jackin❯ workspace
Manage saved workspace configurations
Synopsis
jackin workspace <SUBCOMMAND>Create, list, modify, and delete saved workspace definitions.
A workspace describes project access, not agent tooling. It answers: which host paths should be mounted into the container, and which roles are allowed to use that layout?
Subcommands
workspace create
jackin workspace create <NAME> --workdir <PATH> --mount <SPEC> [OPTIONS]Create a new workspace definition.
| Option | Description |
|---|---|
--workdir <PATH> | Working directory inside the container |
--mount <SPEC> | Bind-mount spec (repeatable, at least one required) |
--allowed-role <NAME> | Restrict to these roles (repeatable) |
--default-role <NAME> | Role to preselect in interactive pickers and CLI context loading |
--default-agent <claude|codex|amp|kimi|opencode> | Default agent for this workspace |
--mount-isolation <DST>=<TYPE> | Set per-mount isolation by container destination. Repeatable. <TYPE> is shared, worktree, or clone. The <DST> must match a mount destination present in the final mount plan; an unknown <DST> is a hard error. |
--keep-awake | macOS only: opt this workspace into the keep-awake reconciler. While any agent in the workspace is running, jackin❯ keeps a single detached caffeinate -imsu alive so the host stays awake. No-op on Linux/Windows. See Keeping the host awake. |
--git-pull | Run git pull on every mounted git repository from the host before the agent container starts. Failures are non-fatal — the launch continues even when offline or the working tree is dirty. See Git pull on entry. |
jackin workspace create my-app --workdir ~/Projects/my-app --mount ~/Projects/my-app
jackin workspace create my-app --workdir ~/Projects/my-app --mount ~/Projects/my-app --mount ~/cache:/cache:ro
jackin workspace create amp-app --workdir ~/Projects/amp-app --mount ~/Projects/amp-app --default-agent amp
jackin workspace create monorepo --workdir /workspace --mount ~/src:/workspace
jackin workspace create restricted --workdir ~/app --mount ~/app --allowed-role agent-smith --default-role agent-smith
jackin workspace create remote --workdir ~/Projects/remote --mount ~/Projects/remote --keep-awake
# Isolated source mount + shared cache child
jackin workspace create jackin \
--workdir /workspace/jackin \
--mount ~/projects/jackin:/workspace/jackin \
--mount ~/.cache/jackin/target:/workspace/jackin/target \
--mount-isolation /workspace/jackin=worktreeworkspace list
jackin workspace list [--format <human|json>]Show all saved workspaces. Pass --format json for machine-readable output with a schema_version field.
workspace show
jackin workspace show <NAME> [--format <human|json>]Display details of a specific workspace including workdir, mounts, and role restrictions. Pass --format json for structured output.
The mount table includes an Isolation column showing each mount's effective isolation mode (shared, worktree, or clone). Mounts with no isolation field in TOML display as shared.
workspace edit
jackin workspace edit <NAME> [OPTIONS]Modify an existing workspace.
| Option | Description |
|---|---|
--workdir <PATH> | Update the working directory |
--mount <SPEC> | Add a mount (repeatable) |
--remove-destination <PATH> | Remove a mount by container path (repeatable) |
--allowed-role <NAME> | Grant role access (repeatable) |
--remove-allowed-role <NAME> | Revoke role access (repeatable) |
--default-role <NAME> | Set the default role for picker preselection and CLI context loading |
--clear-default-role | Clear the default role |
--default-agent <claude|codex|amp|kimi|opencode> | Set default agent |
--clear-default-agent | Clear the explicit default agent so launch resolution uses the role manifest or prompts for multi-agent roles |
--mount-isolation <DST>=<TYPE> | Set isolation for a mount destination (repeatable). Can target an existing mount or a mount being upserted in the same command. |
--delete-isolated-state | Acknowledge deleting preserved isolated state when an edit changes the src of a materialized isolated mount. Required for non-interactive source-drift edits; ignored when no preserved state exists. |
--keep-awake | macOS only: enable the keep-awake reconciler on this workspace. Mutually exclusive with --no-keep-awake. |
--no-keep-awake | Disable the keep-awake reconciler on this workspace. Mutually exclusive with --keep-awake. |
--git-pull | Enable git pull on entry for this workspace. Mutually exclusive with --no-git-pull. |
--no-git-pull | Disable git pull on entry for this workspace. Mutually exclusive with --git-pull. |
--prune | Also remove pre-existing redundant mounts (rule-C violations) as part of this edit. |
--yes, -y | Skip confirmation prompts for mount collapses. |
jackin workspace edit my-app --workdir ~/new-dir
jackin workspace edit my-app --mount ~/cache:/cache:ro
jackin workspace edit my-app --remove-destination /old-mount
jackin workspace edit my-app --allowed-role chainargos/backend-engineer
jackin workspace edit my-app --default-role agent-smith
jackin workspace edit my-app --clear-default-role
jackin workspace edit my-app --default-agent amp
jackin workspace edit my-app --clear-default-agent
jackin workspace edit my-app --keep-awake
jackin workspace edit my-app --no-keep-awake
jackin workspace edit my-app --git-pull
jackin workspace edit my-app --no-git-pull
# Flip an existing mount to per-container worktrees
jackin workspace edit my-app --mount-isolation /workspace/my-app=worktree
# Change the host src of a previously materialized isolated mount
# (non-interactive; explicitly accept that preserved state will be deleted)
jackin workspace edit my-app \
--mount ~/projects/my-app-v2:/workspace/my-app \
--delete-isolated-stateworkspace edit rejects isolation changes on a running container with a clear "eject first" message. Source-drift edits that would invalidate preserved isolated state prompt interactively; non-interactive runs require --delete-isolated-state to proceed.
