Declare every credential under secrets. DigitalOcean delivers each secret to the sandbox as an environment variable, strips the secrets section from the stored YAML, and keeps the values in the secure secrets store.
How to Create an Environment Using a Coding Adapterpublic
Last verified 1 Oct 2026
DigitalOcean Harness Runtime provides managed, hardware-isolated microVM sandboxes with built-in tools such as Chromium to run harnesses and execute arbitrary code. Rich lifecycle APIs preserve conversational history and working state across sessions, letting you pause, resume, and fork work to control costs and adapt to the nonlinear nature of agentic workflows. Scale complete agents such as Claude Code or use sandboxes independently for code execution, all through the same service. See What You Can Build for example use cases.
Harness Runtime supports multiple coding agent adapters. Each adapter runs in its own sandbox. Pick an adapter, set credentials under secrets, and start a session from the spec. To run LangGraph instead of a coding agent, see Run a LangGraph Agent.
Create a Spec File for a Coding Adapter
A spec file is a YAML file that describes the environment you want. You can choose from one of the following coding adapters in your spec:
Set codex as your agent and declare your OpenAI API key under secrets.
name: codex-agent
agent: codex
size: mars-2vcpu-4gb
secrets:
OPENAI_API_KEY: ${OPENAI_API_KEY}
permissions:
default: askExport the key, then save the spec as codex-spec.yaml:
export OPENAI_API_KEY=<your-openai-key>Set claude-code as your agent and declare your Anthropic API key under secrets.
name: claude-code-agent
agent: claude-code
size: mars-2vcpu-4gb
secrets:
ANTHROPIC_API_KEY: ${ANTHROPIC_API_KEY}
permissions:
default: askExport the key, then save the spec as claude-code-spec.yaml:
export ANTHROPIC_API_KEY=<your-anthropic-key>Set opencode as your agent and declare your provider API key under secrets.
name: opencode-agent
agent: opencode
size: mars-2vcpu-4gb
secrets:
OPENAI_API_KEY: ${OPENAI_API_KEY}
permissions:
default: askExport the key, then save the spec as opencode-spec.yaml:
export OPENAI_API_KEY=<your-openai-key>To pin a model, or to use DigitalOcean Inference instead of an external provider key, put the model access key under secrets and the non-secret endpoint settings in env:
env:
HARNESS_INFERENCE_MODEL: deepseek-v4-pro
secrets:
HARNESS_INFERENCE_API_KEY: ${HARNESS_INFERENCE_API_KEY}For more information about the environment spec, see the environment spec reference.
Start and Attach to the Session
Pass the spec file to launch, which creates the sandbox, starts the agent inside it, and attaches your terminal, all in one step:
doctl harness-runtime launch <your-spec-file>.yamlPress Ctrl+D to detach. The session keeps running in the cloud, and the same launch command reconnects you to it. Passing the name of a session that already exists resumes it rather than creating a new one:
doctl harness-runtime launch <your-session-name>If you start the same setup repeatedly, save the spec as an Environment Config and start sessions from it instead of uploading the YAML each time. See Use Environment Configs.
Create an Environment in the Control Panel
Instead of writing a spec file, you can also create an environment in the DigitalOcean Control Panel. You can configure the adapter, the credentials it needs, the tools it calls, and the permission level for each tool.
- In the Control Panel, under Managed Agents, click Harness Runtime, and then click Create Environment in the top right corner.
- On Choose Adapter, select the coding agent to use and click Continue. You can choose from OpenCode, Codex CLI, Claude Code, or Hermes as a coding adapter, or LangGraph as a framework adapter and click Continue.
- On Connections, authorize the providers the environment needs. You can allow it access to your GitHub account, DigitalOcean Serverless Inference, or custom API key. For Serverless Inference, provide the model access key and select the model to use. For custom API key, enter the API base URL, API key, and the model name. See Authorize Providers with Connections. Then, click Continue.
- On Configure, name the environment and choose the Sandbox size. You can also specify the Egress policy as Unrestricted or Restricted to allow or block network access, and set its runtime options such as environment variables or secrets. Then, click Continue.
- On Capabilities (optional), under Tools (optional), click Add tools, and choose the Action Gateway tools the agent can use and click Continue. You can optionally click Add Skill to add a skill to the environment and click Continue.
- On Permissions, from the dropdown menu, set whether each tool runs without asking, requires approval, or is blocked. Click Add Rule to give permissions to your specific tools and click Continue.
- Click Create Environment.
The environment appears in the Environments tab. Start a session from it by clicking Create Session, or from the command line as described in Use Environment Configs. You can then start sending requests to your agent.
You cannot edit the environment configuration after it is created. If you want to make changes, you need to create a new environment.
Troubleshooting
Use this table to diagnose common errors when creating or attaching to a session:
| Symptom | Likely cause | What to do |
|---|---|---|
unknown command "harness-runtime" |
doctl build doesn’t include Harness Runtime commands |
Install the correct doctl build |
401 Unable to authenticate |
Invalid or missing token | Recreate the token and run doctl auth init |
402 Payment Required |
All of the team’s balances are empty, which blocks starting, resuming, forking, and restoring sessions | Add funds, then start the session again. See How to Pay for Harness Runtime. To have a paused session resume on its own once the balance is topped off, start it with --resume-on-topoff |
404 or maintenance page |
Feature not enabled for the team | Confirm the account has access and is in a supported region |
429 quota exceeded |
Concurrent session limit reached | Remove an unused session, then start again |
| Run is terminal | Session ended or was destroyed | Start a new session |
| Connection drops | Transient network issue | Reattach to the same session |