\u002Fguides\u002Fadd-review-agents","3.guides\u002F06.add-review-agents",{"title":83,"path":84,"stem":85},"Kraft for VS Code","\u002Fguides\u002Fvscode","3.guides\u002F07.vscode",{"title":87,"path":88,"stem":89},"Reviewing a change","\u002Fguides\u002Freview-a-change","3.guides\u002F08.review-a-change",{"title":91,"path":92,"stem":93},"Write your own chain","\u002Fguides\u002Fwrite-your-own-chain","3.guides\u002F09.write-your-own-chain",{"title":95,"path":96,"stem":97},"Switch a harness","\u002Fguides\u002Fswitch-harness","3.guides\u002F10.switch-harness",{"title":99,"path":100,"stem":101},"Upgrade your templates","\u002Fguides\u002Fupgrading-templates","3.guides\u002F11.upgrading-templates",{"title":103,"path":104,"stem":105},"Operations","\u002Fguides\u002Foperations","3.guides\u002F12.operations",{"title":107,"path":108,"stem":109},"Worker Kit","\u002Fguides\u002Fworker-kit","3.guides\u002F13.worker-kit",{"title":111,"path":112,"stem":113,"children":114},"Reference","\u002Freference","4.reference",[115,117,139,183,201,205,227,231,235,239],{"title":10,"path":112,"stem":116},"4.reference\u002Findex",{"title":118,"path":119,"stem":120,"children":121},"CLI","\u002Freference\u002Fcli","4.reference\u002F1.cli\u002Findex",[122,123,127,131,135],{"title":10,"path":119,"stem":120},{"title":124,"path":125,"stem":126},"Item verbs","\u002Freference\u002Fcli\u002Fitem","4.reference\u002F1.cli\u002F2.item",{"title":128,"path":129,"stem":130},"View verbs","\u002Freference\u002Fcli\u002Fview","4.reference\u002F1.cli\u002F3.view",{"title":132,"path":133,"stem":134},"Repo verbs","\u002Freference\u002Fcli\u002Frepo","4.reference\u002F1.cli\u002F4.repo",{"title":136,"path":137,"stem":138},"Admin verbs","\u002Freference\u002Fcli\u002Fadmin","4.reference\u002F1.cli\u002F5.admin",{"title":140,"path":141,"stem":142,"children":143},"Configuration","\u002Freference\u002Fconfiguration","4.reference\u002F2.configuration\u002Findex",[144,145,155,159,163,167,171,175,179],{"title":10,"path":141,"stem":142},{"title":146,"path":147,"stem":148,"children":149},"Repos","\u002Freference\u002Fconfiguration\u002Frepos","4.reference\u002F2.configuration\u002F2.repos\u002Findex",[150,151],{"title":10,"path":147,"stem":148},{"title":152,"path":153,"stem":154},"Workspaces","\u002Freference\u002Fconfiguration\u002Frepos\u002Fworkspaces","4.reference\u002F2.configuration\u002F2.repos\u002F3.workspaces",{"title":156,"path":157,"stem":158},"Policy","\u002Freference\u002Fconfiguration\u002Fpolicy","4.reference\u002F2.configuration\u002F3.policy",{"title":160,"path":161,"stem":162},"Library and chains","\u002Freference\u002Fconfiguration\u002Flibrary-and-chains","4.reference\u002F2.configuration\u002F4.library-and-chains",{"title":164,"path":165,"stem":166},"Harnesses file","\u002Freference\u002Fconfiguration\u002Fharnesses-file","4.reference\u002F2.configuration\u002F5.harnesses-file",{"title":168,"path":169,"stem":170},"Access","\u002Freference\u002Fconfiguration\u002Faccess","4.reference\u002F2.configuration\u002F6.access",{"title":172,"path":173,"stem":174},"Intake","\u002Freference\u002Fconfiguration\u002Fintake","4.reference\u002F2.configuration\u002F7.intake",{"title":176,"path":177,"stem":178},"Sandbox host","\u002Freference\u002Fconfiguration\u002Fsandbox","4.reference\u002F2.configuration\u002F8.sandbox",{"title":180,"path":181,"stem":182},"Environment variables","\u002Freference\u002Fconfiguration\u002Fenvironment-variables","4.reference\u002F2.configuration\u002F9.environment-variables",{"title":184,"path":185,"stem":186,"children":187},"Chain nodes","\u002Freference\u002Fchain-nodes","4.reference\u002F3.chain-nodes\u002Findex",[188,189,193,197],{"title":10,"path":185,"stem":186},{"title":190,"path":191,"stem":192},"Subprocess