Sandboxing
##########

JetStream servers can restrict a user's activity to a specific location in the file system, or *sandbox*. Sandboxes can be used to isolate users, or limit them to only specific resources.

Sandboxing can be setup to:
    * Restrict all users to a specific resource (eg. ``/storage``)
    * Restrict users to a user-specific location (eg. user's home directory)
    * Give specific user access to a resource (eg. only ``userA`` can access ``/storage/data``)
    * Give users a list of accessible resources (eg. ``/storage/common-fles``, and user's home directory)

.. warning::

  If a sandbox is not specified, access to whole system root (``/``) is assumed.

.. tip::

  Sandboxing can be managed with a graphical user-interface using the :doc:`Client Application <jetstream-client:locations/location-configure-server>`.

.. tip::

  Sandboxing status of a server can be determined by either calling the :meth:`~jetstream.serverinterface.ServerInterface.getServerInfo` (see :ref:`jetstream-api:structure-server-info`) API call, or by listing the sandboxes using :meth:`~jetstream.serverinterface.ServerInterface.getSandboxMappings` (requires :doc:`superuser </security/superuser>` privileges) API call.

.. rubric:: Topics

.. toctree::
    :maxdepth: 1
    :glob:

    basic
    advanced
    types/index
