agent-sandbox vs ax
Kubernetes SIG Apps' Sandbox CRD and controller: stateful singleton pods with stable identity and persistent storage for agent runtimes and RL — templates, claims, warm pools; gVisor/Kata isolation. — versus — Google's declarative runtime for agent workloads on Kubernetes: Task, Workspace and Model manifests run each agent sandboxed on Agent Substrate, with suspend/resume and ax ssh.
Both make agent workloads first-class Kubernetes resources with suspend and resume; agent-sandbox is SIG Apps' Sandbox CRD over gVisor/Kata pods, AX adds Task, Workspace and Model manifests on Google's Agent Substrate and pre-wires repos, MCP servers and skills.
| agent-sandbox | ax | |
|---|---|---|
| Stars | 4.1k | 13k |
| Forks | 532 | 626 |
| Language | Go | Go |
| License | Apache-2.0 | Apache-2.0 |
| Last activity | 6 days ago | 4 days ago |
| Topics | sandboxes, agents | orchestration, sandboxes |
| Curated connections | 7 | 3 |
agent-sandbox — the curator's take
Pick agent-sandbox when you already run Kubernetes and want agent sandboxes as a declarative, first-class resource: one long-lived pod per agent with a stable hostname, persistent volume, pause/resume and scheduled deletion, plus warm pools so claims start fast. It's upstream Kubernetes (SIG Apps), so it's the boring, vendor-neutral choice, with Go and Python SDKs and a router for reaching pods. The catch is in its own scope note: it orchestrates, it doesn't isolate. Security comes from the RuntimeClass you configure (gVisor, Kata); on the default runtime it's just a pod. No cluster? A microVM runtime like cubesandbox or a hosted sandbox SDK is far less machinery.
ax — the curator's take
Worth watching if you run agents at fleet scale on Kubernetes. AX treats an agent as its own kind of workload, neither service nor batch job: declare a Task with a goal, a Workspace that pre-wires Git repos, MCP servers and skill packages, and a Model, then `ax apply`, `ax watch`, `ax ssh` into the sandbox, and suspend idle agents to resume later. kubectl users will feel at home. The catch is in its own warning banner: heavy development, v1alpha1 APIs and breaking changes expected before a stable release, and Agent Substrate must already run in your cluster. Not for a laptop or a single agent; for a stable Kubernetes primitive today, use agent-sandbox.