tasks","\u002Freference\u002Fchain-nodes\u002Fsubprocess-tasks","4.reference\u002F3.chain-nodes\u002F2.subprocess-tasks",{"title":194,"path":195,"stem":196},"Fix loop and judge","\u002Freference\u002Fchain-nodes\u002Ffix-loop","4.reference\u002F3.chain-nodes\u002F3.fix-loop",{"title":198,"path":199,"stem":200},"Result file","\u002Freference\u002Fchain-nodes\u002Fresult-file","4.reference\u002F3.chain-nodes\u002F4.result-file",{"title":202,"path":203,"stem":204},"Permission gate","\u002Freference\u002Fpermissions","4.reference\u002F4.permissions",{"title":206,"path":207,"stem":208,"children":209},"Agent harnesses","\u002Freference\u002Fharnesses","4.reference\u002F5.harnesses\u002Findex",[210,211,215,219,223],{"title":10,"path":207,"stem":208},{"title":212,"path":213,"stem":214},"Unattended runs","\u002Freference\u002Fharnesses\u002Funattended-runs","4.reference\u002F5.harnesses\u002F2.unattended-runs",{"title":216,"path":217,"stem":218},"Agent profiles","\u002Freference\u002Fharnesses\u002Fagent-profiles","4.reference\u002F5.harnesses\u002F3.agent-profiles",{"title":220,"path":221,"stem":222},"Harness files","\u002Freference\u002Fharnesses\u002Fharness-files","4.reference\u002F5.harnesses\u002F4.harness-files",{"title":224,"path":225,"stem":226},"Fallback and escalation","\u002Freference\u002Fharnesses\u002Ffallback-and-escalation","4.reference\u002F5.harnesses\u002F5.fallback-and-escalation",{"title":228,"path":229,"stem":230},"Inbound triggers","\u002Freference\u002Ftriggers","4.reference\u002F6.triggers",{"title":232,"path":233,"stem":234},"HTTP API","\u002Freference\u002Fhttp-api","4.reference\u002F7.http-api",{"title":236,"path":237,"stem":238},"MCP tools","\u002Freference\u002Fmcp-tools","4.reference\u002F8.mcp-tools",{"title":240,"path":241,"stem":242},"Events","\u002Freference\u002Fevents","4.reference\u002F9.events",{"title":244,"path":245,"stem":246,"children":247},"Project","\u002Fproject","5.project",[248,250,254,258,262,266],{"title":10,"path":245,"stem":249},"5.project\u002Findex",{"title":251,"path":252,"stem":253},"Architecture","\u002Fproject\u002Farchitecture","5.project\u002F1.architecture",{"title":255,"path":256,"stem":257},"Contributing","\u002Fproject\u002Fcontributing","5.project\u002F2.contributing",{"title":259,"path":260,"stem":261},"Security","\u002Fproject\u002Fsecurity","5.project\u002F3.security",{"title":263,"path":264,"stem":265},"Data and privacy","\u002Fproject\u002Fdata-and-privacy","5.project\u002F4.data-and-privacy",{"title":267,"path":268,"stem":269},"Status and support","\u002Fproject\u002Fstatus-and-support","5.project\u002F5.status-and-support",{"id":271,"title":176,"body":272,"description":778,"extension":779,"links":780,"meta":781,"navigation":782,"path":177,"seo":783,"stem":178,"__hash__":784},"docs\u002F4.reference\u002F2.configuration\u002F8.sandbox.md",{"type":273,"value":274,"toc":774},"minimark",[275,297,345,516,519,568,575,578,586,592,596,613,635,670,676,694,713,723,727,759,770],[276,277,278,282,283,286,287,292,293,296],"p",{},[279,280,281],"code",{},"sandbox.yaml"," says how this machine runs sandboxed tasks. Whether a task is sandboxed, and in which image, is set elsewhere: ",[279,284,285],{},"sandbox:"," in ",[288,289,291],"a",{"href":290},"\u002Freference\u002Fconfiguration\u002Frepos#sandboxed-workers","repos.yaml"," or a ",[288,294,295],{"href":157},"policy",". The file is optional; a missing one is all defaults, which suit a machine with Docker and no SELinux.",[298,299,304],"pre",{"className":300,"code":301,"language":302,"meta":303,"style":303},"language-yaml shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","cli: docker\nselinux: auto\nca_bundle: \u002Fetc\u002Fssl\u002Fcorp-ca.pem\n","yaml","",[279,305,306,323,334],{"__ignoreMap":303},[307,308,311,315,319],"span",{"class":309,"line":310},"line",1,[307,312,314],{"class":313},"swJcz","cli",[307,316,318],{"class":317},"sMK4o",":",[307,320,322],{"class":321},"sfazB"," docker\n",[307,324,326,329,331],{"class":309,"line":325},2,[307,327,328],{"class":313},"selinux",[307,330,318],{"class":317},[307,332,333],{"class":321}," auto\n",[307,335,337,340,342],{"class":309,"line":336},3,[307,338,339],{"class":313},"ca_bundle",[307,341,318],{"class":317},[307,343,344],{"class":321}," \u002Fetc\u002Fssl\u002Fcorp-ca.pem\n",[346,347,348,364],"table",{},[349,350,351],"thead",{},[352,353,354,358,361],"tr",{},[355,356,357],"th",{},"Field",[355,359,360],{},"Default",[355,362,363],{},"Means",[365,366,367,408,441,461,485],"tbody",{},[352,368,369,374,377],{},[370,371,372],"td",{},[279,373,314],{},[370,375,376],{},"unset",[370,378,379,382,383,386,387,389,390,393,394,396,397,399,400,403,404,407],{},[279,380,381],{},"docker"," or ",[279,384,385],{},"podman",". Unset: ",[279,388,381],{}," when it is on ",[279,391,392],{},"PATH",", otherwise ",[279,395,385],{},". A ",[279,398,381],{}," that is Podman underneath (the ",[279,401,402],{},"podman-docker"," package) is recognised from its ",[279,405,406],{},"--version"," and treated as Podman.",[352,409,410,414,419],{},[370,411,412],{},[279,413,328],{},[370,415,416],{},[279,417,418],{},"auto",[370,420,421,422,425,426,429,430,433,434,437,438,440],{},"What to do on a host where SELinux enforces, which denies every bind mount a container did not relabel. ",[279,423,424],{},"relabel"," adds the shared ",[279,427,428],{},"z"," label to each mount, which relabels the worktree and your repository's files for containers once. ",[279,431,432],{},"disable"," runs Kraft's containers with ",[279,435,436],{},"--security-opt label=disable",", leaving the files alone and SELinux separation off for those containers only. ",[279,439,418],{}," stops each sandboxed task as a configuration error that names both, because either one changes something outside Kraft. Ignored where SELinux is off or permissive, and where the runtime applies no labels (Docker does only when its daemon runs with SELinux support), since its mounts then work as they are.",[352,442,443,447,449],{},[370,444,445],{},[279,446,339],{},[370,448,376],{},[370,450,451,452,455,456,460],{},"An absolute path to a PEM file of extra root certificates a sandboxed task trusts, such as your TLS-intercepting proxy's CA. Unset: the daemon's ",[279,453,454],{},"SSL_CERT_FILE",", when it has one and it is usable. One that cannot be used stops each sandboxed task. See ",[288,457,459],{"href":458},"#ca-certificates","CA certificates",".",[352,462,463,468,474],{},[370,464,465],{},[279,466,467],{},"relay_image",[370,469,470,473],{},[279,471,472],{},"docker.io\u002Falpine\u002Fsocat@sha256:5ffbd6ae…"," (socat 1.8.1.3, pinned by digest)",[370,475,476,477,480,481,484],{},"The image of the relay container a sandboxed session under a ",[279,478,479],{},"network"," policy runs beside its worker, with no network of its own, forwarding the worker's proxy port to Kraft; on Docker Desktop and Podman machine also the second relay of each session. Set it to use a mirror or your own socat image. ",[279,482,483],{},"kraft admin doctor"," fails when it is not pulled; pull it before filing work.",[352,486,487,492,497],{},[370,488,489],{},[279,490,491],{},"credentials",[370,493,494],{},[279,495,496],{},"{}",[370,498,499,500,504,505,508,509,512,513,515],{},"For a ",[288,501,503],{"href":502},"\u002Freference\u002Fconfiguration\u002Frepos#kits","Kit","'s credentials: each credential@1 ",[279,506,507],{},"service"," mapped to the name of the daemon's own environment variable holding its value, as ",[279,510,511],{},"anthropic: KRAFT_ANTHROPIC_KEY",". A Kit never picks a host variable itself, and its credential is read from nothing else. A required credential with no binding stops each item under the Kit, naming the binding to add; an optional one is skipped, and ",[279,514,483],{}," warns about it.",[276,517,518],{},"Kraft asks the runtime whether it is rootless, and runs the container so that what the worker writes stays yours:",[346,520,521,531],{},[349,522,523],{},[352,524,525,528],{},[355,526,527],{},"Runtime",[355,529,530],{},"Runs the container as",[365,532,533,541,549,556],{},[352,534,535,538],{},[370,536,537],{},"Docker",[370,539,540],{},"Your uid and gid.",[352,542,543,546],{},[370,544,545],{},"Rootless Docker",[370,547,548],{},"Container root, which rootless Docker maps to you. Any other uid would land in your subordinate range, and you could not edit what it wrote. Capabilities stay dropped.",[352,550,551,554],{},[370,552,553],{},"Podman",[370,555,540],{},[352,557,558,561],{},[370,559,560],{},"Rootless Podman",[370,562,563,564,567],{},"Your uid and gid, with ",[279,565,566],{},"--userns=keep-id",": without it your uid does not exist in the container, and the worktree is not writable.",[276,569,570,571,574],{},"On a rootless runtime, a task stops as a configuration error before it starts if the work item's sandbox HOME, its ref store or its result file belongs to another user, as one can after switching runtimes. The message names the path: ",[279,572,573],{},"chown"," it back to yourself, or remove it.",[276,576,577],{},"A workspace item has one ref store for each repository, its members' and its root's, and each is checked the same way.",[276,579,580,581,585],{},"Kraft also asks the runtime which ",[288,582,584],{"href":583},"\u002Freference\u002Fconfiguration\u002Frepos#resource-limits","resource limits"," it can enforce: a task that sets one it cannot stops as a configuration error rather than running without it.",[276,587,588,589,591],{},"Kraft reads the file and asks the runtime once, at the first sandboxed launch after it starts. ",[279,590,483],{}," reads both again, so run it after editing the file; restart Kraft for running tasks to pick the change up.",[593,594,459],"h2",{"id":595},"ca-certificates",[276,597,598,599,382,601,603,604,606,607,609,610,318],{},"A container does not have the files the daemon's ",[279,600,454],{},[279,602,339],{}," name, so Kraft never forwards those paths. When there is an extra CA, ",[279,605,339],{}," or else the daemon's ",[279,608,454],{},", Kraft builds one bundle per image under ",[279,611,612],{},"$KRAFT_HOME\u002Frun\u002Fsandbox-ca\u002F",[614,615,616,632],"ul",{},[617,618,619,620,623,624,627,628,631],"li",{},"the image's own roots, read once per image id by a container with no network, from the first of ",[279,621,622],{},"\u002Fetc\u002Fssl\u002Fcerts\u002Fca-certificates.crt",", ",[279,625,626],{},"\u002Fetc\u002Fpki\u002Ftls\u002Fcerts\u002Fca-bundle.crt"," and ",[279,629,630],{},"\u002Fetc\u002Fssl\u002Fcert.pem"," it holds (none: the extra CA alone);",[617,633,634],{},"then every certificate in the extra CA.",[276,636,637,638,641,642,623,644,623,647,623,650,623,653,623,656,623,659,627,662,665,666,669],{},"The bundle is mounted read-only at ",[279,639,640],{},"\u002Fetc\u002Fkraft\u002Fca-bundle.pem",", for sessions and the setup command alike, and ",[279,643,454],{},[279,645,646],{},"REQUESTS_CA_BUNDLE",[279,648,649],{},"CURL_CA_BUNDLE",[279,651,652],{},"GIT_SSL_CAINFO",[279,654,655],{},"NODE_EXTRA_CA_CERTS",[279,657,658],{},"CODEX_CA_CERTIFICATE",[279,660,661],{},"PIP_CERT",[279,663,664],{},"npm_config_cafile"," all name it. It holds the image's roots too because most of those variables replace a tool's store rather than add to it. A repository's own ",[279,667,668],{},"env"," still wins over any of them.",[276,671,672,673,675],{},"The extra CA is read at every launch, so an edit to ",[279,674,339],{}," or to the file needs no restart. With no extra CA, no bundle is built and nothing is mounted or set.",[276,677,678,684,685,687,688,690,691,693],{},[679,680,681,683],"strong",{},[279,682,454],{}," counts."," When ",[279,686,339],{}," is unset and the daemon has ",[279,689,454],{},", that file is the extra CA, so every sandboxed launch on such a host builds and mounts a bundle. Set ",[279,692,339],{}," to choose a different file.",[276,695,696,699,700,702,703,705,706,708,709,712],{},[679,697,698],{},"An unusable CA."," A ",[279,701,339],{}," that cannot be read, is a directory, is not an absolute path or holds no PEM certificate stops each sandboxed task as a configuration error, and ",[279,704,483],{}," fails the repository's sandbox row: you named it for sandboxes, so it is never skipped. An unusable ",[279,707,454],{}," is ignored instead, since it was not set for sandboxes: tasks launch as they would without it, and doctor shows a ",[279,710,711],{},"ca"," warning saying why it was not used.",[276,714,715,718,719,722],{},[679,716,717],{},"An image whose roots cannot be read."," When the container that reads the image's roots does not run (the pull failed or timed out, the image has no ",[279,720,721],{},"sh",", the runtime did not answer), the task stops as a configuration error naming the image. A bundle of the extra CA alone would replace the store and fail TLS to every other host. Nothing is cached, so the next launch tries again.",[593,724,726],{"id":725},"proxy","Proxy",[276,728,729,730,623,733,623,736,623,739,742,743,745,746,623,749,623,752,755,756,758],{},"The daemon's proxy variables (",[279,731,732],{},"HTTP_PROXY",[279,734,735],{},"HTTPS_PROXY",[279,737,738],{},"ALL_PROXY",[279,740,741],{},"NO_PROXY",", in either case) reach a sandboxed task by name, so a proxy password never appears on the ",[279,744,381],{}," command line. A proxy on the daemon's loopback (",[279,747,748],{},"127.0.0.0\u002F8",[279,750,751],{},"localhost",[279,753,754],{},"::1",") is left out: inside the container that address is the container itself, so forwarding it would fail every request, while leaving it out at least lets the task go direct where the host allows that. ",[279,757,483],{}," warns about such a proxy for each sandboxed repository.",[276,760,761,762,764,765,769],{},"Doctor's proxy and CA checks read the environment of the ",[279,763,483],{}," process itself, not the running daemon's. They agree when both were started from the same shell; if the daemon runs as a service with its own environment, check that environment instead. Under a sandbox ",[288,766,768],{"href":767},"\u002Freference\u002Fconfiguration\u002Frepos#network-policy","network policy"," none of these variables is forwarded, and doctor does not warn: the container's only proxy is Kraft's own, and the daemon makes the outbound connections through its own proxy, on its loopback or not.",[771,772,773],"style",{},"html pre.shiki code .swJcz, html code.shiki .swJcz{--shiki-light:#E53935;--shiki-default:#F07178;--shiki-dark:#F07178}html pre.shiki code .sMK4o, html code.shiki .sMK4o{--shiki-light:#39ADB5;--shiki-default:#89DDFF;--shiki-dark:#89DDFF}html pre.shiki code .sfazB, html code.shiki .sfazB{--shiki-light:#91B859;--shiki-default:#C3E88D;--shiki-dark:#C3E88D}html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}",{"title":303,"searchDepth":325,"depth":325,"links":775},[776,777],{"id":595,"depth":325,"text":459},{"id":725,"depth":325,"text":726},"Every field in sandbox.yaml: which container CLI runs sandboxed tasks, how they get past SELinux, and which extra CA they trust.","md",null,{},true,{"title":176,"description":778},"1anuYtH43yQ13aArbtHKhLh9BvWFJDh_upb69hn-VzU",[786,788],{"title":172,"path":173,"stem":174,"description":787,"children":-1},"Every field in intake.yaml: autonomous pickup.",{"title":180,"path":181,"stem":182,"description":789,"children":-1},"Every KRAFT_* variable Kraft reads or sets, and the other variables it reads or passes to workers.",1790824543714]