TencentCloud/CubeSandboxPublic

Instant, Concurrent, Secure & Lightweight Sandbox for AI Agents.

AI summary: A secure, lightweight sandbox environment for safely executing untrusted code in cloud environments.

Stars
12.8K
+14 today
Forks
1.2K
Watchers
69
Open issues
65
Open PRs
83
Contributors
~108
Commits
1K
Branches
5

GoOtherCreated Apr 10, 2026Last push 4d agoLatest release v0.7.2+90 stars this week+1K this month

Quick answers

What is CubeSandbox?
A secure, lightweight sandbox environment for safely executing untrusted code in cloud environments.
What does CubeSandbox do?
CubeSandbox is a high-performance isolation framework developed by Tencent Cloud, designed specifically to safely execute untrusted or third-party code. It leverages deep kernel-level technologies like namespaces, cgroups, and seccomp to create strict, lightweight execution boundaries that prevent malicious code from compromising the host system. The project provides an ergonomic API for dynamically provisioning these isolated environments, tightly controlling resource usage such as CPU, memory, and network access. It is engineered to maintain near-native execution speeds while enforcing rigorous security policies. It serves as a foundational component for cloud platforms requiring robust multi-tenant isolation, such as serverless computing or automated code evaluation systems.
Who is CubeSandbox for?
Targeted at cloud infrastructure engineers, security researchers, and developers building platforms that require safe execution of multi-tenant or untrusted workloads. Users are expected to have a basic understanding of the relevant underlying technologies.
How do I get started with CubeSandbox?
make build && ./bin/cubesandbox run --image alpine --cmd /bin/sh
How popular is CubeSandbox on GitHub?
TencentCloud/CubeSandbox has 12,798 stars and 1,170 forks on GitHub, and gained 90 stars in the last 7 days.
What license does CubeSandbox use?
TencentCloud/CubeSandbox is released under the Other license.

Star history

since Jul 30, 2026
05K10KJul 2026Aug 2026Sep 2026Oct 2026
12.8K stars as of Oct 4, 2026. Measured daily since Jul 30, 2026; GitHub no longer exposes earlier star timestamps.

