Sandboxes
The agent runs code. Your machine stays intact.
A sandbox is a machine with exec, no network by default, that is destroyed when its TTL runs out (10 minutes by default, 24 hours at most).
kling image toolchain # node, npm, python3 and pipkling sandbox create -image toolchain -name sbkling cp ./analisis.py sb:/tmp/kling exec sb -- python3 /tmp/analisis.pykling sandbox rm sbFrom a template
Section titled “From a template”Prepare a machine once, save it, and sandboxes are born from it with everything inside.
5.6 scold sandbox on toolchain
0.13–0.32 ssandbox from a template
0.57 sfive at once from the same template
Measured on Lima arm64 with nested virtualization.
kling sandbox fork sb -n 3 # 3 independent copies of a live sandboxFor many people: kling-sandbox
Section titled “For many people: kling-sandbox”The sandbox extension puts a front end in front of it: tenants with a token and a quota, templates as recipes and a pre-warmed pool.
kling plugin install sandboxkling sbx template apply -f node.jsonkling sbx new -template node -ttl 30mkling sbx exec <id> -- tsc --versionThis is not isolation between tenants: they share a host. It is allocation and accounting.