Mount collapse
When you add a mount that is an ancestor of existing mounts (same host-to-container offset), the descendants become redundant. jackin workspace edit detects this and prompts before removing them:
Adding mount(s) will subsume 2 existing mount(s):
• ~/Projects/proj-alpha/sub-a
• ~/Projects/proj-alpha/sub-b
These will be removed from the workspace.
Proceed? [y/N]Flags:
--yes/-y— skip the prompt (required for non-interactive use).--prune— also clean up pre-existing redundant mounts in the workspace.
Conflict cases that are rejected with an error (not prompted):
- Readonly mismatch. Parent and descendant have different
:roflags. - Child under existing parent. Adding a mount that is already covered by a pre-existing mount in the workspace.
In both cases the error text names both paths and the operator's next step.
workspace remove
jackin workspace remove <NAME>Delete a saved workspace.
workspace prune
jackin workspace prune <NAME> [OPTIONS]Remove pre-existing redundant mounts from a saved workspace. Useful when upgrading from an older jackin❯ config or after a hand-edit that left redundants.
| Option | Description |
|---|---|
--yes / -y | Skip the interactive prompt |
jackin workspace prune my-app # interactive
jackin workspace prune my-app --yes # non-interactiveA mount is redundant when another mount in the same workspace strictly covers it at the same container location — same host-to-container offset. See Redundant mounts in the mounts guide.
workspace env
Manage operator env vars at workspace and workspace-role scope.
Values are stored verbatim — op://... 1Password references, $VAR / ${VAR} shell-style interpolations, and literal strings all work. jackin❯ resolves values at launch time; there is no editor-side validation of key names or value shape.
Without --role, writes and reads target the workspace-wide scope (applies to every role launch in this workspace). With --role <SELECTOR>, they target the per-(workspace × role) scope (applies only when that role is launched in this workspace). The workspace must already exist — unknown workspaces fail fast with a non-zero exit. The role selector is not pre-validated.
workspace env set
jackin workspace env set <WORKSPACE> <KEY> <VALUE> [OPTIONS]Set or overwrite an env var at the chosen scope.
| Option | Description |
|---|---|
--role <SELECTOR> | Apply to the per-(workspace × role) scope instead of the workspace-wide one |
--comment <TEXT> | Attach an inline comment to the key |
--on-demand | Inject the value at jackin-exec time instead of at launch |
# Workspace scope
jackin workspace env set prod DB_URL "op://Work/Prod/db-url"
# Workspace-role scope
jackin workspace env set prod OPENAI_KEY "op://Work/OpenAI/key" --role agent-smith
# Attach a comment
jackin workspace env set prod DEBUG "1" --comment "temporary; remove after Q2"
# On-demand credential: never resolved at launch, approved per use
jackin workspace env set prod OP_TOKEN "op://Work/svc-account/credential" --on-demandworkspace env unset
jackin workspace env unset <WORKSPACE> <KEY> [OPTIONS]Remove an env var from the chosen scope. Idempotent: if the key is not present, prints <KEY> not set. and exits 0 without modifying anything. Fails fast if <WORKSPACE> does not exist.
| Option | Description |
|---|---|
--role <SELECTOR> | Unset from the per-(workspace × role) scope instead of the workspace-wide one |
jackin workspace env unset prod DB_URL
jackin workspace env unset prod OPENAI_KEY --role agent-smithworkspace env list
jackin workspace env list <WORKSPACE> [OPTIONS]Show the env vars registered at the chosen scope as a table with Key, Value, and On demand columns. Prints No env vars set. when the scope is empty. Values are shown as-stored (no resolution, no masking); On demand is yes for a value resolved at jackin-exec time rather than injected at launch. Fails fast if <WORKSPACE> does not exist.
| Option | Description |
|---|---|
--role <SELECTOR> | List vars from the per-(workspace × role) scope instead of the workspace-wide one |
jackin workspace env list prod
jackin workspace env list prod --role agent-smithworkspace account
Authorize named accounts for a workspace and choose which account each coding agent uses.
jackin workspace account list my-app
jackin workspace account assign my-app work
jackin workspace account select my-app work --agent claude
jackin workspace account select my-app work --agent claude --role agent-smith
jackin workspace account select my-app --agent claude --clear
jackin workspace account unassign my-app work| Subcommand | Effect |
|---|---|
list <WORKSPACE> | Show allowed accounts and agent bindings without secret values. |
assign <WORKSPACE> <ACCOUNT> | Add an existing account to the workspace allowlist. |
unassign <WORKSPACE> <ACCOUNT> | Remove access and clear workspace/role bindings referring to that account. |
select <WORKSPACE> <ACCOUNT> --agent <AGENT> | Select an already assigned account compatible with the agent. |
select <WORKSPACE> <ACCOUNT> --agent <AGENT> --role <ROLE> | Override selection for one role within the workspace allowlist. |
select <WORKSPACE> --agent <AGENT> --clear | Remove the explicit workspace selection; add --role to clear a role selection. |
Assignment grants access. Selection chooses among granted accounts. A global account or global selection never expands a workspace's allowlist. With no compatible account, no agent credentials are forwarded; multiple compatible accounts require an explicit selection.
Create and remove registry entries with account commands. Account changes take effect on the next launch; they do not revoke tokens at the provider.