# Secure, Fast, and Extensible Sandbox Runtime for AI Agents

> Source: <https://github.com/TencentCloud/CubeSandbox>
> Published: 2026-07-29 18:03:10+00:00

**Instant, Concurrent, Secure & Lightweight Sandbox Service for AI Agents**

[ 中文文档](/TencentCloud/CubeSandbox/blob/master/README_zh.md) ·

[·](/TencentCloud/CubeSandbox/blob/master/docs/guide/quickstart.md)

**Quick Start**[·](/TencentCloud/CubeSandbox/blob/master/docs/index.md)

**Documentation**[·](/TencentCloud/CubeSandbox/blob/master/docs/changelog/index.md)

**Changelog**[·](https://x.com/CubeSandbox_AI)

**X(Twitter)**[·](https://github.com/TencentCloud/CubeSandbox/issues/1040)

**Top Contributor Program**

**Submit Use Case** Cube Sandbox is a high-performance, out-of-the-box secure sandbox service built on RustVMM and KVM. It supports both single-node deployment and easy scaling to multi-node clusters. It is compatible with the E2B SDK and can create a hardware-isolated, fully serviceable sandbox in under 60ms with less than 5MB of memory overhead.

|
|

**v0.6: K8s deploy, Volume framework, template aliases****K8s deploy**— Deploy Cube control-plane components and compute nodes on Kubernetes** Volume framework**— E2B-compatible Volume framework that lets users plug in custom backend storage** Template aliases**— Set an alias when creating a template, and create sandboxes by specifying that alias.[Changelog →](/TencentCloud/CubeSandbox/blob/master/docs/changelog/v0.6.0.md)·[K8s deploy →](/TencentCloud/CubeSandbox/blob/master/docs/guide/kubernetes)·[Volume plugin →](/TencentCloud/CubeSandbox/blob/master/docs/guide/volume-plugin.md)**v0.5: AutoPause, Terraform deployer, ARM64 & network policy hardening****AutoPause/AutoResume**— idle sandboxes auto-suspend and wake on the next request.** Terraform one-click cluster deploy****ARM64** native full-stack support**network policy hardening**— per-sandbox traffic tokens, policy-routing egress.[Changelog →](/TencentCloud/CubeSandbox/blob/master/docs/changelog/v0.5.0.md)·[Terraform deploy →](/TencentCloud/CubeSandbox/blob/master/docs/guide/tencentcloud-terraform-deploy.md)**v0.4: Safer egress, easier ops****Credential vault**— Agents call external APIs as usual; keys never enter the sandbox.** Dashboard**— version matrix and template health checks; see at a glance whether templates need rebuilding after upgrades.[Changelog →](/TencentCloud/CubeSandbox/blob/master/docs/changelog/v0.4.0.md)·[Security proxy guide →](/TencentCloud/CubeSandbox/blob/master/docs/guide/security-proxy.md)·[WebUI guide →](/TencentCloud/CubeSandbox/blob/master/docs/guide/webui.md)**Snapshot, Clone & Rollback at hundred-millisecond granularity** CubeSandbox 0.3.0 introduces the

**CubeCoW** Copy-on-Write snapshot engine, enabling event-level snapshots, instant cloning, and rollback to any saved state.[Changelog →](/TencentCloud/CubeSandbox/blob/master/docs/changelog/v0.3.0.md)**🎉 Initial open-source release** Cube Sandbox is now open source! Millisecond boot, hardware-level isolation, E2B-compatible sandbox for AI Agents.

[Changelog →](/TencentCloud/CubeSandbox/blob/master/docs/changelog/v0.1.0.md)
⚡ Ultra-fast StartupResource pooling and snapshot cloning skip all cold-start overhead. Average <60ms cold start — sandbox creation faster than a blink.
|
🔒 Hardware IsolationEvery sandbox runs a dedicated OS kernel in its own MicroVM.
|
🔌 E2B SDK CompatibleCompatible with E2B SDK interface. Switch from E2B Cloud seamlessly by changing one environment variable — zero client code changes.
|
📦 High-density Deployment<5MB overhead per sandbox enables thousands of instances per server via kernel sharing and Copy-on-Write (CoW). Supports automatic sandbox pause and resume, further improving deployment density and cost optimization.
|
🛡️ Network SecurityeBPF-based inter-sandbox isolation and egress filtering at kernel level; built-in L7 security proxy enables per-domain/path/method policies with automatic credential injection — secrets never visible to sandbox code.
|
📸 Flexible State ManagementHigh-frequency snapshot and rollback at hundred-millisecond granularity. Create checkpoints on running sandboxes, roll back to any saved state at any time, or fork from a specific state to explore in parallel.
|
💾 Volume FrameworkE2B-compatible Volume framework that lets users plug in custom backend storage solutions. Volumes have an independent lifecycle and can be shared across sandboxes.
|
🚀 Production DeploymentDeploy production clusters on Tencent Cloud with one click using Terraform. Also supports deployment on standard Kubernetes clusters (preview).
|
💪 ARM Architecture SupportFull native ARM64 support across compilation, build, and deployment workflows.
|

