Skip to content

Sandboxes on Cloudflare

Last updated View as MarkdownAgent setup

Start a sandbox and run untrusted or generated code

Available on Workers Paid plan

A sandbox is an isolated place to run code. The code cannot directly read the memory or data of your application. Your Worker decides which application APIs and data the code receives, and whether the code can reach the public Internet.

You can use a sandbox for agent-written code, user-uploaded applications, data analysis, development previews, build pipelines, or any other work that should not share a process with your application.

Cloudflare provides two sandbox environments. Both are accessible through a Worker, the application that already handles your traffic.

If your application uses @cloudflare/sandbox 0.x, refer to Sandbox SDK 0.x, or move it to the current version with Migrate from Sandbox SDK 0.x.


Containers

Containers run an image you provide. The instance is a full Linux environment, so you can run any language and keep processes running. Your Worker starts the instance and sends it work. HTTP from the Internet reaches the instance only through your Worker.

Each instance is a microVM with its own kernel and network, so no other workload shares it.

A sandbox container uses the Durable Object scheduling policy, which is in public beta.

A Durable Object in your Worker starts the instance from an image and runs a command in it:

container.start({
	image: "cloudflare/debian-trixie",
	entrypoint: ["sleep", "infinity"],
	enableInternet: false,
});
const process = await container.exec(["uname", "-a"]);
const output = await process.output();

Run a Linux command

Build a coding agent runner


Dynamic Workers

Dynamic Workers create a new Worker at runtime. The untrusted code can be JavaScript, Python, or WebAssembly. Compile TypeScript to JavaScript before loading it.

The Workers runtime runs each Dynamic Worker apart from your Worker and from other Dynamic Workers. A Dynamic Worker reaches your application only through the methods and data you pass to it.

Your Worker loads the untrusted module as a new Worker, blocks its outbound requests, and calls it:

const sandbox = env.LOADER.load({
	compatibilityDate: "$today",
	mainModule: "code.js",
	modules: { "code.js": untrustedModule },
	globalOutbound: null,
});
const entrypoint = sandbox.getEntrypoint<CodeEntrypoint>("Code");
const result = await entrypoint.evaluate();

Run JavaScript

Build an AI code interpreter


Concepts

Sandbox lifetime

Understand what keeps a Linux sandbox running, what stops it, and which files a snapshot brings back.

Sandbox security

Decide what each sandbox holds, because its code can use everything you place inside it.

Guides

Run commands

Run Python code and tests, stream output, keep processes running, and open a terminal.

Work with files

Move files, keep a workspace between instances, and mount an R2 bucket.

Manage sandboxes

List a user's sandboxes, and record when and why each one stops.

Coding agents

Run coding agents such as Claude Code, Codex, and Devin in a sandbox that belongs to one task.


Workers

The serverless platform these sandbox environments run on.

Durable Objects

Identity and coordination for an attached container.

Workers AI

Run models on Cloudflare, then execute the code they generate in a sandbox.


More resources

Was this helpful?