{"slug": "give-your-trigger-dev-agent-a-python-sandbox-with-plimsoll", "title": "Give your Trigger.dev agent a Python sandbox with plimsoll", "summary": "A developer built plimsoll, an Apache-2.0 code execution sandbox for AI agents, along with a starter integration for Trigger.dev that runs Python and JavaScript separately from the host task and supports persistent sessions keeping variables and files available between calls. The self-hosted Docker Compose recipe, tested on one host with Trigger.dev v4.7.2, runs the sandbox service beside the worker on a private Docker network and selects gVisor when available, with the starter tasks requiring the 'kernel' isolation tier by default.", "body_md": "An AI agent analysing data often needs to run code: calculate a total, inspect a file, or test an idea. That generated code needs a sandbox.\n\nI built **plimsoll**, an Apache-2.0 code execution sandbox, with an integration for Trigger.dev. It runs Python and JavaScript separately from your task, and supports sessions that keep variables and files available between calls.\n\nPlimsoll is pre-1.0. There is a working starter you can deploy, including a fixed Python task that checks the connection without calling an AI model.\n\nYour Trigger.dev task sends code to plimsoll. Plimsoll executes it in a sandbox and returns the output, along with the isolation tier used.\n\nFor self-hosted Trigger.dev, a Docker Compose recipe runs the sandbox service beside your worker on your infrastructure. Task containers reach it over a private Docker network.\n\nThe self-hosted recipe was tested on one host with Trigger.dev v4.7.2. Its README describes the setup and limitations:\n\n[https://github.com/plimsollmark/plimsoll-trigger-starter/tree/main/self-hosted](https://github.com/plimsollmark/plimsoll-trigger-starter/tree/main/self-hosted)\n\nClone the starter and install its dependencies using Node.js 22.18 or later:\n\n```\ngit clone https://github.com/plimsollmark/plimsoll-trigger-starter.git\ncd plimsoll-trigger-starter\nnpm ci\nnpm run typecheck\n```\n\nBefore deploying, follow the starter’s instructions to configure a plimsoll service your worker can reach:\n\n[https://github.com/plimsollmark/plimsoll-trigger-starter#prepare-plimsolld](https://github.com/plimsollmark/plimsoll-trigger-starter#prepare-plimsolld)\n\nFor self-hosted workers, use the Compose instructions linked above instead.\n\nSet `PLIMSOLL_URL` and the secret `PLIMSOLL_TOKEN` in your Trigger.dev project’s production environment. Set `TRIGGER_PROJECT_REF` for the deployment CLI.\n\nThen run:\n\n```\nnpm run deploy -- --dry-run\nnpm run deploy\n```\n\nYour project should list two tasks: `code-chat` and `deployed-cell-trial`.\n\nThe verification task sends two separate Python calls to one sandbox session.\n\nThe first creates a list and returns its length:\n\n```\nnumbers = [2, 3, 5]\nlen(numbers)\n```\n\nThe second uses the same list:\n\n```\nsum(numbers)\n```\n\nThe expected results are `3` and `10`.\n\nThe second call depends on a variable created by the first. Like two cells in a notebook, they share a running Python interpreter.\n\nSupply your Trigger.dev production API key as `TRIGGER_SECRET_KEY` through your shell or secret manager, then run:\n\n```\nnpm run trial\n```\n\nFor self-hosted Trigger.dev, also set `TRIGGER_API_URL` to your own Trigger.dev address before running the command.\n\nThe task checks the outputs, interpreter reuse, and minimum isolation level. It closes the sandbox when finished, including when a check fails.\n\nA successful run reports `interpreterReused: true` and, with the default isolation requirement, `kernel` for both calls. A broken session or insufficient isolation makes the task fail.\n\nThis trial makes no AI call. Infrastructure charges can still apply.\n\nThe included chat agent exposes an `executeCode` tool and follows Trigger.dev’s documented sandbox lifecycle:\n\n`onTurnStart`.` onChatSuspend` or `onComplete`.\nVariables and files remain available while the session exists. Once it closes, a later session starts fresh.\n\nThis lets an agent load data, inspect it, and calculate results across several calls without rebuilding its workspace every time.\n\nRunning the chat agent requires its model credentials and incurs model usage charges. The fixed verification task does not.\n\nTrigger.dev’s sandbox pattern is documented here:\n\n[https://trigger.dev/docs/ai-chat/patterns/code-sandbox](https://trigger.dev/docs/ai-chat/patterns/code-sandbox)\n\nThe self-hosted Compose setup selects gVisor when available and runc otherwise.\n\ngVisor adds a separate kernel boundary for sandboxed code. Ordinary runc containers share the host kernel and provide a weaker boundary.\n\nThe starter tasks require the `kernel` isolation tier by default. If the service only provides the `container` tier, the tasks refuse to execute unless you explicitly lower that requirement. Keep the stronger requirement for hostile code.\n\nPlimsoll’s daemon is trusted infrastructure: it holds the Docker socket, which gives it powerful access to the host. The self-hosted README also documents credential logging observed with Trigger.dev v4.7.2 and other deployment limits.\n\nThe starter includes the chat integration, a deployed verification task, and the self-hosted Compose recipe:\n\nI maintain plimsoll, and I’d like feedback from people using it with Trigger.dev. If you try it, tell me what broke, especially during setup or when connecting it to an existing worker.", "url": "https://wpnews.pro/news/give-your-trigger-dev-agent-a-python-sandbox-with-plimsoll", "canonical_source": "https://dev.to/carroll_guertin_f06b4f83a/give-your-triggerdev-agent-a-python-sandbox-with-plimsoll-4gf", "published_at": "2026-10-06 11:02:33+00:00", "updated_at": "2026-10-06 11:18:09.107216+00:00", "lang": "en", "topics": ["ai-agents", "ai-tools", "developer-tools", "ai-infrastructure"], "entities": ["plimsoll", "Trigger.dev", "gVisor", "runc", "Docker Compose", "Node.js", "Python", "JavaScript"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/give-your-trigger-dev-agent-a-python-sandbox-with-plimsoll", "markdown": "https://wpnews.pro/news/give-your-trigger-dev-agent-a-python-sandbox-with-plimsoll.md", "text": "https://wpnews.pro/news/give-your-trigger-dev-agent-a-python-sandbox-with-plimsoll.txt", "jsonld": "https://wpnews.pro/news/give-your-trigger-dev-agent-a-python-sandbox-with-plimsoll.jsonld"}}