## 1.cubesandbox.-.mp4 |
## 2.cubesandbox.demo.mp4 |
## Cube-Sandbox.RL.demo.mp4 |
## 5.cube.V0.3.0.-.-.mp4 |
Installation & Demo
|
Performance Test
|
RL (SWE-Bench)
|
Snapshot · Clone · Rollback
|

In the context of AI Agent code execution, CubeSandbox achieves the perfect balance of security and performance:

| Metric | Docker Container | Traditional VM | CubeSandbox |
|---|---|---|---|
Isolation Level |
Low (Shared Kernel Namespaces) | High (Dedicated Kernel) | Extreme (Dedicated Kernel + eBPF) |
Boot Speed *Full-OS boot duration |
200ms | Seconds | Sub-millisecond (<60ms) |
Memory Overhead |
Low (Shared Kernel) | High (Full OS) | Ultra-low (Aggressively stripped, <5MB) |
Deployment Density |
High | Low | Extreme (Thousands per node) |
E2B SDK Compatible |
/ | / | ✅ Drop-in |

*Cold start benchmarked on bare-metal. 60ms at single concurrency; under 50 concurrent creations, avg 67ms, P95 90ms, P99 137ms — consistently sub-150ms.**Memory overhead measured with sandbox specs ≤ 32GB. Larger configurations may see a marginal increase.*

For detailed metrics on startup latency and resource overhead, see the [Core Operations Performance Benchmark Report](/TencentCloud/CubeSandbox/blob/master/docs/blog/posts/2026-06-01-cubesandbox-perf-benchmark.md) (bare metal) and the [PVM Cloud Server Benchmark Report](/TencentCloud/CubeSandbox/blob/master/docs/blog/posts/2026-06-03-cubesandbox-perf-benchmark-pvm.md).

*⚡ Millisecond-level startup — watch the fast-start flow above.*

Cube Sandbox requires an **x86_64 Linux** environment with **KVM** support.

The guide walks you through everything in **four steps** — provisioning a server, installing Cube Sandbox, creating a sandbox template, and running your first agent code. No source build needed, up and running in minutes.

**Choose your deployment path:**

|
🏆 Recommended |

[🏗 Bare Metal →](/TencentCloud/CubeSandbox/blob/master/docs/guide/bare-metal-deploy.md)[💻 Dev-Env →](/TencentCloud/CubeSandbox/blob/master/docs/guide/dev-environment.md)⚠️ **Not recommended — poor performance**
*🖥️ Visual management — from overview to creating a sandbox and streaming logs, all in your browser.*

After one-click deployment, open in your browser:

```
http://<control-node IP>:12088
```

**Recommended three steps:**

**Check overview**— Open** Overview**, confirm nodes are Ready and capacity looks healthy** Prepare a template**— Install an official preset from** Template Store**; skip if you already have a`READY`

template under**Templates****Create a sandbox**—** Sandboxes → + New sandbox**, pick a`READY`

template, and view live logs on the detail page within seconds

See the full [WebUI console guide](/TencentCloud/CubeSandbox/blob/master/docs/guide/webui.md).

[Documentation Home](/TencentCloud/CubeSandbox/blob/master/docs/index.md)— complete guide navigation- ☁️
[PVM Deployment](/TencentCloud/CubeSandbox/blob/master/docs/guide/pvm-deploy.md)— deploy on ordinary cloud VMs without bare metal or nested virtualization [Template Concepts](/TencentCloud/CubeSandbox/blob/master/docs/guide/templates.md)— image-to-template concepts and workflows[Example Projects](/TencentCloud/CubeSandbox/blob/master/docs/guide/tutorials/examples.md)— hands-on examples (code execution, browser automation, OpenClaw integration, RL training, and more)- 🖥️
[WebUI Console](/TencentCloud/CubeSandbox/blob/master/docs/guide/webui.md)— visual management right after install (`:12088`

