Sandbox Agents
Sandbox agents pair an ADK Agent with an isolated execution environment β filesystem, shell, mounted storage, exposed ports, snapshots β so the model can manipulate real files and run real commands inside a controlled boundary.
This index links to the per-topic documentation.
| Topic | Document |
|---|---|
| Types | types.md |
| Capabilities | capabilities.md |
| Clients (backends) | clients.md |
| Selection (cost-aware) | selection.md |
| Cost & billing | cost.md |
| Security policy | security.md |
| Observability | observability.md |
| Snapshots | snapshots.md |
| Manifest materialization | manifest-materialization.md |
| IaC integration | iac.md |
| Runner integration | runner_integration.md |
Quickstart
from augments.adk.run.config import RunConfig
from augments.adk.run.runner import Runner
from augments.adk.sandbox.agent import SandboxAgent
from augments.adk.sandbox.capabilities.shell import ShellCapability
from augments.adk.sandbox.clients.local import LocalSubprocessSandboxClient
from augments.adk.sandbox.config import SandboxRunConfig
agent = SandboxAgent(
name="coder",
system_prompt="You are a sandboxed coder.",
capabilities=[ShellCapability()],
)
client = LocalSubprocessSandboxClient()
run_config = RunConfig(sandbox=SandboxRunConfig(client=client))
result = await Runner.arun(agent, "List files in /tmp", run_config=run_config)Architecture
The Runner detects isinstance(agent, SandboxAgent) (or non-None
RunConfig.sandbox) and brackets the agent loop with a
sandbox_run_context that:
- Acquires a per-agent
SandboxConcurrencyGuard. - Validates capability dependency requirements.
- Clones capabilities for per-run isolation.
- Resolves the session by priority: explicit session β session_state resume β client.create with manifest β selector picks from candidates.
- Binds session + run_as on every cloned capability.
- Folds the manifest through
process_manifest. - Calls
session.start()for runner-owned sessions. - Yields the lifecycle handle for the rest of the agent loop.
- On exit, calls
session.aclose()(for runner-owned) and releases the guard.
See runner_integration.md for detail.