agent-sandbox vs tensorlake
Kubernetes SIG Apps' Sandbox CRD and controller: stateful singleton pods with stable identity and persistent storage for agent runtimes and RL — templates, claims, warm pools; gVisor/Kata isolation. — versus — Serverless platform for agent sandboxes: stateful Firecracker microVMs with snapshots, cloning, auto suspend/resume and network policy, plus fan-out orchestration functions. Python SDK and CLI.
Stateful, suspendable per-agent sandboxes either way: agent-sandbox keeps them as Kubernetes resources in your cluster, Tensorlake runs them as managed Firecracker VMs.
| agent-sandbox | tensorlake | |
|---|---|---|
| Stars | 4.1k | 1.0k |
| Forks | 532 | 148 |
| Language | Go | Python |
| License | Apache-2.0 | Apache-2.0 |
| Last activity | 3 days ago | today |
| Topics | sandboxes, agents | sandboxes, agents |
| Curated connections | 6 | 4 |
agent-sandbox — the curator's take
Pick agent-sandbox when you already run Kubernetes and want agent sandboxes as a declarative, first-class resource: one long-lived pod per agent with a stable hostname, persistent volume, pause/resume and scheduled deletion, plus warm pools so claims start fast. It's upstream Kubernetes (SIG Apps), so it's the boring, vendor-neutral choice, with Go and Python SDKs and a router for reaching pods. The catch is in its own scope note: it orchestrates, it doesn't isolate. Security comes from the RuntimeClass you configure (gVisor, Kata); on the default runtime it's just a pod. No cluster? A microVM runtime like cubesandbox or a hosted sandbox SDK is far less machinery.
tensorlake — the curator's take
Pick Tensorlake when you want hosted sandboxes that behave like real machines: stateful Firecracker VMs that suspend when idle and resume with memory intact, snapshot and clone mid-run, live-migrate, and take per-sandbox egress allowlists, plus a serverless function runtime to fan out agent work with each function in its own sandbox. This repo is the SDK and CLI; the runtime is Tensorlake Cloud, so it is an API key, not something you self-host. The filesystem benchmark against E2B, Modal and Daytona is their own. Need it on your own hardware? cubesandbox or agent-sandbox. Running one agent's code locally? A container may be enough.