Contribution activity

commits per day, last 52 weeks
SepOctNovDecJanFebMarAprMayJunJulAugSepMonWedFri2025-09-28: 0 commits2025-09-29: 0 commits2025-09-30: 0 commits2025-10-01: 0 commits2025-10-02: 0 commits2025-10-03: 0 commits2025-10-04: 0 commits2025-10-05: 0 commits2025-10-06: 0 commits2025-10-07: 0 commits2025-10-08: 0 commits2025-10-09: 0 commits2025-10-10: 0 commits2025-10-11: 0 commits2025-10-12: 0 commits2025-10-13: 0 commits2025-10-14: 0 commits2025-10-15: 0 commits2025-10-16: 0 commits2025-10-17: 0 commits2025-10-18: 0 commits2025-10-19: 0 commits2025-10-20: 0 commits2025-10-21: 0 commits2025-10-22: 0 commits2025-10-23: 0 commits2025-10-24: 0 commits2025-10-25: 0 commits2025-10-26: 0 commits2025-10-27: 0 commits2025-10-28: 0 commits2025-10-29: 0 commits2025-10-30: 0 commits2025-10-31: 0 commits2025-11-01: 0 commits2025-11-02: 0 commits2025-11-03: 0 commits2025-11-04: 0 commits2025-11-05: 0 commits2025-11-06: 0 commits2025-11-07: 0 commits2025-11-08: 0 commits2025-11-09: 0 commits2025-11-10: 0 commits2025-11-11: 0 commits2025-11-12: 0 commits2025-11-13: 0 commits2025-11-14: 0 commits2025-11-15: 0 commits2025-11-16: 0 commits2025-11-17: 0 commits2025-11-18: 0 commits2025-11-19: 0 commits2025-11-20: 0 commits2025-11-21: 0 commits2025-11-22: 0 commits2025-11-23: 0 commits2025-11-24: 0 commits2025-11-25: 0 commits2025-11-26: 0 commits2025-11-27: 0 commits2025-11-28: 0 commits2025-11-29: 0 commits2025-11-30: 0 commits2025-12-01: 0 commits2025-12-02: 0 commits2025-12-03: 0 commits2025-12-04: 0 commits2025-12-05: 0 commits2025-12-06: 0 commits2025-12-07: 0 commits2025-12-08: 0 commits2025-12-09: 0 commits2025-12-10: 0 commits2025-12-11: 0 commits2025-12-12: 0 commits2025-12-13: 0 commits2025-12-14: 0 commits2025-12-15: 0 commits2025-12-16: 0 commits2025-12-17: 0 commits2025-12-18: 0 commits2025-12-19: 0 commits2025-12-20: 0 commits2025-12-21: 0 commits2025-12-22: 0 commits2025-12-23: 0 commits2025-12-24: 0 commits2025-12-25: 0 commits2025-12-26: 0 commits2025-12-27: 0 commits2025-12-28: 0 commits2025-12-29: 0 commits2025-12-30: 0 commits2025-12-31: 0 commits2026-01-01: 0 commits2026-01-02: 0 commits2026-01-03: 0 commits2026-01-04: 0 commits2026-01-05: 0 commits2026-01-06: 0 commits2026-01-07: 0 commits2026-01-08: 0 commits2026-01-09: 0 commits2026-01-10: 0 commits2026-01-11: 0 commits2026-01-12: 0 commits2026-01-13: 0 commits2026-01-14: 0 commits2026-01-15: 0 commits2026-01-16: 0 commits2026-01-17: 0 commits2026-01-18: 0 commits2026-01-19: 0 commits2026-01-20: 0 commits2026-01-21: 0 commits2026-01-22: 0 commits2026-01-23: 0 commits2026-01-24: 0 commits2026-01-25: 0 commits2026-01-26: 0 commits2026-01-27: 0 commits2026-01-28: 0 commits2026-01-29: 0 commits2026-01-30: 0 commits2026-01-31: 0 commits2026-02-01: 0 commits2026-02-02: 0 commits2026-02-03: 0 commits2026-02-04: 0 commits2026-02-05: 0 commits2026-02-06: 0 commits2026-02-07: 0 commits2026-02-08: 0 commits2026-02-09: 0 commits2026-02-10: 0 commits2026-02-11: 0 commits2026-02-12: 0 commits2026-02-13: 0 commits2026-02-14: 0 commits2026-02-15: 0 commits2026-02-16: 0 commits2026-02-17: 0 commits2026-02-18: 0 commits2026-02-19: 0 commits2026-02-20: 0 commits2026-02-21: 0 commits2026-02-22: 0 commits2026-02-23: 0 commits2026-02-24: 0 commits2026-02-25: 0 commits2026-02-26: 0 commits2026-02-27: 0 commits2026-02-28: 0 commits2026-03-01: 0 commits2026-03-02: 0 commits2026-03-03: 0 commits2026-03-04: 0 commits2026-03-05: 0 commits2026-03-06: 0 commits2026-03-07: 0 commits2026-03-08: 0 commits2026-03-09: 0 commits2026-03-10: 0 commits2026-03-11: 0 commits2026-03-12: 0 commits2026-03-13: 0 commits2026-03-14: 0 commits2026-03-15: 0 commits2026-03-16: 0 commits2026-03-17: 0 commits2026-03-18: 0 commits2026-03-19: 0 commits2026-03-20: 0 commits2026-03-21: 0 commits2026-03-22: 0 commits2026-03-23: 0 commits2026-03-24: 0 commits2026-03-25: 0 commits2026-03-26: 0 commits2026-03-27: 0 commits2026-03-28: 0 commits2026-03-29: 0 commits2026-03-30: 0 commits2026-03-31: 0 commits2026-04-01: 0 commits2026-04-02: 0 commits2026-04-03: 0 commits2026-04-04: 0 commits2026-04-05: 0 commits2026-04-06: 0 commits2026-04-07: 0 commits2026-04-08: 0 commits2026-04-09: 0 commits2026-04-10: 0 commits2026-04-11: 0 commits2026-04-12: 0 commits2026-04-13: 0 commits2026-04-14: 3 commits2026-04-15: 0 commits2026-04-16: 8 commits2026-04-17: 2 commits2026-04-18: 0 commits2026-04-19: 0 commits2026-04-20: 8 commits2026-04-21: 8 commits2026-04-22: 12 commits2026-04-23: 18 commits2026-04-24: 14 commits2026-04-25: 1 commit2026-04-26: 0 commits2026-04-27: 5 commits2026-04-28: 6 commits2026-04-29: 2 commits2026-04-30: 1 commit2026-05-01: 0 commits2026-05-02: 0 commits2026-05-03: 0 commits2026-05-04: 5 commits2026-05-05: 0 commits2026-05-06: 3 commits2026-05-07: 8 commits2026-05-08: 5 commits2026-05-09: 4 commits2026-05-10: 1 commit2026-05-11: 3 commits2026-05-12: 8 commits2026-05-13: 9 commits2026-05-14: 14 commits2026-05-15: 7 commits2026-05-16: 3 commits2026-05-17: 1 commit2026-05-18: 5 commits2026-05-19: 10 commits2026-05-20: 11 commits2026-05-21: 7 commits2026-05-22: 1 commit2026-05-23: 2 commits2026-05-24: 2 commits2026-05-25: 8 commits2026-05-26: 4 commits2026-05-27: 12 commits2026-05-28: 10 commits2026-05-29: 7 commits2026-05-30: 0 commits2026-05-31: 3 commits2026-06-01: 6 commits2026-06-02: 8 commits2026-06-03: 7 commits2026-06-04: 6 commits2026-06-05: 13 commits2026-06-06: 2 commits2026-06-07: 0 commits2026-06-08: 8 commits2026-06-09: 9 commits2026-06-10: 4 commits2026-06-11: 14 commits2026-06-12: 14 commits2026-06-13: 1 commit2026-06-14: 4 commits2026-06-15: 4 commits2026-06-16: 9 commits2026-06-17: 7 commits2026-06-18: 5 commits2026-06-19: 0 commits2026-06-20: 0 commits2026-06-21: 0 commits2026-06-22: 14 commits2026-06-23: 8 commits2026-06-24: 2 commits2026-06-25: 7 commits2026-06-26: 14 commits2026-06-27: 6 commits2026-06-28: 6 commits2026-06-29: 4 commits2026-06-30: 3 commits2026-07-01: 8 commits2026-07-02: 5 commits2026-07-03: 11 commits2026-07-04: 7 commits2026-07-05: 1 commit2026-07-06: 14 commits2026-07-07: 10 commits2026-07-08: 15 commits2026-07-09: 8 commits2026-07-10: 17 commits2026-07-11: 3 commits2026-07-12: 3 commits2026-07-13: 7 commits2026-07-14: 6 commits2026-07-15: 5 commits2026-07-16: 5 commits2026-07-17: 7 commits2026-07-18: 4 commits2026-07-19: 3 commits2026-07-20: 16 commits2026-07-21: 11 commits2026-07-22: 20 commits2026-07-23: 18 commits2026-07-24: 9 commits2026-07-25: 0 commits2026-07-26: 1 commit2026-07-27: 8 commits2026-07-28: 8 commits2026-07-29: 7 commits2026-07-30: 13 commits2026-07-31: 6 commits2026-08-01: 3 commits2026-08-02: 0 commits2026-08-03: 6 commits2026-08-04: 11 commits2026-08-05: 7 commits2026-08-06: 8 commits2026-08-07: 8 commits2026-08-08: 1 commit2026-08-09: 1 commit2026-08-10: 5 commits2026-08-11: 7 commits2026-08-12: 13 commits2026-08-13: 7 commits2026-08-14: 2 commits2026-08-15: 1 commit2026-08-16: 1 commit2026-08-17: 11 commits2026-08-18: 10 commits2026-08-19: 10 commits2026-08-20: 4 commits2026-08-21: 2 commits2026-08-22: 3 commits2026-08-23: 0 commits2026-08-24: 10 commits2026-08-25: 19 commits2026-08-26: 13 commits2026-08-27: 17 commits2026-08-28: 14 commits2026-08-29: 0 commits2026-08-30: 0 commits2026-08-31: 6 commits2026-09-01: 15 commits2026-09-02: 9 commits2026-09-03: 5 commits2026-09-04: 10 commits2026-09-05: 1 commit2026-09-06: 1 commit2026-09-07: 5 commits2026-09-08: 9 commits2026-09-09: 4 commits2026-09-10: 5 commits2026-09-11: 8 commits2026-09-12: 2 commits2026-09-13: 0 commits2026-09-14: 6 commits2026-09-15: 5 commits2026-09-16: 5 commits2026-09-17: 4 commits2026-09-18: 3 commits2026-09-19: 1 commit2026-09-20: 4 commits2026-09-21: 18 commits2026-09-22: 5 commits2026-09-23: 7 commits2026-09-24: 4 commits2026-09-25: 0 commits2026-09-26: 0 commits
1,018 commits in the last yearLessMore

