StackMap
Subscribe

agent-sandbox vs tensorlake

Kubernetes SIG Apps' Sandbox CRD and controller: stateful singleton pods with stable identity and persistent storage for agent runtimes and RL — templates, claims, warm pools; gVisor/Kata isolation. — versus — Serverless platform for agent sandboxes: stateful Firecracker microVMs with snapshots, cloning, auto suspend/resume and network policy, plus fan-out orchestration functions. Python SDK and CLI.

The curated verdict

Stateful, suspendable per-agent sandboxes either way: agent-sandbox keeps them as Kubernetes resources in your cluster, Tensorlake runs them as managed Firecracker VMs.

agent-sandboxtensorlake
Stars4.1k1.0k
Forks532148
LanguageGoPython
LicenseApache-2.0Apache-2.0
Last activity3 days agotoday
Topicssandboxes, agentssandboxes, agents
Curated connections64

agent-sandbox — the curator's take

Pick agent-sandbox when you already run Kubernetes and want agent sandboxes as a declarative, first-class resource: one long-lived pod per agent with a stable hostname, persistent volume, pause/resume and scheduled deletion, plus warm pools so claims start fast. It's upstream Kubernetes (SIG Apps), so it's the boring, vendor-neutral choice, with Go and Python SDKs and a router for reaching pods. The catch is in its own scope note: it orchestrates, it doesn't isolate. Security comes from the RuntimeClass you configure (gVisor, Kata); on the default runtime it's just a pod. No cluster? A microVM runtime like cubesandbox or a hosted sandbox SDK is far less machinery.

tensorlake — the curator's take

Pick Tensorlake when you want hosted sandboxes that behave like real machines: stateful Firecracker VMs that suspend when idle and resume with memory intact, snapshot and clone mid-run, live-migrate, and take per-sandbox egress allowlists, plus a serverless function runtime to fan out agent work with each function in its own sandbox. This repo is the SDK and CLI; the runtime is Tensorlake Cloud, so it is an API key, not something you self-host. The filesystem benchmark against E2B, Modal and Daytona is their own. Need it on your own hardware? cubesandbox or agent-sandbox. Running one agent's code locally? A container may be enough.