Sandbox Types (Layer 1)
All Layer-1 sandbox types live in augments.adk.types.sandbox. They
have no provider SDK imports and serialize to JSON without
conversion hops.
Manifest
Manifest describes the workspace a session should materialize.
| Field | Purpose |
|---|---|
root | Workspace root path inside the sandbox (default /workspace) |
entries | dict[str, BaseEntry] keyed by workspace-relative path |
environment | Env vars injected at session start |
users / groups | Multi-user workspaces (rare; default empty) |
extra_path_grants | SandboxPathGrant permissions outside the manifest |
remote_mount_command_allowlist | Mount-tool argv allowlist |
BaseEntry subclasses: File, Dir, LocalFile, LocalDir,
GitRepo, and the Mount family (S3Mount, GCSMount, R2Mount,
AzureBlobMount, BoxMount, S3FilesMount).
Mounts
Mount.mount_path is workspace-relative; absolute paths and ..
escapes raise at validation time. Mount.read_only defaults to True.
Mount.mount_strategy is a discriminated union:
InContainerMountStrategy(pattern=...)β backend runs a mount tool inside the container. Patterns:RcloneMountPattern,MountpointMountPattern,FuseMountPattern,S3FilesMountPattern.DockerVolumeMountStrategy(driver, driver_options)β Docker volume driver attaches the storage before container start.
augments.adk.sandbox.policy.mounts translates these to each backend's
wire format (Docker volumes, K8s CSI volumes, hosted-bridge create-
body fields).
Exec result + ports
ExecResult(stdout, stderr, exit_code, duration_ms)β output ofsession.run(...). Non-zero exits are surfaced (not raised).ExposedPortEndpoint(host, port, tls, query)β output ofsession.resolve_exposed_port(port). Helpers:url_for(scheme).PtyHandle(session_id, command, backend_payload)β opaque PTY reference;backend_payloadMUST NOT be introspected outside the backend.
Snapshot + IaC
SnapshotRef(snapshot_id, store_uri)β store-scoped address.SnapshotMetadata(ref, created_at_iso, size_bytes, manifest_hash)β whatSnapshotStore.list()/save()return.IaCBundleβ seedocs/sandbox/iac.md.
Span data + usage
SandboxSpanData(backend_id, command, exit_code, duration_ms, manifest_hash, resource_usage, snapshot_id)β feeds the tracing layer alongside the existing function/generation span types.SandboxSingleExecUsage+SandboxUsage(__add__)β mirrors theLLMUsageaccumulator semantics for cross-run aggregation.
Permissions
RunAsUser,User,Group,Permissions(perm_str),FileMode(IntEnum)β POSIX-style permission modelling for workspace files and exec sessions.SandboxPathGrant(path, read_only, description)+WorkspacePathPolicyβ explicit grants outside the manifest.
See src/augments/adk/types/sandbox/ for source.