Secure, Fast, and Extensible Sandbox Runtime for AI Agents Tencent Cloud has open-sourced Cube Sandbox, a high-performance secure sandbox runtime for AI agents built on RustVMM and KVM that creates hardware-isolated sandboxes in under 60ms with less than 5MB of memory overhead. The v0.6 release adds Kubernetes deployment, an E2B-compatible volume framework, and template aliases, while the project supports snapshot, clone, and rollback at hundred-millisecond granularity via its CubeCoW engine. Instant, Concurrent, Secure & Lightweight Sandbox Service for AI Agents 中文文档 /TencentCloud/CubeSandbox/blob/master/README zh.md · · /TencentCloud/CubeSandbox/blob/master/docs/guide/quickstart.md Quick Start · /TencentCloud/CubeSandbox/blob/master/docs/index.md Documentation · /TencentCloud/CubeSandbox/blob/master/docs/changelog/index.md Changelog · https://x.com/CubeSandbox AI X Twitter · https://github.com/TencentCloud/CubeSandbox/issues/1040 Top Contributor Program Submit Use Case Cube Sandbox is a high-performance, out-of-the-box secure sandbox service built on RustVMM and KVM. It supports both single-node deployment and easy scaling to multi-node clusters. It is compatible with the E2B SDK and can create a hardware-isolated, fully serviceable sandbox in under 60ms with less than 5MB of memory overhead. | | v0.6: K8s deploy, Volume framework, template aliases K8s deploy — Deploy Cube control-plane components and compute nodes on Kubernetes Volume framework — E2B-compatible Volume framework that lets users plug in custom backend storage Template aliases — Set an alias when creating a template, and create sandboxes by specifying that alias. Changelog → /TencentCloud/CubeSandbox/blob/master/docs/changelog/v0.6.0.md · K8s deploy → /TencentCloud/CubeSandbox/blob/master/docs/guide/kubernetes · Volume plugin → /TencentCloud/CubeSandbox/blob/master/docs/guide/volume-plugin.md v0.5: AutoPause, Terraform deployer, ARM64 & network policy hardening AutoPause/AutoResume — idle sandboxes auto-suspend and wake on the next request. Terraform one-click cluster deploy ARM64 native full-stack support network policy hardening — per-sandbox traffic tokens, policy-routing egress. Changelog → /TencentCloud/CubeSandbox/blob/master/docs/changelog/v0.5.0.md · Terraform deploy → /TencentCloud/CubeSandbox/blob/master/docs/guide/tencentcloud-terraform-deploy.md v0.4: Safer egress, easier ops Credential vault — Agents call external APIs as usual; keys never enter the sandbox. Dashboard — version matrix and template health checks; see at a glance whether templates need rebuilding after upgrades. Changelog → /TencentCloud/CubeSandbox/blob/master/docs/changelog/v0.4.0.md · Security proxy guide → /TencentCloud/CubeSandbox/blob/master/docs/guide/security-proxy.md · WebUI guide → /TencentCloud/CubeSandbox/blob/master/docs/guide/webui.md Snapshot, Clone & Rollback at hundred-millisecond granularity CubeSandbox 0.3.0 introduces the CubeCoW Copy-on-Write snapshot engine, enabling event-level snapshots, instant cloning, and rollback to any saved state. Changelog → /TencentCloud/CubeSandbox/blob/master/docs/changelog/v0.3.0.md 🎉 Initial open-source release Cube Sandbox is now open source Millisecond boot, hardware-level isolation, E2B-compatible sandbox for AI Agents. Changelog → /TencentCloud/CubeSandbox/blob/master/docs/changelog/v0.1.0.md ⚡ Ultra-fast StartupResource pooling and snapshot cloning skip all cold-start overhead. Average <60ms cold start — sandbox creation faster than a blink. | 🔒 Hardware IsolationEvery sandbox runs a dedicated OS kernel in its own MicroVM. | 🔌 E2B SDK CompatibleCompatible with E2B SDK interface. Switch from E2B Cloud seamlessly by changing one environment variable — zero client code changes. | 📦 High-density Deployment<5MB overhead per sandbox enables thousands of instances per server via kernel sharing and Copy-on-Write CoW . Supports automatic sandbox pause and resume, further improving deployment density and cost optimization. | 🛡️ Network SecurityeBPF-based inter-sandbox isolation and egress filtering at kernel level; built-in L7 security proxy enables per-domain/path/method policies with automatic credential injection — secrets never visible to sandbox code. | 📸 Flexible State ManagementHigh-frequency snapshot and rollback at hundred-millisecond granularity. Create checkpoints on running sandboxes, roll back to any saved state at any time, or fork from a specific state to explore in parallel. | 💾 Volume FrameworkE2B-compatible Volume framework that lets users plug in custom backend storage solutions. Volumes have an independent lifecycle and can be shared across sandboxes. | 🚀 Production DeploymentDeploy production clusters on Tencent Cloud with one click using Terraform. Also supports deployment on standard Kubernetes clusters preview . | 💪 ARM Architecture SupportFull native ARM64 support across compilation, build, and deployment workflows. | 1.cubesandbox.-.mp4 | 2.cubesandbox.demo.mp4 | Cube-Sandbox.RL.demo.mp4 | 5.cube.V0.3.0.-.-.mp4 | Installation & Demo | Performance Test | RL SWE-Bench | Snapshot · Clone · Rollback | In the context of AI Agent code execution, CubeSandbox achieves the perfect balance of security and performance: | Metric | Docker Container | Traditional VM | CubeSandbox | |---|---|---|---| Isolation Level | Low Shared Kernel Namespaces | High Dedicated Kernel | Extreme Dedicated Kernel + eBPF | Boot Speed Full-OS boot duration | 200ms | Seconds | Sub-millisecond <60ms | Memory Overhead | Low Shared Kernel | High Full OS | Ultra-low Aggressively stripped, <5MB | Deployment Density | High | Low | Extreme Thousands per node | E2B SDK Compatible | / | / | ✅ Drop-in | Cold start benchmarked on bare-metal. 60ms at single concurrency; under 50 concurrent creations, avg 67ms, P95 90ms, P99 137ms — consistently sub-150ms. Memory overhead measured with sandbox specs ≤ 32GB. Larger configurations may see a marginal increase. For detailed metrics on startup latency and resource overhead, see the Core Operations Performance Benchmark Report /TencentCloud/CubeSandbox/blob/master/docs/blog/posts/2026-06-01-cubesandbox-perf-benchmark.md bare metal and the PVM Cloud Server Benchmark Report /TencentCloud/CubeSandbox/blob/master/docs/blog/posts/2026-06-03-cubesandbox-perf-benchmark-pvm.md . ⚡ Millisecond-level startup — watch the fast-start flow above. Cube Sandbox requires an x86 64 Linux environment with KVM support. The guide walks you through everything in four steps — provisioning a server, installing Cube Sandbox, creating a sandbox template, and running your first agent code. No source build needed, up and running in minutes. Choose your deployment path: | 🏆 Recommended | 🏗 Bare Metal → /TencentCloud/CubeSandbox/blob/master/docs/guide/bare-metal-deploy.md 💻 Dev-Env → /TencentCloud/CubeSandbox/blob/master/docs/guide/dev-environment.md ⚠️ Not recommended — poor performance 🖥️ Visual management — from overview to creating a sandbox and streaming logs, all in your browser. After one-click deployment, open in your browser: http://