Signals and awards

derived from tracked data
  • Widely adopted

    12,798 stars

  • Very active

    1,018 commits in 52 weeks

  • Community-driven

    ~108 contributors

  • Repeat trending

    3 trending appearances

What CubeSandbox does

CubeSandbox is a high-performance isolation framework developed by Tencent Cloud, designed specifically to safely execute untrusted or third-party code. It leverages deep kernel-level technologies like namespaces, cgroups, and seccomp to create strict, lightweight execution boundaries that prevent malicious code from compromising the host system. The project provides an ergonomic API for dynamically provisioning these isolated environments, tightly controlling resource usage such as CPU, memory, and network access. It is engineered to maintain near-native execution speeds while enforcing rigorous security policies. It serves as a foundational component for cloud platforms requiring robust multi-tenant isolation, such as serverless computing or automated code evaluation systems.

Targeted at cloud infrastructure engineers, security researchers, and developers building platforms that require safe execution of multi-tenant or untrusted workloads. Users are expected to have a basic understanding of the relevant underlying technologies.

  • Kernel-level isolation: Utilizes namespaces, cgroups, and seccomp to enforce strict boundaries around untrusted code execution.
  • Granular resource control: Precisely limits and monitors CPU, memory, disk I/O, and network bandwidth for every provisioned sandbox.
  • High-performance execution: Engineered to minimize startup latency and execution overhead, ensuring near-native speeds for sandboxed applications.
  • Dynamic provisioning API: Provides a robust interface for rapidly creating, managing, and tearing down secure environments on demand.
  • Advanced threat mitigation: Prevents unauthorized system calls and filesystem access, protecting the underlying host from exploitation.

