Skip to main content
Pre-release

This release is a pre-release and may not be stable for production use.

Capsem Inspect AI Sandbox Extension (inspect-capsem-sandbox)

inspect-capsem-sandbox registers a capsem SandboxEnvironment for Inspect AI backed by isolated Capsem micro-VMs.

What Name
Distribution (pip install) inspect-capsem-sandbox
Python import package inspect_capsem
Inspect sandbox type capsem
Repository directory integrations/inspect-ai

Installation

inspect-capsem-sandbox depends on capsem (>=0.6.3), inspect-ai, pydantic, and pyyaml, and drives the Capsem HTTP gateway (capsem-service) through the Python capsem SDK. It requires SDK APIs newer than the released capsem 0.6.3: those already on main (EXEC_TIMEOUT_CEILING_SECS, GATEWAY_REQUEST_BUDGET_SECS, decode_exec_output, and OCI container fields on Hypervisor.create) plus #286 (streaming of large binary bodies), #287 (CREATE_READY_SECS and the Hypervisor.create request_timeout), and Hypervisor.vm(id=...) foreign VM attachment; the capsem>=0.6.3 floor in integrations/inspect-ai/pyproject.toml must be bumped to the next published capsem release once cut. Install from the GitHub repository, pinned to the same branch, tag, or commit revision <rev> so the extension and the SDK match:

pip install \
  "capsem @ git+https://github.com/google/capsem.git@<rev>#subdirectory=sdk/python" \
  "inspect-capsem-sandbox @ git+https://github.com/google/capsem.git@<rev>#subdirectory=integrations/inspect-ai"

With uv:

uv add \
  "capsem @ git+https://github.com/google/capsem.git@<rev>#subdirectory=sdk/python" \
  "inspect-capsem-sandbox @ git+https://github.com/google/capsem.git@<rev>#subdirectory=integrations/inspect-ai"

Once installed, inspect_ai discovers the capsem sandbox environment through its [project.entry-points.inspect_ai] entry point.

Quickstart

Run any Inspect evaluation in a Capsem VM sandbox:

inspect eval task.py --sandbox capsem

Or configure the sandbox in a @task definition (execution_mode="vm" runs directly in a Capsem micro-VM; execution_mode="container" runs inside an OCI workload container or nested Docker container built from an image, dockerfile, or single-service compose_file):

from inspect_ai import Task, task
from inspect_capsem import CapsemSandboxConfig


@task
def my_eval() -> Task:
    return Task(
        dataset=...,
        solver=...,
        scorer=...,
        sandbox=(
            "capsem",
            CapsemSandboxConfig(execution_mode="vm", template="code", cpu_count=4, ram_gb=8),
        ),
    )

A string sandbox config is also accepted: a Dockerfile / Containerfile path, a compose.yaml / docker-compose.yml path, or a container image reference ("python:3.12-slim").

Documentation

See web/docs/src/content/docs/usage/inspect-ai.md for:

  • vm vs. container execution modes, single-service Docker Compose support, and CapsemSandboxConfig fields
  • Gateway discovery (CAPSEM_GATEWAY_URL, CAPSEM_GATEWAY_TOKEN, CAPSEM_RUN_DIR, CAPSEM_HOME) and INSPECT_CAPSEM_* image-cache / staging environment variables
  • Execution timeouts, output limits (OutputLimitExceededError), write_file permissions, and SIGINT / inspect sandbox cleanup capsem lifecycle handling
  • In-guest Dockerfile builds, host content-addressed image caching, and MITM CA trust injection inside containers

For the underlying Python gateway client, see sdk/python/README.md.

Metadata

Release files for inspect-capsem-sandbox 0.1.0a0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for inspect-capsem-sandbox 0.1.0a0
File Size Uploaded
inspect_capsem_sandbox-0.1.0a0.tar.gz 293.2 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for inspect-capsem-sandbox 0.1.0a0
File Interpreter ABI Platform
inspect_capsem_sandbox-0.1.0a0-py3-none-any.whl Python 3 none any Details

Total release size: 345.3 kB

Release files / inspect_capsem_sandbox-0.1.0a0.tar.gz

Download URL inspect_capsem_sandbox-0.1.0a0.tar.gz
Size 293.2 kB
Tags Source
SHA-256 checksum
How to use checksums
a9901bef7e80f275e9c0e4a44c1995f258f77493fcf25d72ecb6111caaf98251
BLAKE2b-256 checksum
How to use checksums
e6b4ef56dbf4ee3612965525e67f6ecb2714d713d6eba2fb2f516fb62e73c216
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.9.27 {"installer":{"name":"uv","version":"0.9.27","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Debian GNU/Linux rodete","version":null,"id":"rodete","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}

Release files / inspect_capsem_sandbox-0.1.0a0-py3-none-any.whl

Download URL inspect_capsem_sandbox-0.1.0a0-py3-none-any.whl
Size 52.1 kB
Tags Python 3
SHA-256 checksum
How to use checksums
5acc7a40e1e211773adbb37b976ea8449e3a384859ad586cbfadf78073ea0f5f
BLAKE2b-256 checksum
How to use checksums
f43b881cc7f614548fe18255f7f0216f178c9910b5810c346a0ef53837e2554f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.9.27 {"installer":{"name":"uv","version":"0.9.27","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Debian GNU/Linux rodete","version":null,"id":"rodete","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}

Release history Release notifications | RSS feed

This release

0.1.0a0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page