) - 🔐
[Security Proxy & Credential Vault](/TencentCloud/CubeSandbox/blob/master/docs/guide/security-proxy.md)— CubeEgress domain filtering, injection, and auditing - 🤖
[Digital Assistant AgentHub](/TencentCloud/CubeSandbox/blob/master/docs/guide/digital-assistant.md)— create and manage OpenClaw assistants (Preview) - 💻
[Development Environment (QEMU VM)](/TencentCloud/CubeSandbox/blob/master/docs/guide/dev-environment.md)— no KVM access? Try Cube Sandbox inside a disposable OpenCloudOS 9 VM

| Component | Responsibility |
|---|---|
CubeAPI |
High-concurrency REST API Gateway (Rust), compatible with E2B. Swap the URL for seamless migration. |
CubeMaster |
Cluster orchestrator. Receives API requests and dispatches them to corresponding Cubelets. Manages resource scheduling and cluster state. |
CubeProxy |
Reverse proxy, compatible with the E2B protocol, routing requests to the appropriate sandbox instances. |
Cubelet |
Compute node local scheduling component. Manages the complete lifecycle of all sandbox instances on the node. |
CubeVS |
eBPF-based virtual switch, providing kernel-level network isolation and security policy enforcement. |
CubeEgress |
OpenResty-based egress security gateway: L7 domain filtering, credential injection, and access auditing; works with CubeVS kernel policies so sandbox traffic cannot bypass inspection. |
CubeHypervisor & CubeShim |
Virtualization layer — CubeHypervisor manages KVM MicroVMs, CubeShim implements the containerd Shim v2 API to integrate sandboxes into the container runtime. |

👉 For more details, please read the [Architecture Design Document](/TencentCloud/CubeSandbox/blob/master/docs/architecture/overview.md) and [CubeVS Network Model](/TencentCloud/CubeSandbox/blob/master/docs/architecture/network.md).

We welcome contributions of all kinds—whether it's a bug report, feature suggestion, documentation improvement, or code submission!

- 🐞
**Found a Bug or have questions?** Submit an issue on[GitHub Issues](https://github.com/tencentcloud/CubeSandbox/issues). - 💡
**Have an Idea?** Join the conversation in[GitHub Discussions](https://github.com/tencentcloud/CubeSandbox/discussions). - 🛠️
**Want to Code?** Check out our[CONTRIBUTING.md](/TencentCloud/CubeSandbox/blob/master/CONTRIBUTING.md)to learn how to submit a Pull Request. - 📝
**Want to contribute docs?** Submit bilingual PRs to our community doc channels:[Troubleshooting](/TencentCloud/CubeSandbox/blob/master/docs/guide/troubleshooting/index.md),[Use Cases](/TencentCloud/CubeSandbox/blob/master/docs/guide/usecases/index.md), and[Integrations](/TencentCloud/CubeSandbox/blob/master/docs/guide/integrations/index.md). Additionally, the**Cube 100 Program** is now open — we're looking for the first 100 teams running AI agents in production with Cube. Limited to 100 seats.**Learn more & apply →** - 💬
**Want to Chat?** Join our[Discord](https://discord.gg/kkapzDXShb).

**Coming soon** — see the [full roadmap](/TencentCloud/CubeSandbox/blob/master/docs/guide/roadmap.md) for details.

| Feature | Description |
|---|---|
Kubernetes-Native Deployment |
Evolve from Helm-based deployment toward CRD- and Operator-centric native management, with smooth upgrade capabilities |
Cross-Node Pause & Resume |
Suspend a sandbox on one node and resume it on another with full memory and filesystem state preserved |
E2B API Compatibility |
Close remaining gaps with the E2B specification for full drop-in compatibility |
Control Plane / Data Plane Separation |
Decouple the control plane from the data plane so control plane upgrades or failures never affect sandboxes already in flight |
Sandbox Fault Recovery |
Automatic detection and recovery of crashed VMs, stuck shim processes, and network partitions with configurable recovery policies |
Scheduling & Operations Enhancements |
Resource-aware placement, affinity rules, live rebalancing, and node drain with sandbox migration |

CubeSandbox is released under the [Apache License 2.0](/TencentCloud/CubeSandbox/blob/master/LICENSE).

The birth of CubeSandbox stands on the shoulders of open-source giants. Special thanks to [Cloud Hypervisor](https://github.com/cloud-hypervisor/cloud-hypervisor), [Kata Containers](https://github.com/kata-containers/kata-containers), virtiofsd, containerd-shim-rs, ttrpc-rust, and others. We have made tailored modifications to some components to fit the CubeSandbox execution model, and the original in-file copyright notices are preserved.

Cube Sandbox is listed in the [CNCF Landscape](https://landscape.cncf.io/?landscape=observability-and-analysis&group=ai-native&item=ai-native-infra--workload-runtime--cubesandbox).
