Create a sandbox from a template and start it
Enforces the org’s quotas (running sandboxes, total sandboxes,
monthly hours). The egress policy defaults to mode default.
secrets must name existing vault entries (400 otherwise; 503 when
the deployment has no vault key).
/v1/sandboxesAuthorizationBearer token · headerrequiredOrg-scoped API key, pols_....
application/jsonnameNameLowercase letters, digits and dashes, starting with a letter.
sizeSizeSandbox size. small: 2 vCPU, 4 GiB RAM, 20 GiB disk. default: 4 vCPU, 8 GiB, 50 GiB. large: 8 vCPU, 16 GiB, 100 GiB. xlarge: 16 vCPU, 32 GiB, 200 GiB.
smalldefaultlargexlargetemplatestringTemplate ID or name. Defaults to the ubuntu-24.04 system template.
envobjectEnvironment variables for every exec in the sandbox. Prefer
secrets for API keys and passwords: env values are stored as
given.
secretsSecretNamesVault entries to set as environment variables of the same name.
Together with env (and, for a fork, the source's environment and
entries) at most 100 variables; a name may not also be in env.
egressEgressPolicyA sandbox's outbound network policy, chosen at create or fork and immutable thereafter.
Show propertiesHide properties
modeEgressModerequiredWhat a sandbox may reach on the network. default: the public
internet. allowlist: only the destinations in allow. none: no
outbound traffic. In every mode, private (RFC 1918), CGNAT
(100.64.0.0/10), loopback, link-local (169.254.0.0/16, including the
cloud metadata address 169.254.169.254) and IPv6 unique-local and
link-local destinations, the sandbox host and the management plane
are blocked, along with multicast, limited broadcast and outbound
SMTP (TCP port 25). Host-local DHCP and required neighbor discovery
remain available. Only default mode can use the host resolver;
allowlist and none block it. For DNS in allowlist mode, list a public
resolver's CIDR and configure the sandbox to use that resolver.
defaultallowlistnoneallowstring[]Only with mode allowlist, and then required: destination IPv4
or IPv6 CIDR prefixes (for example 203.0.113.7/32 or
2001:db8::/32). Single addresses need /32 or /128; bare IPs and
hostnames are not supported. Entries that overlap a built-in
blocked range are refused. Additional operator-denied destinations
remain blocked by the runtime even when listed here. Returned in
canonical CIDR form.
Accepted; the sandbox is being created.
idstringrequirednamestring | nullsizeSizerequiredSandbox size. small: 2 vCPU, 4 GiB RAM, 20 GiB disk. default: 4 vCPU, 8 GiB, 50 GiB. large: 8 vCPU, 16 GiB, 100 GiB. xlarge: 16 vCPU, 32 GiB, 200 GiB.
smalldefaultlargexlargevcpusintegerrequiredmemory_mibintegerrequireddisk_gibintegerrequiredtemplate_idstring | nullThe template it was created from; null for forks.
source_sandbox_idstring | nullThe sandbox it was forked from.
statusSandboxStatusrequiredWhere the sandbox actually is. pending means not created in the
runtime yet, or still booting. running means booted: its guest
agent answers, so exec and file calls work. A booting sandbox keeps
its previous status, but its running interval (and billing) starts
when the VM starts. error means the reconciler gave up; delete it.
pendingrunningstoppeddeletederrordesired_stateDesiredStaterequiredrunningstoppeddeletedlast_errorstring | nullenv_keysstring[]requiredNames of the environment variables set on the sandbox (values are never returned). Empty once the sandbox is deleted, because deleting a sandbox erases its environment.
secretsstring[]requiredNames of the vault entries the sandbox gets as environment variables. Their values are read from the vault when the VM is created; replacing an entry later does not change this sandbox.
egressEgressPolicyrequiredA sandbox's outbound network policy, chosen at create or fork and immutable thereafter.
Show propertiesHide properties
modeEgressModerequiredWhat a sandbox may reach on the network. default: the public
internet. allowlist: only the destinations in allow. none: no
outbound traffic. In every mode, private (RFC 1918), CGNAT
(100.64.0.0/10), loopback, link-local (169.254.0.0/16, including the
cloud metadata address 169.254.169.254) and IPv6 unique-local and
link-local destinations, the sandbox host and the management plane
are blocked, along with multicast, limited broadcast and outbound
SMTP (TCP port 25). Host-local DHCP and required neighbor discovery
remain available. Only default mode can use the host resolver;
allowlist and none block it. For DNS in allowlist mode, list a public
resolver's CIDR and configure the sandbox to use that resolver.
defaultallowlistnoneallowstring[]Only with mode allowlist, and then required: destination IPv4
or IPv6 CIDR prefixes (for example 203.0.113.7/32 or
2001:db8::/32). Single addresses need /32 or /128; bare IPs and
hostnames are not supported. Entries that overlap a built-in
blocked range are refused. Additional operator-denied destinations
remain blocked by the runtime even when listed here. Returned in
canonical CIDR form.
created_atstring<date-time>requiredupdated_atstring<date-time>requiredstarted_atstring<date-time> | nullWhen the current (or last) running interval started.
stopped_atstring<date-time> | nulldeleted_atstring<date-time> | nullstatsResourceStatsOne sample of a running sandbox's resource use, as stats on a
sandbox (present while it runs and has a recent sample) and in
GET /v1/sandboxes/{sandbox}/stats.
Show propertiesHide properties
sampled_atstring<date-time>requiredcpu_percentnumber<double>Share of the sandbox's vCPUs that were busy, averaged since the previous sample: 100 means all of them. Absent in the first sample after the sandbox starts.
cpu_coresnumber<double>The same as a number of busy vCPUs, for example 1.5. Absent with cpu_percent.
memory_used_bytesinteger<int64>requiredMemory in use inside the VM, as its guest agent reports it.
memory_total_bytesinteger<int64>requiredMemory the guest sees (slightly less than the size's RAM, which the guest kernel reserves part of).
disk_used_bytesinteger<int64>requiredSpace the root disk volume takes in the host's storage pool, as the pool reports it. On a copy-on-write clone (a sandbox created from a template, or a fork) this can leave out blocks it still shares with its origin. 0 when the host does not report it.
disk_total_bytesinteger<int64>requiredSize of the root disk.
Rate limited (rate_limited): too many requests or failed
authentications from this address, too many requests or
lifecycle calls for this org, or too many of its exec, file,
computer and CDP calls in progress at once. Retry after
Retry-After seconds.
errorobjectrequiredShow propertiesHide properties
codestringrequiredStable machine-readable code: bad_request (400),
unauthorized (401), forbidden (403), quota_exceeded
(403), not_found (404), conflict (409),
rate_limited (429, see Retry-After), internal (500),
runtime_error (502, the sandbox host failed),
unavailable (503, the feature is not configured on this
deployment), timeout (504, or 408 when a request body
stalls).
messagestringrequiredError.
errorobjectrequiredShow propertiesHide properties
codestringrequiredStable machine-readable code: bad_request (400),
unauthorized (401), forbidden (403), quota_exceeded
(403), not_found (404), conflict (409),
rate_limited (429, see Retry-After), internal (500),
runtime_error (502, the sandbox host failed),
unavailable (503, the feature is not configured on this
deployment), timeout (504, or 408 when a request body
stalls).
messagestringrequired