Sandboxes

Run agent-written code away from your laptop.

Give each job a Linux environment, resource limits, a time budget, and a network policy. Drive it from one CLI, API, and customer account.
01Create, run, stop

A sandbox for the work at hand.

tachyonic login
tachyonic sandbox create --budget 30m
tachyonic sandbox exec <sandbox-id> -- python3 --version
tachyonic sandbox rm <sandbox-id>

Replace the sandbox ID with the one returned by create. Sandbox commands require CLI 0.18.0 or later. Check your installed version before following the quickstart.

02Controls

Choose the limits before the job starts.

A workspace for each job

Run commands, open a shell, and copy files through the CLI or API. Keep agent-written code away from your laptop.

Explicit resource limits

Choose CPU, memory, and disk within your plan. Set a wall-clock budget and an optional dollar budget for the job.

Network policy

Choose an allowlist, open HTTP and HTTPS egress, or no outbound access. Add only the hosts the job needs.

Usage and lifecycle events

Read the sandbox's state, command events, metered usage, and estimated cost. Stop it when the job is done.

03Isolation

Know the boundary you requested.

Container isolation shares the host kernel. A sandbox is a controlled execution environment, and it does not make arbitrary code safe. Review the image, the commands, the files, and the hosts you permit.

Placement reports the isolation it selected. An explicit isolation requirement is refused when matching capacity is unavailable. Available pools can change; check tachyonic regions before choosing one.

Read the sandbox controls
04One account

Run the code. Then test the agent.

A sandbox runs your job. A security runtime tests how an authorized agent endpoint behaves under attack. Both use Tachyonic keys and the customer console.