Where teams use it

Serverless function execution

Providing the secure, underlying isolation layer required to safely run multi-tenant serverless workloads on shared cloud infrastructure.

Automated code evaluation

Safely executing and grading user-submitted code snippets in online competitive programming platforms or educational tools.

Secure continuous integration

Isolating untrusted build scripts and dependencies during CI/CD pipelines to prevent supply chain attacks against the build server.

Malware analysis

Creating tightly controlled, disposable environments to safely execute and observe the behavior of potentially malicious software.

Getting started: make build && ./bin/cubesandbox run --image alpine --cmd /bin/sh

README

master branch

Cube Sandbox Logo

CubeSandbox

Instant, Concurrent, Secure & Lightweight Sandbox Service for AI Agents

TencentCloud/CubeSandbox | Trendshift

GitHub Stars GitHub Issues Apache 2.0 License PRs Welcome PyPI Version CNCF Landscape

Fast startup Hardware-level isolation E2B compatible High concurrency & high density

中文文档 · Quick Start · Documentation · Changelog · X(Twitter) · Top Contributor Program · Submit Use Case


Cube Sandbox is a high-performance, out-of-the-box secure sandbox service built on RustVMM and KVM. It supports both single-node deployment and easy scaling to multi-node clusters. It is compatible with the E2B SDK and can create a hardware-isolated, fully serviceable sandbox in under 60ms with less than 5MB of memory overhead.

📰 News

v0.7.0 v0.7: Cross-node pause/resume, control plane & ops separation, faster sandbox networking
Cross-node pause/resume — with an S3 backend, suspend a sandbox on one node and resume it on another, or create sandboxes from snapshots (preview)
Control plane & operations separation — node management moves into CubeOps with multi-replica deployment and the new cubeopscli
Changelog →
v0.6.0 v0.6: K8s deploy, Volume framework, template aliases
K8s deploy — Deploy Cube control-plane components and compute nodes on Kubernetes
Volume framework — E2B-compatible Volume framework that lets users plug in custom backend storage
Template aliases — Set an alias when creating a template, and create sandboxes by specifying that alias.
Changelog → · K8s deploy → · Volume plugin →
v0.5.0 v0.5: AutoPause, Terraform deployer, ARM64 & network policy hardening
AutoPause/AutoResume — idle sandboxes auto-suspend and wake on the next request. Terraform one-click cluster deploy ARM64 native full-stack support network policy hardening — per-sandbox traffic tokens, policy-routing egress.
Changelog → · Terraform deploy →
v0.4.0 v0.4: Safer egress, easier ops
Credential vault — Agents call external APIs as usual; keys never enter the sandbox. Dashboard — version matrix and template health checks; see at a glance whether templates need rebuilding after upgrades.
Changelog → · Security proxy guide → · WebUI guide →
v0.3.0 Snapshot, Clone & Rollback at hundred-millisecond granularity
CubeSandbox 0.3.0 introduces the CubeCoW Copy-on-Write snapshot engine, enabling event-level snapshots, instant cloning, and rollback to any saved state. Changelog →
v0.1.0 🎉 Initial open-source release
Cube Sandbox is now open source! Millisecond boot, hardware-level isolation, E2B-compatible sandbox for AI Agents. Changelog →

Product Highlights

⚡ Ultra-fast Startup

Resource pooling and snapshot cloning skip all cold-start overhead. Average <60ms cold start — sandbox creation faster than a blink.

Quick start →
🔒 Hardware Isolation

Every sandbox runs a dedicated OS kernel in its own MicroVM.

Architecture →
🔌 E2B SDK Compatible

Compatible with E2B SDK interface. Switch from E2B Cloud seamlessly by changing one environment variable — zero client code changes.

Examples →
📦 High-density Deployment

<5MB overhead per sandbox enables thousands of instances per server via kernel sharing and Copy-on-Write (CoW). Supports automatic sandbox pause and resume, further improving deployment density and cost optimization.

Quick start →
🛡️ Network Security

eBPF-based inter-sandbox isolation and egress filtering at kernel level; built-in L7 security proxy enables per-domain/path/method policies with automatic credential injection — secrets never visible to sandbox code.

Security proxy guide →
📸 Flexible State Management

High-frequency snapshot and rollback at hundred-millisecond granularity. Create checkpoints on running sandboxes, roll back to any saved state at any time, or fork from a specific state to explore in parallel.

v0.3 changelog →
💾 Volume Framework

E2B-compatible Volume framework that lets users plug in custom backend storage solutions. Volumes have an independent lifecycle and can be shared across sandboxes.

Volume plugin →
🚀 Production Deployment

Deploy production clusters on Tencent Cloud with one click using Terraform. Also supports deployment on standard Kubernetes clusters (preview).

Terraform deploy → · K8s deploy →
💪 ARM Architecture Support

Full native ARM64 support across compilation, build, and deployment workflows.

