RepoInclusionAI (Ant Group)InclusionAI (Ant Group)published Jul 11, 2026seen 3d

inclusionAI/sandboxd

Go

Open original ↗

Captured source

source ↗
published Jul 11, 2026seen 3dcaptured 3dhttp 200method plain

inclusionAI/sandboxd

Description: A sandbox runtime daemon.

Language: Go

License: Apache-2.0

Stars: 2

Forks: 2

Open issues: 0

Created: 2026-07-11T12:35:48Z

Pushed: 2026-07-21T14:34:27Z

Default branch: main

Fork: no

Archived: no

README:

sandboxd

sandboxd is the Linux sandbox lifecycle service used by AKernel. It exposes a small gRPC API, manages sandbox resources, and currently runs sandboxes with gVisor. Kata Containers support will be open-sourced soon.

Responsibilities

  • Start, wait for, inspect, measure, and delete sandboxes.
  • Prepare local, OCI, Nydus, and S3-backed rootfs and mounts.
  • Allocate cgroups (currently v1 only) and veth interfaces and configure iptables for NAT.

Architecture

gRPC service
|
sandbox lifecycle manager
├── sandbox runtime adapter ──> gVisor
├── image manager ────────────> distill-fs / OCI
└── resource managers ────────> cgroup v1 / veth / iptables

API / CLI

The public protobuf contract is [api/runtime/v1/sandbox-api.proto](api/runtime/v1/sandbox-api.proto).

The sbox binary is an administrative CLI for managing sandboxes.

Build and test

make
make test
make vet

The privileged E2E suite requires Docker, cgroup v1, iptables, and the tested runsc release:

RUNSC_BINARY=/usr/local/bin/runsc make e2e

See [test/e2e/README.md](test/e2e/README.md) for the developer test environment. AKernel integration is validated through the all-in-one node image and standalone deployment in the AKernel repository.

Protobuf development

Protobuf generation uses a pinned Docker image defined by the Makefile and tools/protobuf.Dockerfile, independent of host-installed protobuf tools:

make protos
make check-protos

Commit the generated Go bindings with the corresponding protobuf change.

Project layout

api/ public protobuf API and generated Go code
cmd/sandboxd/ sandboxd daemon
cmd/sbox/ administrative CLI
config/ configuration types and defaults
configs/ AKernel integration configuration templates
internal/server/ gRPC service and daemon orchestration
pkg/runtime/ sandbox runtime abstraction and gVisor adapter
pkg/imagemanager/ rootfs and mount integration
pkg/networkmanager/ veth and iptables integration
pkg/cgroupmanager/ cgroup v1 integration
test/e2e/ privileged runsc E2E
tools/ pinned protobuf code-generation image

Known limitations

  • Only gVisor, cgroup v1, netstack sandbox networking, and iptables are supported in v0.1.0.
  • The direct OCI registry client currently skips TLS certificate verification and should only be used with trusted registries.

License

Copyright (c) 2026 Ant Group Corporation.

Licensed under the Apache License, Version 2.0. See [LICENSE](LICENSE). Third-party Go modules are declared in go.mod and retain their respective licenses.