Deploying Craft
Choose and prepare a sandbox runtime for self-hosted Craft
This reference describes the underlying platform. Use a Nexus school release with its school membership, class policy, and cost controls. Installing a base engine alone does not add those controls.
Craft runs generated code in isolated sandboxes and sends sandbox network traffic through an egress proxy. Self-hosted deployments can run these sandboxes in Kubernetes or Docker.
Kubernetes#
Deploy sandbox pods, the proxy, RBAC, and workers with the Nexus Helm chart.
Docker Compose#
Run sandbox containers and the proxy on a trusted single Docker host.
Use Kubernetes if more than a few people will use Craft, especially when they may work concurrently. Each active user needs a sandbox, so Docker Compose is best suited to small, single-host deployments.
| Kubernetes | Docker Compose | |
|---|---|---|
| Sandbox runtime | One pod per active user | One container per active user |
| Recommended for | Production and multi-node deployments | Single-host self-hosted deployments |
| Provisioning | Nexus Helm chart | onyx-cli deploy install --include-craft |
| Host access | Kubernetes API through scoped RBAC | Docker socket access on the host |
Requirements#
Both deployment paths require:
A full Nexus deployment with the vector database and background workers. Craft does not run on Nexus Lite.
A supported Nexus release and matching application and sandbox image versions.
A Nexus API URL that the sandbox runtime can reach, configured as
ONYX_SERVER_URL(Docker Compose sets a working default; Helm requires it).Capacity for a sandbox per active Craft user.
An Anthropic, OpenAI, or OpenRouter provider configured after deployment.
Sandboxes execute model-generated code. Review Craft Architecture before enabling Craft, especially the sandbox, network, credential, and sharing boundaries.
After the runtime is ready#
Configure a model#
In Admin Panel → Language Models, add an Anthropic, OpenAI, or OpenRouter provider and make at least one model available to your Craft users.
Configure workspace access#
Open Admin Panel → Craft → Access. Keep the workspace default off for a limited rollout, or enable Craft for everyone.
Run a complete test#
As an enabled user, start a Craft session, send a prompt that creates a file, and open or download the result.
Add Apps and Skills#
Configure external services under Admin Panel → Craft → Apps and reusable workflows under Craft → Skills.
Managing Craft#
Configure access, models, Apps, and workspace instructions.
Craft Architecture#
Understand sandbox isolation, egress, credentials, and approvals.