Bare-metal deploy →

Demos

1.cubesandbox.-.mp4
2.cubesandbox.demo.mp4
Cube-Sandbox.RL.demo.mp4
5.cube.V0.3.0.-.-.mp4
Installation & Demo Performance Test RL (SWE-Bench) Snapshot · Clone · Rollback

Benchmarks

In the context of AI Agent code execution, CubeSandbox achieves the perfect balance of security and performance:

Metric Docker Container Traditional VM CubeSandbox
Isolation Level Low (Shared Kernel Namespaces) High (Dedicated Kernel) Extreme (Dedicated Kernel + eBPF)
Boot Speed
*Full-OS boot duration
200ms Seconds Sub-millisecond (<60ms)
Memory Overhead Low (Shared Kernel) High (Full OS) Ultra-low (Aggressively stripped, <5MB)
Deployment Density High Low Extreme (Thousands per node)
E2B SDK Compatible / / ✅ Drop-in
  • Cold start benchmarked on bare-metal. 60ms at single concurrency; under 50 concurrent creations, avg 67ms, P95 90ms, P99 137ms — consistently sub-150ms.
  • Memory overhead measured with sandbox specs ≤ 32GB. Larger configurations may see a marginal increase.

For detailed metrics on startup latency and resource overhead, see the Core Operations Performance Benchmark Report (bare metal) and the PVM Cloud Server Benchmark Report.

Sub-150ms sandbox delivery under both single and high-concurrency workloads CubeSandbox base memory footprint across various instance sizes
(*Blue: Sandbox specifications; Orange: Base memory overhead). Note that memory consumption increases only marginally as instance sizes scale up.

Quick Start


Cube Sandbox fast start walkthrough

⚡ Millisecond-level startup — watch the fast-start flow above.

Cube Sandbox requires an x86_64 Linux environment with KVM support.

The guide walks you through everything in four steps — provisioning a server, installing Cube Sandbox, creating a sandbox template, and running your first agent code. No source build needed, up and running in minutes.

Choose your deployment path:

🖥 PVM · Cloud VM →
🏆 Recommended
🏗 Bare Metal → 💻 Dev-Env →
⚠️ Not recommended — poor performance

First thing after install: open the Web console

WebUI console walkthrough

🖥️ Visual management — from overview to creating a sandbox and streaming logs, all in your browser.

After one-click deployment, open in your browser:

http://<control-node IP>:12088

Recommended three steps:

  1. Check overview — Open Overview, confirm nodes are Ready and capacity looks healthy
  2. Prepare a template — Install an official preset from Template Store; skip if you already have a READY template under Templates
  3. Create a sandbox — Sandboxes → + New sandbox, pick a READY template, and view live logs on the detail page within seconds

See the full WebUI console guide.

Deep Dive

Architecture

Cube Sandbox Architecture

Component Responsibility
CubeAPI High-concurrency REST API Gateway (Rust), compatible with E2B. Swap the URL for seamless migration.
CubeMaster Cluster orchestrator. Receives API requests and dispatches them to corresponding Cubelets. Manages resource scheduling and cluster state.
CubeProxy Reverse proxy, compatible with the E2B protocol, routing requests to the appropriate sandbox instances.
Cubelet Compute node local scheduling component. Manages the complete lifecycle of all sandbox instances on the node.
CubeVS eBPF-based virtual switch, providing kernel-level network isolation and security policy enforcement.
CubeEgress OpenResty-based egress security gateway: L7 domain filtering, credential injection, and access auditing; works with CubeVS kernel policies so sandbox traffic cannot bypass inspection.
CubeHypervisor & CubeShim Virtualization layer — CubeHypervisor manages KVM MicroVMs, CubeShim implements the containerd Shim v2 API to integrate sandboxes into the container runtime.

👉 For more details, please read the Architecture Design Document and CubeVS Network Model.

Community & Contributing

We welcome contributions of all kinds—whether it's a bug report, feature suggestion, documentation improvement, or code submission!

  • 🐞 Found a Bug or have questions? Submit an issue on GitHub Issues.
  • 💡 Have an Idea? Join the conversation in GitHub Discussions.
  • 🛠️ Want to Code? Check out our CONTRIBUTING.md to learn how to submit a Pull Request.
  • 📝 Want to contribute docs? Submit bilingual PRs to our community doc channels: Troubleshooting, Use Cases, and Integrations. Additionally, the Cube 100 Program is now open — we're looking for the first 100 teams running AI agents in production with Cube. Limited to 100 seats. Learn more & apply →
  • 💬 Want to Chat? Join our Discord.

Roadmap

Coming soon — see the full roadmap for details.

