StackMap
Subscribe
Explore / agent-sandbox
kubernetes-sigs

agent-sandbox

Kubernetes SIG Apps' Sandbox CRD and controller: stateful singleton pods with stable identity and persistent storage for agent runtimes and RL — templates, claims, warm pools; gVisor/Kata isolation.

4,044 530 Go Apache-2.0updated 3 days ago
View on GitHubDispute this mapping →
Curator's take

Pick agent-sandbox when you already run Kubernetes and want agent sandboxes as a declarative, first-class resource: one long-lived pod per agent with a stable hostname, persistent volume, pause/resume and scheduled deletion, plus warm pools so claims start fast. It's upstream Kubernetes (SIG Apps), so it's the boring, vendor-neutral choice, with Go and Python SDKs and a router for reaching pods. The catch is in its own scope note: it orchestrates, it doesn't isolate. Security comes from the RuntimeClass you configure (gVisor, Kata); on the default runtime it's just a pod. No cluster? A microVM runtime like cubesandbox or a hosted sandbox SDK is far less machinery.

Mapped by ShipWithAI editors · links verified

Continue your stack

What teams reach for next — and why each earns a place beside agent-sandbox. Ranked by curator confidence.

pairs wellpairs wellalternativealternativealternativellm-dpipelockOpenSandboxCubeSandboxsuperserveagent-sandbox
pairs wellalternativebuilt withpick a node for the why · open it from the panel
Weekly digest
README.md2 min read
Agent Sandbox logo

Agent Sandbox

GitHub release Apache-2.0 license

Website · Docs · DeepWiki · Getting Started · Examples · Roadmap

agent-sandbox enables easy management of isolated, stateful, singleton workloads, ideal for use cases like AI agent runtimes and reinforcement learning.

This project is developing a Sandbox Custom Resource Definition (CRD) and controller for Kubernetes, under the umbrella of SIG Apps. The goal is to provide a declarative, standardized API for managing workloads that require the characteristics of a long-running, stateful, singleton container with a stable identity, much like a lightweight, single-container VM experience built on Kubernetes primitives.

[!NOTE] Scope: Agent Sandbox is a sandbox orchestrator. It delegates low-level container isolation to secure "Sandbox Runtimes" (like gVisor or Kata Containers) by managing Pods configured to use these runtimes (via RuntimeClass).

Overview

Core: Sandbox

The Sandbox CRD is the core of agent-sandbox. It provides a declarative API for managing a single, stateful pod with a stable identity and persistent storage. This is useful for workloads that don't fit well into the stateless, replicated model of Deployments or the numbered, stable model of StatefulSets.

Key features of the Sandbox CRD include:

  • Stable Identity: Each Sandbox has a stable hostname and network identity.
  • Persistent Storage: Sandboxes can be configured with persistent storage that survives restarts.
  • Lifecycle Management: The Sandbox controller manages the lifecycle of the pod, including creation, scheduled deletion, pausing and resuming.

Extensions

The extensions module provides additional CRDs and controllers that build on the core Sandbox API to provide more advanced features.

  • SandboxTemplate: Provides a way to define reusable templates for creating Sandboxes, making it easier to manage large numbers of similar Sandboxes.
  • SandboxClaim: Allows users to create Sandboxes from a SandboxWarmPool, abstracting away the details of the underlying Sandbox configuration.
  • SandboxWarmPool: Manages a pool of pre-warmed Sandboxes that can be quickly allocated to users, reducing the time it takes to get a new Sandbox up and running.

Architecture

agent-sandbox follows the Kubernetes controller pattern. Users create a Sandbox custom resource, and the controller manages the underlying runtime resources.

Architecture Diagram

flowchart LR

    User[User]

    Claim[SandboxClaim]
    Template[SandboxTemplate]
    Sandbox[Sandbox]

    Pod[Pod]
    Runtime[Sandbox Runtime]

    WarmPool[SandboxWarmPool]

    subgraph Extensions[Extensions]
      Claim
      Template
      WarmPool
    end

    %% User paths
    User -->|creates| Sandbox
    User -->|creates| Claim

    %% Claim workflow
    WarmPool -->|references| Template
    Claim -->|adopts| Sandbox

    %% Pod handling
    Claim -->|adopts sandboxes from| WarmPool
    Sandbox -->|creates Pod| Pod

    %% Runtime
    Pod --> Runtime

    %% Warm pool
    WarmPool -->|pre-warms sandboxes| Sandbox

Installation

Standard Install (Core + Extensions)

Recommended for most users:

# Quick install (latest release):
kubectl apply -f https://github.com/kubernetes-sigs/agent-sandbox/releases/la