Skip to content

Sandboxes

The agent runs code. Your machine stays intact.

Sandbox from a template

A sandbox is a machine with exec, no network by default, that is destroyed when its TTL runs out (10 minutes by default, 24 hours at most).

Terminal window
kling image toolchain # node, npm, python3 and pip
kling sandbox create -image toolchain -name sb
kling cp ./analisis.py sb:/tmp/
kling exec sb -- python3 /tmp/analisis.py
kling sandbox rm sb

Prepare a machine once, save it, and sandboxes are born from it with everything inside.

5.6 scold sandbox on toolchain
0.13–0.32 ssandbox from a template
0.57 sfive at once from the same template

Measured on Lima arm64 with nested virtualization.

Terminal window
kling sandbox fork sb -n 3 # 3 independent copies of a live sandbox

The sandbox extension puts a front end in front of it: tenants with a token and a quota, templates as recipes and a pre-warmed pool.

Terminal window
kling plugin install sandbox
kling sbx template apply -f node.json
kling sbx new -template node -ttl 30m
kling sbx exec <id> -- tsc --version

This is not isolation between tenants: they share a host. It is allocation and accounting.