Feature Description
Cross-Node Pause/Resume Performance Cut pause/resume latency and speed up snapshot transfer so cross-node resume approaches same-node speed
E2B API Compatibility Close remaining gaps with the E2B specification for full drop-in compatibility
Sandbox Fault Recovery Automatic detection and recovery of crashed VMs, stuck shim processes, and network partitions with configurable recovery policies
Scheduling & Operations Enhancements Resource-aware placement, affinity rules, live rebalancing, and node drain with sandbox migration
S3 Performance and Cost Optimization Incremental uploads, better cache, and cheaper storage classes so S3 snapshot/volume I/O stays fast at lower cost
Filesystem-Only Snapshots Snapshot the writable filesystem without a memory dump for cheaper, faster clone/restore when a cold start from disk is enough
GPU Sandboxes Attach host GPUs to sandboxes so Agent and inference workloads can run CUDA inside the isolated VM, with GPU-aware scheduling

Contributors

Thanks to all contributors:

Contributors

License

CubeSandbox is released under the Apache License 2.0.

The birth of CubeSandbox stands on the shoulders of open-source giants. Special thanks to Cloud Hypervisor, Kata Containers, virtiofsd, containerd-shim-rs, ttrpc-rust, and others. We have made tailored modifications to some components to fit the CubeSandbox execution model, and the original in-file copyright notices are preserved.


CNCF Landscape

Cube Sandbox is listed in the CNCF Landscape.

View on GitHub

Recent activity

commits and pull requests

Recent open issues

view all

Discussions

all 25

Releases and announcements

51 total
  1. v0.7.2v0.7.2Sep 24, 202645 downloads

    ## 2026.09.24 Release v0.7.2 CubeSandbox 0.7.2 introduces 3 major features along with multiple enhancements and bug fixes. 56 commits from 29 contributors. ### 🎯 Major Features #### Much faster cross-node restore reads Sandboxes restored cross-node on the S3 backend read disk data from S3 on demand; this release optimizes that read path systematically: - New whole-object local cache: immutable data objects on S3 are kept on the local node, so repeated reads after a restore — and re-importing the same snapshot — hit the local cache instead of going back to S3. - Reduced read amplification during restore: scattered small reads are coalesced into whole-object GETs, and the concurrent fetch budget is capped. - With the default MinIO setup, cross-node restore / create-from-snapshot reaches running in under 1 second. #### New JuiceFS volume plugin New JuiceFS storage plugin: sandboxes can mount a JuiceFS filesystem as a persistent volume, with full POSIX semantics. #### Automatic reclaim of idle guest memory Idle memory inside sandboxes is reclaimed back to the host: node memory usage falls back dynamically with the real usage of the sandboxes, so a single n

  2. v0.7.2-rc3v0.7.2-rc3Sep 24, 2026pre-release9 downloads

    v0.7.2-rc3

  3. v0.7.2-rc2v0.7.2-rc2Sep 23, 2026pre-release19 downloads

    v0.7.2-rc2

  4. v0.7.2-rc1v0.7.2-rc1Sep 21, 2026pre-release32 downloads

    v0.7.2-rc1

  5. kernel-release-260921-1kernel-release-260921-1Sep 21, 2026162 downloads

    Dedicated kernel assets release (BM + PVM guest + PVM host).

Code frequency

additions and deletions
+539.1K-539.1KWeek of 2026-04-12: +539,109 linesWeek of 2026-04-12: -135 linesWeek of 2026-04-19: +16,406 linesWeek of 2026-04-19: -1,591 linesWeek of 2026-04-26: +29,430 linesWeek of 2026-04-26: -1,010 linesWeek of 2026-05-03: +2,565 linesWeek of 2026-05-03: -1,096 linesWeek of 2026-05-10: +8,396 linesWeek of 2026-05-10: -3,191 linesWeek of 2026-05-17: +14,977 linesWeek of 2026-05-17: -1,214 linesWeek of 2026-05-24: +46,282 linesWeek of 2026-05-24: -3,637 linesWeek of 2026-05-31: +246,382 linesWeek of 2026-05-31: -114,418 linesWeek of 2026-06-07: +57,720 linesWeek of 2026-06-07: -12,515 linesWeek of 2026-06-14: +12,101 linesWeek of 2026-06-14: -922 linesWeek of 2026-06-21: +31,172 linesWeek of 2026-06-21: -5,719 linesWeek of 2026-06-28: +22,929 linesWeek of 2026-06-28: -5,730 linesWeek of 2026-07-05: +26,357 linesWeek of 2026-07-05: -9,903 linesWeek of 2026-07-12: +31,673 linesWeek of 2026-07-12: -3,060 linesWeek of 2026-07-19: +75,092 linesWeek of 2026-07-19: -29,772 linesWeek of 2026-07-26: +8,878 linesWeek of 2026-07-26: -1,693 linesWeek of 2026-08-02: +31,791 linesWeek of 2026-08-02: -23,217 linesWeek of 2026-08-09: +27,264 linesWeek of 2026-08-09: -4,463 linesWeek of 2026-08-16: +27,996 linesWeek of 2026-08-16: -2,373 linesWeek of 2026-08-23: +120,313 linesWeek of 2026-08-23: -14,262 linesWeek of 2026-08-30: +48,467 linesWeek of 2026-08-30: -35,237 linesWeek of 2026-09-06: +69,242 linesWeek of 2026-09-06: -22,385 linesWeek of 2026-09-13: +16,780 linesWeek of 2026-09-13: -2,867 linesWeek of 2026-09-20: +28,323 linesWeek of 2026-09-20: -3,572 linesApr 12, 2026Sep 20, 2026
+1.5M lines added, -304K removed over the last year.

