Skip to main content

weft-microsandbox

Microsandbox runner plugin for Weft.

This extension runs disposable command and one-shot provider_cli agent tasks inside Microsandbox microVM sandboxes. It is intended for probably-hostile tools, MCP servers, and skills that need a harder process and filesystem boundary than the host runner.

The runner name is microsandbox.

Install with:

uv add 'weft[microsandbox]'

The current Microsandbox SDK supports Linux x86_64/aarch64 and macOS Apple Silicon. The SDK is Apache-2.0 licensed. A working local Microsandbox runtime is required for real execution; weft spec validate --preflight --load-runner checks the local runtime gate explicitly.

Tool Mode

{
  "spec": {
    "type": "command",
    "process_target": "python",
    "args": ["-c", "print('hello')"],
    "runner": {
      "name": "microsandbox",
      "options": {
        "image": "python:3.12-alpine",
        "mode": "tool",
        "network": "none",
        "workspace_mode": "none"
      }
    }
  }
}

Agent Mode

{
  "spec": {
    "type": "agent",
    "persistent": false,
    "agent": {
      "runtime": "provider_cli",
      "conversation_scope": "per_message",
      "runtime_config": {
        "provider": "codex"
      }
    },
    "runner": {
      "name": "microsandbox",
      "options": {
        "image": "ghcr.io/acme/codex-provider:latest",
        "mode": "agent",
        "executable": "codex",
        "network": "allow",
        "workspace_mode": "none"
      }
    }
  }
}

runner.options.executable is the executable inside the guest image. It is not resolved on the host.

Runner Options

  • image: required OCI image.
  • mode: optional; derived from spec.type as tool for command tasks and agent for agent tasks.
  • executable: required for agent mode; guest-local provider CLI command.
  • network: none by default, or allow.
  • workspace_mode: none by default, or copy, mount-read-only, or mount-read-write.
  • mounts: explicit host mounts. Entries default to read-only.
  • cwd: guest working directory. Required for workspace modes.
  • sandbox_name_prefix: optional runtime name prefix.

Security Defaults

  • network defaults to none.
  • workspace_mode defaults to none.
  • host environment variables are not forwarded unless they are explicit in spec.env.
  • persistent and interactive tasks are rejected.

Current Limitations

Memory, CPU, and file-descriptor limits are passed to the Microsandbox SDK, but the runner does not yet map SDK OOM or metrics evidence to RunnerOutcome(status="limit"). A guest killed by the runtime for memory pressure may currently surface as a generic execution error.

This runner is a process, VM, and filesystem boundary. It is not a semantic defense against prompt injection or malicious output.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

weft_microsandbox-0.5.2.tar.gz (11.8 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

weft_microsandbox-0.5.2-py3-none-any.whl (15.4 kB view details)

Uploaded Python 3

File details

Details for the file weft_microsandbox-0.5.2.tar.gz.

File metadata

  • Download URL: weft_microsandbox-0.5.2.tar.gz
  • Upload date:
  • Size: 11.8 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: uv/0.11.11 {"installer":{"name":"uv","version":"0.11.11","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

File hashes

Hashes for weft_microsandbox-0.5.2.tar.gz
Algorithm Hash digest
SHA256 29a552d2dd3d2fd11f7328d98ec72c6172bb6bdc3ca3eaea3055d1793c62ebfd
MD5 0d1bdde86897857a2d04d6b442209385
BLAKE2b-256 425b39be7661feda5440a63810ea4765f7e9c66ca2dc9ca2b4bcebc083870bec

See more details on using hashes here.

File details

Details for the file weft_microsandbox-0.5.2-py3-none-any.whl.

File metadata

  • Download URL: weft_microsandbox-0.5.2-py3-none-any.whl
  • Upload date:
  • Size: 15.4 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: uv/0.11.11 {"installer":{"name":"uv","version":"0.11.11","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

File hashes

Hashes for weft_microsandbox-0.5.2-py3-none-any.whl
Algorithm Hash digest
SHA256 957b9a1a94879e22b0f25dbe65f9c61ce9614ba3651f90255efbbbb22eb333f6
MD5 9a2e375febe96433e708325d6aafe993
BLAKE2b-256 34367dc770b1b69fdf7a3b6fed9a5d76e0ef8ff7f5216cb3cfbc787e5c4de920

See more details on using hashes here.

Release history Release notifications | RSS feed

This release

0.5.2 This release

2 files

0.5.1

2 files

0.5.0

2 files

0.1.0

2 files

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page