LIFEHUBBER
Choose theme

AI Resources

CubeSandbox

GitHub stars: 12.8K GitHub forks: 1.2K Last pushed September 30, 2026: Pushed 1d ago
Stats from GitHub

CubeSandbox is TencentCloud infrastructure for running agent code in Linux MicroVMs through an E2B-compatible API. It supplies the execution environment; your agent still chooses the work to run.

A saved sandbox does not necessarily move between servers. CubeSandbox distinguishes node-local XFS snapshots from a preview S3-backed path, chosen when creating the template, for resuming on a compatible node. Use this as a first read, not a recommendation. Open the original project before trusting details like terms, limits, privacy, cost, setup, or safety.

What it is

A place to execute agent code

Use its sandbox API when a coding agent or code interpreter needs a Linux environment to run commands and programs. Templates define the starting environment; lifecycle operations manage the resulting sandbox.

Why it stands out

Choose where a paused sandbox can return

XFS snapshot packages are tied to their original node. The preview S3-backed path can support another compatible node, but the backend must be selected at template creation: an existing XFS template cannot simply be converted later.

Availability

Self-hosted, with server requirements

The public repository provides standalone and cloud deployment paths, plus a Kubernetes path marked preview. This is a technical Linux server installation with root access and XFS storage. The quick start distinguishes the x86_64 cloud PVM route from ARM64 native-KVM deployment.

Why it matters

What makes it useful

A code interpreter needs somewhere to execute its generated program. CubeSandbox places that work in a KVM MicroVM with its own guest kernel and provides commands and code-interpreter calls around it. The runtime design is distinct from a model or an agent framework; it is not a guarantee that every workload or host configuration is safe.

Notable points

What stands out

An S3 snapshot alone does not make a workload portable. The cross-node guide also requires compatible CPU and kernel capabilities and a completed remote snapshot. A raw host mount pins the sandbox to its original node; a plugin-backed volume needs a backend that can attach on the destination. Check those dependencies before planning recovery on a second server.

Before using

What to review

The quick start requires root access, glibc 2.31 or newer, and XFS at /data/cubelet with at least 50 GB of disk space; 200 GB is recommended. Follow the documented CPU and virtualization route for the host.

Review authentication and network exposure for the deployment. The quick-start SDK sample API-key value is not a production authentication setup.

For an existing Kubernetes cluster moving to v0.7.2, read the host-network default change and its drain-and-acknowledge upgrade steps. The release also fixes incremental-snapshot data loss and S3 hot-upgrade EIO errors; an upgrade still needs the documented procedure.

Two official host-mount advisories have different version boundaries: unrestricted host bind mounts lists versions below 0.5.1 and patch 0.5.1; the symlink allowlist bypass lists versions through 0.5.1 and no patched version. Review the separate notices rather than treat 0.5.1 as a fix for both.

Reader fit

Who may find it relevant

Builders running agent-generated programs who need a self-hosted execution service and can operate its Linux hosts.

Infrastructure teams whose pause-and-resume plan must account for snapshot storage, destination nodes and attached volumes.

Readers adapting an E2B-based application who can check its required operations against the current compatibility notes and examples.

Editorial note

Why LifeHubber lists it

Before moving a code-interpreter task to v0.7.2, create a sandbox with a harmless marker environment variable and read it through both run_code and commands.run. The release makes creation-time variables available to run_code as well as shell commands, but requires the new sandbox-code example image. Checking both paths with that image can reveal whether the interpreter and shell see the same task configuration.

Source links

Source materials

Reader note

Before relying on this entry

LifeHubber lists entries to help readers inspect AI projects, not to endorse them or prove they are safe, suitable, accurate, maintained, or right for a specific use. We do not verify every entry in depth. Before relying on anything listed, review the original materials, terms, privacy practices, limits, and risks that matter for your situation.

What to explore next

Compare the sandbox with the wider runtime around it.

CubeSandbox focuses on a MicroVM-based sandbox design and lifecycle controls. These paths help compare a broader agent sandbox surface and environments built for training and evaluation.

Advertisements

Advertisements

For project maintainers

Listed here? You can use the badge.

If you maintain a project with a current LifeHubber listing, you may add the optional “Listed on LifeHubber AI Resources” badge to its README, docs, or website. No introduction or permission request is needed.

See what’s moving