cocoon sandbox
MicroVM sandboxes for AI agents, built on
cocoon. Warm claims are
sub-millisecond; a pool miss clones from a golden snapshot in tens of
milliseconds; cold boot is ~0.2–0.4 s on bare metal.
SDK (Go/Python) sandboxd (per node) guest microVM
client.New/new ─ HTTP ─► claim: warm pool / golden clone Cloud Hypervisor
exec/files/… ─ HTTP upgrade (kept) ─► byte relay ─ vsock ─► silkd :2048
memberlist mesh: warm-count gossip,
MOVED-style redirect to the owning node
Cloud Hypervisor serves both network lanes. net=none has no NIC and uses
vsock-only I/O (hardened default); net=egress attaches a bridge/CNI NIC.
Guides
- Deploying sandboxd — single node, configuration reference,
images, running as a service
- Clusters — joining a mesh, querying members, how redirect
placement works, relocating handles
- sandboxd HTTP API — every endpoint: claim/release,
renew, hibernate, fork, promote, checkpoints, preview, the guest-port
relay, claim env, runtime tenants, config reload, online pool
reconfigure, metrics, the usage journal
- Go SDK — connecting (single node and clusters), every option,
the full sandbox surface, error handling
- Python SDK — the guest and data-plane surface for the
Python-first agent ecosystem, stdlib-only; node pool retuning remains Go-only
- LangChain toolkit — sandbox tools for LangChain/LangGraph
agents, with checkpoint branching
- MCP server — sandboxes as Model Context Protocol tools for
Claude Code, Cursor, and agent frameworks
- OpenAI Agents SDK adapter — run Agents SDK tools
inside cocoon microVMs via the custom sandbox-provider interface
- Android sandboxes — the redroid flavor: claim shape, adb
access through the relay, checkpoint/branch
- Browser sandboxes — headless Chromium with CDP through
the relay: Playwright/Puppeteer access, checkpoint/branch of a live
browser
- e2b sandboxes — the e2b-rt and e2b-ci flavors: e2b’s envd on
loopback beside silkd, e2b’s code interpreter, the guest half of the
e2b-compatible data plane, and the warm-pool gate that keeps a claim from
outrunning it
- Guarded egress — allow-listed, audited outbound access with
host-side credential injection, on both lanes: no NIC (none) or an
nftables-locked NIC (egress)
- Security model — trust boundaries, what a compromised
guest can reach, the deployment assumptions the guarantees rest on, and
the honest limitations
- silkd — the in-guest daemon: protocol, verb reference, lanes
and limits
- Performance — measured latencies and the environments
they were measured in
- Benchmarks — what each number measures,
make bench
reproduction, and the dated results log
Repository
Source and issue tracker:
github.com/cocoonstack/sandbox.