awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectAboutHow we rankPressMCP server
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
TencentCloud avatar

TencentCloud/CubeSandbox

0
View on GitHub↗
cubesandbox.com↗

CubeSandbox

CubeSandbox is a Kubernetes-based platform for executing AI agents in secure, lightweight environments. It provides a code execution sandbox that uses hardware isolation and dedicated guest kernels to run untrusted code without risking the host system.

The project features a network egress firewall that restricts outbound communication via domain allowlists and audit logging. It also includes a container snapshotting manager capable of capturing the runtime memory and disk state of environments to enable instant cloning and recovery.

The platform covers cluster orchestration through a web-based administrative dashboard for monitoring node health and managing container templates. Additional capabilities include secure credential injection via external vaults and the distribution of reusable image templates across cluster nodes to reduce startup latency.

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Features

  • Hardware-Isolated Execution Environments - Runs untrusted code in dedicated environments with separate kernels to prevent host system compromise.
  • AI Execution Sandboxes - Provides secure and lightweight isolated environments specifically designed for AI agents to run untrusted code.
  • Sandbox Environment Snapshots - Captures runtime memory and disk state of isolated environments for instant cloning or rollbacks.
  • Code Execution Sandboxes - Provides a secure environment for running untrusted code using hardware isolation and dedicated guest kernels.
  • Snapshot Capture and Restoration Managers - Captures and clones the runtime memory and disk state of containers to enable instant environment recovery.
  • Egress Traffic Firewalls - Restricts outbound communication from sandboxes using domain allowlists and audit logging.
  • Isolated Execution Sandboxes - Provides secure, resource-constrained sandboxes for the safe execution of untrusted code.
  • Hardware-Isolated Environments - Provides hardware-isolated environments with dedicated guest kernels to run untrusted AI agent code safely.
  • Sandbox Network Security Controls - Filters outbound traffic using domain allowlists and generates audit logs to prevent unauthorized communication.
  • Domain Filtering - Implements outbound traffic filtering based on domain name patterns to prevent unauthorized connections.
  • Isolated Code Execution - Runs arbitrary code in hardware-isolated environments with dedicated guest kernels to prevent unauthorized system access.
  • AI Sandbox Platforms - Deploys isolated, lightweight execution environments for AI agents based on Kubernetes container orchestration.
  • Network Traffic Filtering - Restricts outbound communication for isolated environments using domain allowlists and audit logs.
  • Sandbox State Management Systems - Captures and restores the state of isolated environments via snapshots to enable instant cloning.
  • Sandbox Templates - Converts container images into reusable templates for rapid deployment across cluster nodes.
  • Cluster Orchestration Dashboards - Provides a centralized administrative interface for monitoring node health and managing containerized templates.
  • Container Image Templates - Creates and distributes reusable container image templates across cluster nodes to accelerate sandbox deployment.
  • Image Distributions Across Members - Replicates container images across cluster nodes to reduce environment startup latency.
  • Kubernetes Dashboards - Provides a web-based administrative console for monitoring node health and managing container templates.
  • Runtime Credential Injection - Retrieves sensitive keys from a secure external vault and injects them into requests during runtime.
  • Automated Cluster Health Monitors - Provides a browser-based administrative console to monitor node health and manage templates.
  • Security and Sandboxing - Secure and lightweight sandbox for AI agents.
6,519 stars·532 forks·Rust·11 views

Star history

Star history chart for tencentcloud/cubesandboxStar history chart for tencentcloud/cubesandbox

Frequently asked questions

What does tencentcloud/cubesandbox do?

CubeSandbox is a Kubernetes-based platform for executing AI agents in secure, lightweight environments. It provides a code execution sandbox that uses hardware isolation and dedicated guest kernels to run untrusted code without risking the host system.

What are the main features of tencentcloud/cubesandbox?

The main features of tencentcloud/cubesandbox are: Hardware-Isolated Execution Environments, AI Execution Sandboxes, Sandbox Environment Snapshots, Code Execution Sandboxes, Snapshot Capture and Restoration Managers, Egress Traffic Firewalls, Isolated Execution Sandboxes, Hardware-Isolated Environments.

What are some open-source alternatives to tencentcloud/cubesandbox?

Open-source alternatives to tencentcloud/cubesandbox include: e2b-dev/e2b — E2B is a cloud-based infrastructure platform designed to provide secure, isolated execution environments for code and… alibaba/opensandbox — OpenSandbox is a secure sandbox runtime and containerized code execution engine designed to run AI-generated code and… daytonaio/daytona — Daytona is a cloud-native development environment platform designed to orchestrate ephemeral, containerized… zerocore-ai/microsandbox — microsandbox is a platform that runs untrusted code inside hardware-isolated microVMs, each with its own kernel,… cloudflare/moltworker — Moltworker is an AI agent sandbox and model orchestrator designed for the secure execution of untrusted code and shell… opensquilla/opensquilla — OpenSquilla is an LLM agent orchestration framework designed to coordinate multi-step AI workflows and tool execution…

Open-source alternatives to CubeSandbox

Similar open-source projects, ranked by how many features they share with CubeSandbox.
  • e2b-dev/e2be2b-dev avatar

    e2b-dev/E2B

    10,950View on GitHub↗

    E2B is a cloud-based infrastructure platform designed to provide secure, isolated execution environments for code and shell commands. It functions as an ephemeral orchestrator that provisions lightweight virtual machines, allowing developers and autonomous agents to run untrusted processes within a sandbox that is completely separated from the host system. The platform distinguishes itself through its focus on programmable, serverless workspaces that support the full lifecycle of cloud-based development. By utilizing hardware-level isolation and snapshot-based resumption, it enables the near-

    MDXagentaiai-agent
    View on GitHub↗10,950
  • alibaba/opensandboxalibaba avatar

    alibaba/OpenSandbox

    11,682View on GitHub↗

    OpenSandbox is a secure sandbox runtime and containerized code execution engine designed to run AI-generated code and scripts in isolated environments. It serves as a workload orchestrator that prevents host system contamination by utilizing kernel-level isolation to execute arbitrary commands and scripts. The project distinguishes itself by providing a model context server that bridges large language models to the sandbox for performing file operations and system commands. It also includes a remote GUI sandbox that supports browser automation and desktop interfaces via remote access protocol

    Python
    View on GitHub↗11,682
  • daytonaio/daytonadaytonaio avatar

    daytonaio/daytona

    72,416View on GitHub↗

    Daytona is a cloud-native development environment platform designed to orchestrate ephemeral, containerized workspaces. It provides a centralized system for managing reproducible coding environments as code, ensuring consistency across distributed teams by abstracting the underlying infrastructure. By utilizing declarative configuration, the platform automates the entire lifecycle of development sandboxes, from initial provisioning to resource governance. The platform distinguishes itself through its infrastructure-agnostic runner layer, which allows development environments to be deployed ac

    TypeScriptagentic-workflowaiai-agents
    View on GitHub↗72,416
  • cloudflare/moltworkercloudflare avatar

    cloudflare/moltworker

    9,909View on GitHub↗

    Moltworker is an AI agent sandbox and model orchestrator designed for the secure execution of untrusted code and shell commands generated by large language models. It functions as a gateway proxy that routes requests to multiple AI providers through a unified interface, integrating a container runtime backed by S3-compatible object storage to persist state across ephemeral lifecycles. The system distinguishes itself by combining an AI model orchestrator with a headless browser controller for automated web scraping and screenshot capture. It manages the full lifecycle of AI agents, including m

    TypeScriptai-agentscloudflare-workers
    View on GitHub↗9,909
  • See all 30 alternatives to CubeSandbox→