opensandbox-groupOps & cloud
OpenSandbox
An open-source sandbox platform for AI agents and code execution with Docker/Kubernetes runtimes, SDKs, CLI, and MCP integration.
- Backend
- DevOps
- Security
- Automation
- CLI
- API/SDK
- Library/framework
- Linux
- Self-hostable
- Runs locally
- Docker supported
- Popularity
- 15.6k Stars
- GitHub stars
- Recent activity
- 10/1/2026
- Updated in the last 30 days
- License
- APACHE-2.0
- Permissive
Why it matters
We look beyond stars: what problem it solves, whether it creates real utility, and what makes its approach worth noticing.
Problem
AI agents need to run partially trusted code, shells, browsers, and tools, but executing them directly on hosts or shared clusters creates permission, credential, network, and resource-isolation risks.
Practical value
Unified sandbox APIs, SDKs, CLI, and MCP combine Docker/Kubernetes runtimes with command/file operations, network policy, and credential boundaries, reducing the need for teams to build agent execution infrastructure from scratch.
Innovation / differentiation
It elevates a code-execution sandbox from a container wrapper into a general control plane for AI workloads, keeping a consistent developer interface across different runtimes and isolation technologies.
Leverage potential
The sandbox is an infrastructure primitive reusable by coding agents, GUI agents, evaluations, code interpreters, and training systems, giving it leverage far beyond a single end-user feature.
Why now
Agents are rapidly moving from calling APIs to executing code and manipulating environments, making secure execution infrastructure a core product layer rather than a background engineering detail.
Community activity
In the last 90 days there were 251 new issues and 665 pull requests; the bounded issue/PR samples include 35 issue authors and 19 PR contributors, with at least 30 releases.
Maintainer responsiveness
The 100-issue window sample had a 81% close rate, and the 100-pull-request sample had a 67% merge rate. Maintainer-response observations covered 59% of that issue sample, with a 2% response rate and median first response of 6 days.
Key highlights
- Unified sandbox lifecycle, command execution, and file-operation APIs
- Multi-language SDKs, the
osbCLI, and an MCP server - Local Docker and Kubernetes runtimes
Quick start
How it is installed, how hard it is, and where to start.
Where it runs
Self-hosted (your own server)
Difficulty
Medium — some setup needed
- 01Prepare Docker; the local examples also require Python 3.10 or newer.
- 02Run
uvx opensandbox-server init-config ~/.sandbox.toml --example dockerto create a local Docker-based configuration. - 03Start the sandbox service with
uvx opensandbox-server, then connect through an SDK, theosbCLI, or an MCP client. - 04For production workloads that execute untrusted code, configure gVisor, Kata, Firecracker, or another supported secure runtime following the official guide.
Best for
- Teams that want data on their own servers
- Developers who want to try it on their machine
- People who prefer Docker deploys
More about it
OpenSandbox is a general-purpose sandbox platform for AI applications and code execution. It defines lifecycle and execution APIs and ships Python, Java/Kotlin, JavaScript/TypeScript, C#, and Go SDKs together with the osb CLI and an MCP server.
The runtime supports local Docker and Kubernetes scheduling. Sandboxes can expose command execution, filesystem operations, code interpreters, Chrome/Playwright environments, and full desktop environments. Networking components include ingress, per-sandbox egress controls, and a Credential Vault that can inject credentials without exposing the underlying secrets directly to workloads.
Isolation depends on deployment configuration. The project supports gVisor, Kata Containers, and Firecracker microVM runtimes, but these require explicit setup and should not be assumed from a default Docker deployment.
Sources
Each field shows its status and source — expand to review.
12 · Expand
Sources
Each field shows its status and source — expand to review.
capability tags
Verifiedautomation, security
Source: manual_curated · Manually curated from the verified project README; no AI draft. · 8/17/2026
Latest release
Verifiedrelease-1.1.0
Source: GitHub API · latest_release=release-1.1.0 · 10/2/2026
License
VerifiedApache-2.0
Source: GitHub API · license.spdx_id=Apache-2.0 · 10/2/2026
needs api key
VerifiedNo
Source: manual_curated · Manually curated from the verified project README; no AI draft. · 8/17/2026
One-liner
Verified{"en":"An open-source sandbox platform for AI agents and code execution with Docker/Kubernetes runtimes, SDKs, CLI, and MCP integration.","zh":"为 AI Agent 和代码执行场景提供 Docker/Kubernetes 隔离运行环境、SDK、CLI 与 MCP 接口的开源沙箱平台。"}
Source: manual_curated · Manually curated from the verified project README; no AI draft. · 8/17/2026
Platforms
Verifiedlinux
Source: manual_curated · Manually curated from the verified project README; no AI draft. · 8/17/2026
Category hint
Inferred from materialsai-apps
Source: Project README · hint=ai-apps · 8/14/2026
product forms
Verifiedcli, api_sdk, library_framework
Source: manual_curated · Manually curated from the verified project README; no AI draft. · 8/17/2026
role tags
Verifiedbackend, devops, security
Source: manual_curated · Manually curated from the verified project README; no AI draft. · 8/17/2026
supports docker
VerifiedYes
Source: Repository file · dockerfile=true; compose=false · 10/2/2026
supports local
VerifiedYes
Source: manual_curated · Manually curated from the verified project README; no AI draft. · 8/17/2026
supports self host
VerifiedYes
Source: manual_curated · Manually curated from the verified project README; no AI draft. · 8/17/2026
Related projects
Other verified projects matched by category, capabilities, and intended roles.
Flawless
An enterprise Agentic SRE platform for Kubernetes and cloud infrastructure that automates fault discovery, evidence gathering, diagnosis, controlled execution, and recovery verification.
Nova-Server
A self-hosted, censorship-resistant proxy server and admin panel for Linux VPS, supporting Xray-core, sing-box, Hysteria2, and AmneziaWG.
terraform
Terraform is an infrastructure-as-code tool that manages the lifecycle of cloud and local resources using declarative configuration files.
minikube
Run a local Kubernetes cluster on your machine, supporting multi-cluster, persistent volumes, and various container runtimes for development.
oneuptime
An open-source observability platform combining uptime monitoring, on-call alerting, incident response, status pages, logs, metrics, and traces.
arkade
A CLI installer for developer tools and Kubernetes apps that selects binaries by OS/architecture and provides repeatable app installation commands.