Taking over a link or an environment address
On newer boxes, sandbox_wire puts your own process or a published version under a name that went out through a link or the connector, in place, keeping the box's URLs.
On a box whose sandbox_status → health.features includes take-over, which every box started from 2026-09-25 12:40 UTC has (image box-202609251946; a box keeps the boxd it started with, across freezes), sandbox_wire can put a service of the box under a name that now goes out of the box, through a link or through the connector:
sandbox_wire { "id": "<id>", "service": "billing.acme.internal", "port": 8080, "targetPort": 8081 }
sandbox_wire { "id": "<id>", "service": "billing.acme.internal", "port": 8080, "version": "refund-a1b2c3d", "env": { "WORKERS_ENABLED": "false" } }
- The first form is your own process on
targetPort; the second a published version (withenvandcontainerPortas usual). Either one, on aname:portthat is a link or one of the environment's addresses, takes that name over in place. - The name keeps its address in the box, so programs that cached its DNS answer keep working; from then on it reaches
targetPortin the box. - Connections open through the link or the connector are closed; programs reconnect, now to the box's copy.
- A link stops being a link:
fromBoxandfromPortleavesandbox_status.services, and the other box'slinkedFromno longer lists this box. The box keeps its URLs. - The name must be taken over on the port it goes out on; on another port the call fails with
<name> is reached through the connector or a link on port [<port>]; a name cannot be a service in the box on port <n> and go out on another. A name that goes out on several ports (an environment listingdb.internal:5432anddb.internal:6432, say) cannot be taken over on one of them either:<name> is also reached through the connector or a link on port [<port>]; a name cannot be a service in the box on one port and go out on another. A name cannot be a service in the box on one port and go out on another. Declare such a name atsandbox_startinstead, where it points at the box on every port. - A
modeswitch on a link name always fails with 409:<name> is a link in this box, which has no box or external mode. Wire it again with fromBox or fromPort to change where it goes, or pass port (and targetPort) to run the service in the box instead.
On older boxes, without take-over in health.features:
- a link name with
portfails with 409<name> is a link in this box, and box <id> runs boxd <version>, which cannot turn a link into a service in the box. Wire it again with fromBox or fromPort to change where it goes, or start a new box that declares the service, and withversion:<name> is a link in this box, and box <id> runs boxd <version>, which cannot turn a link into a published version. Start a new box that declares the version, or wire the link again with fromBox or fromPort; - a name added with
portorversionthat is one of the environment's addresses keeps going to the connector; declare such names atsandbox_startinstead.
Every tool and topic is listed in the tool reference.