Isolated execution

Sandboxes

Create isolated runtime environments on connected or managed infrastructure.

Sandboxes are the low-level execution units beneath Studio workspaces, builds, agents, and Product workloads. They remain infrastructure resources rather than becoming Products themselves.

Explicit placement

Select eligible clusters and hosts through runtime capability, architecture, health, and policy.

Typed lifecycle

Create, start, stop, inspect, archive, and connect through control-plane and agent contracts.

Default-deny networking

Begin without an external network path and attach only the access or mesh capability the workload needs.

Durable state

Attach purpose-scoped volumes and object storage without copying provider credentials into the sandbox.

Your operation.
Your infrastructure.

Keep the operational product, policy, and delivery model consistent whether work lands on your own machines or selected cloud capacity.

  • Unified sandbox management
  • Distributed sandbox volumes
  • Cross-agent Tailscale-compatible mesh
  • Self-hosted clusters
  • Linux ARM64 and Apple Silicon agents
  • Complete BYO platform from $10 per month
  • Centralized logging & metrics
  • Infrastructure-agnostic APIs
sandbox session
Create a sandbox with gstacks, connect to it over SSH, then start Claude Code with the claude command.