Commits per week

last 52 weeks
770Week of 2025-09-28: 0 commitsWeek of 2025-10-05: 0 commitsWeek of 2025-10-12: 0 commitsWeek of 2025-10-19: 0 commitsWeek of 2025-10-26: 0 commitsWeek of 2025-11-02: 0 commitsWeek of 2025-11-09: 0 commitsWeek of 2025-11-16: 0 commitsWeek of 2025-11-23: 0 commitsWeek of 2025-11-30: 0 commitsWeek of 2025-12-07: 0 commitsWeek of 2025-12-14: 0 commitsWeek of 2025-12-21: 0 commitsWeek of 2025-12-28: 0 commitsWeek of 2026-01-04: 0 commitsWeek of 2026-01-11: 0 commitsWeek of 2026-01-18: 0 commitsWeek of 2026-01-25: 0 commitsWeek of 2026-02-01: 0 commitsWeek of 2026-02-08: 0 commitsWeek of 2026-02-15: 0 commitsWeek of 2026-02-22: 0 commitsWeek of 2026-03-01: 0 commitsWeek of 2026-03-08: 0 commitsWeek of 2026-03-15: 0 commitsWeek of 2026-03-22: 0 commitsWeek of 2026-03-29: 0 commitsWeek of 2026-04-05: 0 commitsWeek of 2026-04-12: 13 commitsWeek of 2026-04-19: 61 commitsWeek of 2026-04-26: 14 commitsWeek of 2026-05-03: 25 commitsWeek of 2026-05-10: 45 commitsWeek of 2026-05-17: 37 commitsWeek of 2026-05-24: 43 commitsWeek of 2026-05-31: 45 commitsWeek of 2026-06-07: 50 commitsWeek of 2026-06-14: 29 commitsWeek of 2026-06-21: 51 commitsWeek of 2026-06-28: 44 commitsWeek of 2026-07-05: 68 commitsWeek of 2026-07-12: 37 commitsWeek of 2026-07-19: 77 commitsWeek of 2026-07-26: 46 commitsWeek of 2026-08-02: 41 commitsWeek of 2026-08-09: 36 commitsWeek of 2026-08-16: 41 commitsWeek of 2026-08-23: 73 commitsWeek of 2026-08-30: 46 commitsWeek of 2026-09-06: 34 commitsWeek of 2026-09-13: 24 commitsWeek of 2026-09-20: 38 commitsSep 28, 2025Sep 20, 2026
1K commits in the last 52 weeks.

