About this project

OpenSandbox is a general-purpose sandbox platform aimed at AI applications. According to its README, it provides a secure, scalable execution environment for workloads such as Coding Agents, GUI Agents, Agent Evaluation, AI Code Execution and RL Training, with a consistent API from a laptop to a large cluster. Key capabilities described: - SDKs, CLI and MCP: native SDKs for Python, Java/Kotlin, TypeScript, C#/.NET and Go, plus the `osb` command-line tool and an MCP server. The README presents one API surface for sandbox creation, command execution and file operations. - Open protocol: sandbox lifecycle and execution APIs are defined as public OpenAPI contracts, so custom runtimes can be integrated without changing client code. - Runtimes and environments: Docker and Kubernetes runtimes are available behind the same SDK calls, with built-in Command, Filesystem and Code Interpreter environments. Documented use cases include coding CLIs (Claude Code, Gemini CLI, Codex CLI, OpenCode, Qwen Code, Kimi CLI), browser automation (Chrome, Playwright) and desktop environments (VNC, VS Code / code-server). - Hybrid deployment: the project describes mixing long-running Kubernetes-native container workloads with short-lived microVM sandboxes in one cluster. It mentions pre-warmed Firecracker-backed pools for constant-time admission and roughly 80ms startup, and FastSandbox pause/resume that checkpoints state to an artifact store and releases compute, resuming on any host. - Network policy and credential vault: a unified ingress gateway with multiple routing strategies, per-sandbox egress controls, and credential injection intended to keep real secrets away from sandbox workloads. - Strong isolation: workloads can run under gVisor, Kata Containers or Firecracker microVMs for isolation from the host. Getting started: the README lists Docker and Python 3.10+ as requirements. A sandbox server can be initialized and started with `uvx opensandbox-server init-config ~/.sandbox.toml --example docker` and `uvx opensandbox-server`. The Python SDK is installed with `pip install opensandbox`, and a short example shows creating an Alpine-based sandbox, running shell commands, writing and reading files, executing a script, and destroying the sandbox. Official container images are published to Docker Hub, GitHub Container Registry and Alibaba Cloud Container Registry. The README states that tagged release images are signed keylessly with Cosign and include provenance attestations, and it recommends pinning production images by digest and verifying them against the OpenSandbox GitHub Actions identity. Documentation covers architecture, credential vault, release verification, enhancement proposals, SDK references, CLI, MCP server, OpenAPI specs and server configuration. The project is licensed under Apache 2.0 and offers GitHub Issues, Discord and DingTalk channels for discussion.