# Build brief — a focused alternative to CodeSandbox

> **Verdict:** Partly, if you narrow it · **Buildability:** 52/100 · **Category:** Dev Tools
> **Source:** https://www.canitbevibecoded.com/codesandbox
> Independent editorial assessment from Can It Be Vibe Coded? Not affiliated with, endorsed by, or derived from CodeSandbox. Verify current pricing and capabilities before acting.

## Context

**CodeSandbox** — Cloud development environments and browser-based coding sandboxes. It currently costs $12/mo.

You can self-host a browser IDE, but fast templates, previews, cloud VMs, collaboration, and workflow integrations are the product.

This brief describes a focused, single-operator replacement for the part of CodeSandbox that is genuinely reproducible. It is deliberately narrower than the product it replaces, and it says so in writing. Build the useful core; do not pretend to have rebuilt the rest.

## What you are building

Run code-server or dev containers, expose preview URLs, sync git repos, and add templates.

- Build the focused developer workflow you use repeatedly, with local configuration.
- A responsive interface with real empty, loading, success, and error states.

## Requirements

### Functional

- Container host.
- Code-server/devcontainer tooling.
- Reverse proxy.
- Git integration.
- Auth.

### Non-functional

- Accessibility: semantic markup, labelled controls, visible focus, and reduced-motion support.
- Security: server-side secrets, validated input, and no credentials in the client bundle.
- Reliability: retries with backoff on external calls, and a clear failure state when a provider is down.
- Portability: the operator can export their data and leave without losing it.

## Implementation brief

Build me a personal cloud dev environment to replace CodeSandbox.
Requirements:

- Do not write an IDE. Set up code-server (VS Code in the browser) on my
  VPS via its official install script, running under systemd, bound to
  localhost.
- Access over Tailscale or an SSH tunnel only; no public exposure, built-in
  password auth switched off. That is the whole security model, keep it
  that simple.
- A sandbox CLI: sandbox new <name> --template node|python|static copies a
  folder from templates/ into ~/sandboxes/<name>, runs its install step,
  and prints the code-server URL opened to it.
- Three templates: node (Express hello world + nodemon), python (venv +
  Flask), static (index.html served with live-server).
- Previews: each sandbox's dev server gets its own port, reachable through
  the same tunnel; a tiny index page lists sandboxes and their ports.
- sandbox rm <name> archives the folder to a tarball before deleting it.
- No accounts, no telemetry; everything lives on my own server.
- Out of scope: multi-user collaboration, instant VM forking, and public
  preview URLs; managed infrastructure is the hosted product.
- README: install steps, tunnel setup, and how to add a template.

## Delivery standard

- Inspect the repository first, then write a short implementation plan before writing code.
- Deliver the smallest complete end-to-end workflow first; every primary control must work against persisted data.
- Use real validation and storage; never substitute fake dashboards, decorative controls, hard-coded success states, or mock integrations.
- Include responsive layouts plus genuine empty, loading, success, validation, and failure states.
- Keep secrets server-side in environment variables, provide .env.example, and never commit credentials or user data.
- Add structured logs around every external call and return actionable errors without leaking sensitive details.
- Write unit tests for the core logic and one automated test of the main user journey.
- Finish with a README covering setup, architecture, data location, backups, tests, deployment, and known limitations.

## Acceptance criteria

- [ ] A clean install starts the app using only the README and .env.example.
- [ ] The primary journey works from first visit through saved result, reload, edit, export, and deletion where applicable.
- [ ] Invalid input, missing configuration, provider failure, and an empty database each have a usable state.
- [ ] The interface works at 390px and 1440px, is keyboard navigable, and shows visible focus on every control.
- [ ] Tests, type checking, linting, and a production build all pass with no ignored failures.
- [ ] No part of the interface implies a live integration, security guarantee, or scale capability that was not actually built and verified.

## Non-goals

Do not build these, and do not claim to have replaced them:

- Instant templates.
- Cloud sandboxes.
- Preview URLs.
- Collaboration.
- Reliability at the vendor's scale is an operations problem, not a prompt.
- Permissions, presence, and shared workflows are difficult to simplify.

## What you still own after launch

- Run migrations, backups, restores, and dependency updates.
- Test the critical journey after every model, API, or hosting change.
- Monitor failures and fix the edge cases a first prompt will miss.

## Risk

**Operational risk.** The code is achievable; dependable data, integrations, and ongoing operations are the real cost.

Editorial confidence in this assessment: medium. No independent one-shot implementation is linked yet.

## Prior art

Working open-source software you can read, fork, or borrow from before starting:

- [code-server](https://github.com/coder/code-server) — Open-source VS Code in browser; building block for a self-hosted sandbox

---

Generated by [Can It Be Vibe Coded?](https://www.canitbevibecoded.com) · Full report: https://www.canitbevibecoded.com/codesandbox
