Skip to main content

drukbox-python-sdk

Async Python client for the Drukbox host API.

The SDK builds reusable sandbox templates, provisions sandbox VMs, reads host state, deletes hosts and templates, and returns the SSH connection details a caller needs. It speaks HTTP only: SSH sessions, file transfer, command execution, and retry orchestration belong in the caller.

Install

pip install drukbox-python-sdk
uv add drukbox-python-sdk

Usage

from drukbox_sdk import SandboxAPI

sandbox = SandboxAPI(
    base_url="https://sandbox.internal.ts.net",
    token="...",
)

try:
    host = await sandbox.create_host(
        image="ghcr.io/drukbox/sandbox:abc123",
        env={"FOO": "bar"},
        idempotency_key="agent-run-42",
    )
    # Dial whichever reachable address fits your network: host.external_ssh_host
    # for the provider's public path (may be empty when the service runs an
    # AWS-with-Tailscale-on deployment) or host.internal_ssh_host for the
    # tailnet MagicDNS name (only when Tailscale is enabled). Use host.known_hosts
    # for SSH host-key verification. If the provider mints a per-VM keypair
    # (AWS with Tailscale off), host.private_key carries the private half —
    # returned exactly once at create time; subsequent get_host returns None.
finally:
    await sandbox.delete_host(host.id)
    await sandbox.aclose()

create_host blocks until the host is active — typically ~10–30s, up to a few minutes worst case. The SDK's default timeout (300s) covers this. Pass an idempotency_key for retry safety: a retry with the same key after a successful provision returns the original host instead of creating a duplicate.

SandboxAPI.from_env(prefix="SANDBOX_") reads SANDBOX_SERVICE_URL, SANDBOX_SERVICE_TOKEN, and optional SANDBOX_SERVICE_TIMEOUT.

Contract

Public exports live in drukbox_sdk:

  • SandboxAPI
  • SandboxHost
  • SandboxTemplate
  • DoctorReport and DoctorCheck
  • HTTPProxy and HTTPProxyAttachment
  • SandboxAPIError and typed subclasses for auth, not found, conflict, unavailable, and unclassified response errors

Supported host operations:

  • create_host
  • get_host
  • attach
  • list_hosts
  • renew_host
  • delete_host
  • doctor
  • aclose

create_host supports the service's optional image, env, expires_at, permanent, provider, instance_type, disk_gb, template, and Idempotency-Key inputs. instance_type (provider-native size, e.g. t3.xlarge / cx33) and disk_gb pin the VM shape; omit either for the provider default. Omit expires_at for the default lease, pass a datetime for an explicit expiry, or pass permanent=True for a never-reaped host. template accepts a template ID. An explicit image wins over it.

renew_host extends a host's lease via POST /hosts/{id}/renew. Omit expires_at to extend by the service's default TTL; renewal never makes a host permanent.

Supported template operations:

  • create_template
  • get_template
  • list_templates
  • delete_template

create_template returns immediately with a building record. Poll get_template until the status is available or failed. A failed record carries the reason in last_error.

Supported HTTP-proxy operations:

  • create_http_proxy
  • delete_http_proxy
  • attach_http_proxy
  • detach_http_proxy

HTTP proxies are account-bound exe.dev resources, not host state — deleting a host does not remove proxies fronting it. create_http_proxy takes an origin-only target (scheme + host, no path/query/fragment/credentials) and at least one headers entry; attach_http_proxy / detach_http_proxy point a proxy at a host's backing VM (the host must be bootstrapping or active).

doctor fetches GET /doctor — read-only dependency health. The service runs one cheap, non-mutating probe per dependency (database, active VM provider, Tailscale when enabled) and always responds 200, so callers branch on DoctorReport.ok rather than the HTTP status. A failed DoctorCheck carries a stable hint slug for remediation.

The SDK does not mint Tailscale auth keys, manage ACLs, establish SSH, provision Linux users, transfer files, or run remote commands.

Development

uv sync
uv run ruff check
uv run ruff format --check
uv run pyright
uv run pytest

Tests use respx to fake the Drukbox HTTP API. They do not need a real network, VM provider, or Drukbox service.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

drukbox_python_sdk-0.1.0.tar.gz (18.4 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

drukbox_python_sdk-0.1.0-py3-none-any.whl (12.2 kB view details)

Uploaded Python 3

File details

Details for the file drukbox_python_sdk-0.1.0.tar.gz.

File metadata

  • Download URL: drukbox_python_sdk-0.1.0.tar.gz
  • Upload date:
  • Size: 18.4 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for drukbox_python_sdk-0.1.0.tar.gz
Algorithm Hash digest
SHA256 d81cb31f865f67c01b28d531989525f9367bbbae0a335835aa61ad4400756715
MD5 2fc564e8b3ae70738fce5bfb04b1be99
BLAKE2b-256 960173e978566c3c6670ec2f5fcbd4829508f4f3edb992fa01856a120ef4f7b0

See more details on using hashes here.

Provenance

The following attestation bundles were made for drukbox_python_sdk-0.1.0.tar.gz:

Publisher: release.yml on czpython/drukbox-python-sdk

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file drukbox_python_sdk-0.1.0-py3-none-any.whl.

File metadata

File hashes

Hashes for drukbox_python_sdk-0.1.0-py3-none-any.whl
Algorithm Hash digest
SHA256 9a72cc443404d40bbdb23b08e691ff89746130b88e5bc2ac2e375f93eafebe04
MD5 10a0170df18aa7384959155d988a44a0
BLAKE2b-256 65f770dc580b901cbb6eec1fd6aa12cfa5c87f9ba8854840793ce59c534b8a11

See more details on using hashes here.

Provenance

The following attestation bundles were made for drukbox_python_sdk-0.1.0-py3-none-any.whl:

Publisher: release.yml on czpython/drukbox-python-sdk

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

0.2.0

2 files

This release

0.1.0 This release

2 files

0.0.7

2 files

0.0.6

2 files

0.0.5

2 files

0.0.4

2 files

0.0.3

2 files

0.0.2

2 files

0.0.1

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page