When work happens

weekday and hour
SunMonTueWedThuFriSat036912151821Sun 0:00 — 1 commitsSun 1:00 — 0 commitsSun 2:00 — 0 commitsSun 3:00 — 0 commitsSun 4:00 — 0 commitsSun 5:00 — 0 commitsSun 6:00 — 1 commitsSun 7:00 — 0 commitsSun 8:00 — 0 commitsSun 9:00 — 2 commitsSun 10:00 — 3 commitsSun 11:00 — 2 commitsSun 12:00 — 2 commitsSun 13:00 — 6 commitsSun 14:00 — 2 commitsSun 15:00 — 1 commitsSun 16:00 — 3 commitsSun 17:00 — 1 commitsSun 18:00 — 2 commitsSun 19:00 — 0 commitsSun 20:00 — 1 commitsSun 21:00 — 2 commitsSun 22:00 — 2 commitsSun 23:00 — 1 commitsMon 0:00 — 1 commitsMon 1:00 — 0 commitsMon 2:00 — 0 commitsMon 3:00 — 0 commitsMon 4:00 — 1 commitsMon 5:00 — 0 commitsMon 6:00 — 0 commitsMon 7:00 — 0 commitsMon 8:00 — 0 commitsMon 9:00 — 1 commitsMon 10:00 — 13 commitsMon 11:00 — 15 commitsMon 12:00 — 12 commitsMon 13:00 — 0 commitsMon 14:00 — 11 commitsMon 15:00 — 20 commitsMon 16:00 — 26 commitsMon 17:00 — 18 commitsMon 18:00 — 13 commitsMon 19:00 — 16 commitsMon 20:00 — 20 commitsMon 21:00 — 9 commitsMon 22:00 — 4 commitsMon 23:00 — 2 commitsTue 0:00 — 0 commitsTue 1:00 — 0 commitsTue 2:00 — 1 commitsTue 3:00 — 0 commitsTue 4:00 — 0 commitsTue 5:00 — 1 commitsTue 6:00 — 0 commitsTue 7:00 — 0 commitsTue 8:00 — 3 commitsTue 9:00 — 4 commitsTue 10:00 — 20 commitsTue 11:00 — 28 commitsTue 12:00 — 13 commitsTue 13:00 — 2 commitsTue 14:00 — 16 commitsTue 15:00 — 28 commitsTue 16:00 — 22 commitsTue 17:00 — 19 commitsTue 18:00 — 9 commitsTue 19:00 — 4 commitsTue 20:00 — 9 commitsTue 21:00 — 8 commitsTue 22:00 — 3 commitsTue 23:00 — 2 commitsWed 0:00 — 1 commitsWed 1:00 — 1 commitsWed 2:00 — 0 commitsWed 3:00 — 0 commitsWed 4:00 — 0 commitsWed 5:00 — 0 commitsWed 6:00 — 0 commitsWed 7:00 — 1 commitsWed 8:00 — 1 commitsWed 9:00 — 1 commitsWed 10:00 — 15 commitsWed 11:00 — 29 commitsWed 12:00 — 6 commitsWed 13:00 — 3 commitsWed 14:00 — 21 commitsWed 15:00 — 24 commitsWed 16:00 — 16 commitsWed 17:00 — 18 commitsWed 18:00 — 4 commitsWed 19:00 — 19 commitsWed 20:00 — 22 commitsWed 21:00 — 7 commitsWed 22:00 — 3 commitsWed 23:00 — 0 commitsThu 0:00 — 1 commitsThu 1:00 — 1 commitsThu 2:00 — 0 commitsThu 3:00 — 0 commitsThu 4:00 — 0 commitsThu 5:00 — 1 commitsThu 6:00 — 0 commitsThu 7:00 — 0 commitsThu 8:00 — 0 commitsThu 9:00 — 2 commitsThu 10:00 — 8 commitsThu 11:00 — 28 commitsThu 12:00 — 9 commitsThu 13:00 — 2 commitsThu 14:00 — 11 commitsThu 15:00 — 17 commitsThu 16:00 — 24 commitsThu 17:00 — 26 commitsThu 18:00 — 11 commitsThu 19:00 — 13 commitsThu 20:00 — 17 commitsThu 21:00 — 18 commitsThu 22:00 — 8 commitsThu 23:00 — 4 commitsFri 0:00 — 4 commitsFri 1:00 — 0 commitsFri 2:00 — 1 commitsFri 3:00 — 3 commitsFri 4:00 — 1 commitsFri 5:00 — 0 commitsFri 6:00 — 0 commitsFri 7:00 — 0 commitsFri 8:00 — 1 commitsFri 9:00 — 2 commitsFri 10:00 — 14 commitsFri 11:00 — 20 commitsFri 12:00 — 12 commitsFri 13:00 — 4 commitsFri 14:00 — 17 commitsFri 15:00 — 25 commitsFri 16:00 — 17 commitsFri 17:00 — 21 commitsFri 18:00 — 8 commitsFri 19:00 — 4 commitsFri 20:00 — 7 commitsFri 21:00 — 5 commitsFri 22:00 — 3 commitsFri 23:00 — 5 commitsSat 0:00 — 9 commitsSat 1:00 — 0 commitsSat 2:00 — 1 commitsSat 3:00 — 0 commitsSat 4:00 — 0 commitsSat 5:00 — 0 commitsSat 6:00 — 1 commitsSat 7:00 — 0 commitsSat 8:00 — 0 commitsSat 9:00 — 1 commitsSat 10:00 — 2 commitsSat 11:00 — 3 commitsSat 12:00 — 2 commitsSat 13:00 — 2 commitsSat 14:00 — 2 commitsSat 15:00 — 5 commitsSat 16:00 — 2 commitsSat 17:00 — 4 commitsSat 18:00 — 2 commitsSat 19:00 — 2 commitsSat 20:00 — 2 commitsSat 21:00 — 3 commitsSat 22:00 — 0 commitsSat 23:00 — 2 commits
Commit volume by weekday and hour (UTC). Larger dots mean more commits.
DateListRankStars gained
Apr 24, 2026daily#23+101
Apr 23, 2026daily#22+91
Apr 22, 2026daily#8+189
  • Significant-Gravitas/AutoGPT

    AutoGPT is the vision of accessible AI for everyone, to use and to build on. Our mission is to provide the tools, so that you can focus on what matters.

    187.7K stars · Python

  • avelino/awesome-go

    A curated list of awesome Go frameworks, libraries and software

    186.9K stars · Go

  • Shubhamsaboo/awesome-llm-apps

    100+ AI Agents, Agent Skills and RAG Apps - Free and Open Source.

    140.7K stars · Python

  • kubernetes/kubernetes

    Production-Grade Container Scheduling and Management

    128.3K stars · Go

  • microsoft/TypeScript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

    111.3K stars · Go

  • JuliusBrussee/caveman

    🪨 why use many token when few token do trick. Viral skill + proxy for coding agents that cuts 65% of tokens by talking like a caveman.

    109.8K stars · Go