🔌 API & Nền tảng•Mã nguồn mở•
OpenSandbox
Cloud sandbox từ Alibaba, chạy code AI-generated trong container cách ly với VM-level security, hỗ trợ 15+ runtime.
#opensandbox
Danh mục
🔌 API & Nền tảng
Giá
Mã nguồn mở
GitHub Stars
⭐ 15,649
Ngôn ngữ
Python
License
Apache-2.0
Ngày thêm
2026-03-27
Tóm tắt từ README GitHub
OpenSandbox
Run AI agents in sandboxes on your own infrastructure.
OpenSandbox gives AI applications isolated environments to execute code, run commands, manage files, and operate browsers or desktops. Start locally with Docker and deploy on Kubernetes through a unified sandbox API.
Quick Start · Examples · Documentation · Fast Sandbox
Features
Feature What it enables Learn more
--------- ----------------- ------------
Fast Sandbox runtime Fast, high-density sandboxes on Kubernetes. Reference warm Firecracker creation: 97 ms P50 (serial) / 308 ms P99 (10 concurrent) . Firecracker sandboxes support pause/resume with memory and disk state preserved. Integration · Performance · Pause/resume
Agent working environments Execute commands, manage files, and run code with built-in APIs. Integration examples show how to run coding agents, browsers, and desktops inside sandboxes. Examples
Network access control Route inbound traffic through a unified ingress gateway and control outbound access with per-sandbox egress policies. Ingress · Egress
Credential Vault Let agents call external services without exposing real credentials to sandbox workloads. Credential Vault
Local to cluster
Xem thêm từ README.mdThu gọn README.md
Đánh giá chi tiết
Tổng quan
OpenSandbox là nền tảng cloud sandbox mã nguồn mở từ Alibaba, cho phép chạy code AI-generated trong môi trường container cách ly với VM-level security. OpenSandbox cung cấp API để tạo sandbox on-demand, chạy code, quản lý file, và dọn dẹp tự động. Repo có hơn 9,300 stars, viết bằng Go.
Tính năng chính
- Container sandbox với VM-level isolation (gVisor/Kata)
- 15+ runtime có sẵn: Python, Node.js, Go, Rust, Java, C++
- REST API: tạo sandbox, upload file, chạy code, lấy output
- Resource limits: CPU, RAM, disk, network per-sandbox
- Auto cleanup: sandbox tự hủy sau timeout
- Snapshot/restore: lưu và khôi phục trạng thái sandbox
Stack kỹ thuật
- Go, Docker/containerd
- gVisor hoặc Kata containers cho isolation
- REST API + WebSocket streaming
Điểm mạnh
- VM-level security: code chạy trong sandbox không thoát ra được
- 15+ runtime sẵn có, không cần build image
- API đơn giản, tích hợp vào AI agent/pipeline dễ dàng
- Resource control chặt, tránh abuse
Hạn chế
- Cần self-host, không có managed service
- Yêu cầu Docker + gVisor/Kata, setup không trivial
- Documentation còn thiếu so với E2B (đối thủ)
- GPU support chưa có
Phù hợp khi nào
Khi build AI agent cần chạy code user/AI-generated an toàn, đặc biệt nếu muốn self-host và cần VM-level isolation thay vì Docker thông thường.