Skip to main content

Lightweight, secure sandboxes for untrusted processes.

Project description

Vpod Python SDK

A lightweight, portable sandbox that gives an untrusted process an instant Linux environment.

GitHub CI

It uses a RISC‑V architecture and runs entirely inside WebAssembly.

  • Fast startup : Boot in under a second.
  • Portable : Runs anywhere without any setup required.
  • Isolated : All execution state stays inside the WASM sandbox.

Installation

pip install vpod

Usage

Persistent session (Recommended)

All calls share the same running VM. Using a context manager (with) automatically cleans up resources when done:

from vpod import Sandbox

with Sandbox.create() as sbx:
    sbx.commands.run("export FOO=bar")
    sbx.commands.run("touch /tmp/data.csv")

    result = sbx.commands.run("echo $FOO")
    print(result.stdout)  # bar

Python REPL

Run Python code with persistent state across calls. Variables and imports persist for the lifetime of the session.

from vpod import Sandbox

with Sandbox.create() as sbx:
    sbx.code.run("import requests")
    sbx.code.run("data = [1, 2, 3]")
    result = sbx.code.run("print(sum(data))")
    print(result.text)  # 6

Advanced Configuration

You can mount local directories into the sandbox and specify which snapshot to use.

from vpod import Sandbox

# Mount a local workspace and use a snapshot with pre-installed data science tools
mounts = {"workspace": "/workspace:rw"}

with Sandbox.create(snapshot="vsnap-data", mounts=mounts) as sbx:
    sbx.code.run("import pandas as pd")
    sbx.code.run("print('Pandas is ready!')")

Shell commands (stateless)

If you just need a quick one-off execution without preserving state:

from vpod import Sandbox

sbx = Sandbox.create()
result = sbx.commands.run("echo hello")
print(result.stdout)    # hello
sbx.close()             # Clean up the sandbox process

Snapshots

The first call to Sandbox.create() downloads the VM snapshot and caches it locally. Subsequent calls use the cache instantly.

To pre-download (e.g. in a Dockerfile or CI setup):

from vpod import snapshots

for s in snapshots.fetch_registry():
    print(s["name"], s["tag"])

snapshots.pull("alpine:latest")

Available Snapshots

Name Tag Description Memory Limit (RAM)
alpine 3.23.0 Minimal Alpine Linux snapshot. 256 MB
vsnap-base 0.1.0 Alpine-based general-purpose snapshot with Python. 256 MB
vsnap-data 0.1.0 Alpine-based snapshot with numpy, pandas, and scipy. 512 MB

How it works

A vpod runs a RISC‑V virtual machine compiled to WebAssembly. The core implements the RV64GC specification:

  • G (General-purpose): I/M/A/F/D extensions for integer, multiply/divide, atomics, and floating-point.
  • C (Compressed): 30% smaller code size, improving memory efficiency.

The WASM component communicates with the host through WASI 0.2, providing controlled access to networking and I/O while keeping all execution state isolated inside the sandbox.

Limitations

  • Emulation overhead: No hardware acceleration in WASM. CPU-intensive workloads run slower than native.
  • No GPU access: CUDA, Metal, and hardware ML accelerators are not yet available.

For full documentation and to report issues, visit the main GitHub repository.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

vpod-0.3.1.tar.gz (158.0 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

vpod-0.3.1-py3-none-any.whl (155.8 kB view details)

Uploaded Python 3

File details

Details for the file vpod-0.3.1.tar.gz.

File metadata

  • Download URL: vpod-0.3.1.tar.gz
  • Upload date:
  • Size: 158.0 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.10.20

File hashes

Hashes for vpod-0.3.1.tar.gz
Algorithm Hash digest
SHA256 963735fe6936e110b1e3f1a58adb952394ad5384ff1b8211f5b8df1da7ce9a37
MD5 43e79e1c0646e0c65df267468d256efc
BLAKE2b-256 84b50a5799d1d68f6b1eac38b31500bec5e60169f222844ab70d17d35edd33f5

See more details on using hashes here.

File details

Details for the file vpod-0.3.1-py3-none-any.whl.

File metadata

  • Download URL: vpod-0.3.1-py3-none-any.whl
  • Upload date:
  • Size: 155.8 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.10.20

File hashes

Hashes for vpod-0.3.1-py3-none-any.whl
Algorithm Hash digest
SHA256 e04446a0f33bc0c12e17cd63e3063536931898921d6779d0a97884117e015fee
MD5 c85a8040451d9bf2b5b15bfe3d10dba8
BLAKE2b-256 93fe18083e40291b282e477cca72553ab97d24ec29d30cad39b77bbf93552f39

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page