Troubleshooting
Start with the exact resource id and the operation that failed. Most requests also return an x-request-id header - include it in any support request.
miosa doctor # checks CLI version, config, endpoint, key, and clock skew A skewed clock breaks signed webhooks and expiring tokens, so miosa doctor is a fast first check.
Sandbox will not start
- Still
provisioning. The runtime is not ready yet. PollGET /api/v1/sandboxes/{id}and wait forstateto becomerunningandreadyto betrue. error. A boot or runtime failure. Checksbx.data["metadata"]forlast_error, then destroy and create a new sandbox.execis refused. A sandbox that is still starting rejects commands. The CLI’sexecretries with backoff for up to 90 seconds; SDK callers should do the same or wait forready.
Commands fail or hang
- A command returns non-zero. The sandbox exits with the remote command’s status. Read
stderr; nothing is silently swallowed. exectimes out. The max exec timeout is 300 seconds regardless of the sandbox’s own timeout. For long work, start a background process and poll its logs instead.- A file upload fails. The maximum file upload is 100 MB. Split larger artifacts or write them from inside the sandbox.
- HTTP
429. You hit a rate limit. Wait for the seconds in theRetry-Afterheader. See Rate limits.
Previews do not load
404or connection refused. Nothing is listening on the port you exposed. Confirm the server is bound to0.0.0.0, not just127.0.0.1, and that the port number matches.- A private preview needs a token. Private previews require a valid token. See Previews for visibility and sharing.
A secret is not working
Secrets are covered in depth in Security troubleshooting. That page catalogs the most common issues - a placeholder that is not swapped, an unbound or mismatched scope, and rotation that seems not to take effect - with root causes and fixes, alongside Connect Accounts, the Network Allowlist, the Audit Log, and white-label credentials.
The network is blocked
A sandbox starts in audit-only mode, so nothing is blocked until you enforce an allowlist. If a call is blocked, check the pending queue (sandbox.network.pending()) or filter the audit log by action=reject; each row names the rule in rejected_by. Common gaps (pip, npm, CDNs) are listed in Internet access and egress.
A deployment failed
- Build fails. Read the build logs for the deployment version; see the App Engine deploy guide for container build paths.
- A custom domain does not resolve. Apex records need ALIAS / ANAME support in your DNS provider.
- You need the previous version back. Roll back to a prior release; see Releases and Rollback.
For host, tunnel, and bring-your-own-cloud problems, see OpenComputers troubleshooting.
SSH and connections
There is no public SSH endpoint. miosa ssh, the SDK SSH tunnel, and preview URLs are the only ways in. See Connecting to a running sandbox.
Still stuck
Open a support ticket from the MIOSA dashboard and include the resource id, the operation, a timestamp with timezone, and the x-request-id. Remove API keys, tokens, and private URLs from anything you paste. See Support for other channels.