awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectAboutHow we rankPressMCP server
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
zerocore-ai avatar

zerocore-ai/microsandbox

0
View on GitHub↗
4,802 stars·221 forks·Rust·apache-2.0·6 viewsdocs.microsandbox.dev↗

Microsandbox

microsandbox is a platform that runs untrusted code inside hardware-isolated microVMs, each with its own kernel, filesystem, and network stack. It boots directly from standard OCI container images, supports copy-on-write filesystem layers, and integrates with AI agents to execute tool calls and generated code in isolated environments with secret protection.

What sets microsandbox apart is its host-side network proxy that enforces firewall rules, intercepts DNS, inspects TLS traffic, and injects secrets at the network boundary without exposing them inside the VM. It provides SSH access to microVMs without requiring an SSH daemon inside the guest, and can capture, export, and boot from filesystem snapshots for state preservation and replication. The platform also surfaces typed error objects across SDKs for precise failure matching.

Beyond core isolation, microsandbox includes full sandbox lifecycle management — creation, graceful shutdown, force termination, replacement, and state deletion — along with configurable storage attachments, interactive terminal sessions, command execution with streaming output, and metric export via OpenTelemetry to backends like Datadog and Prometheus.

The engine deploys as a Docker container from multi-arch images and is configured through a JSON settings file.

Features

  • Code Execution Sandboxes - Boots microVMs from OCI images and runs commands with instant startup in isolated environments.
  • MicroVM Sandboxes - Isolates each workload in a dedicated virtual machine with its own kernel, filesystem, and network stack.
  • AI Agent Tooling - The sandbox platform executes AI agent tool calls and generated code inside a dedicated microVM that controls filesystem, network, and secrets.
  • AI Agent Integrations - The sandbox platform integrates AI coding agents so they create and manage sandboxes via installed skills or an MCP server.
  • MicroVM Agent Sandboxes - An execution environment that integrates with AI agents to run tool calls and generated code inside isolated microVMs with secret protection.
  • Sandbox Environment Snapshots - Captures the writable filesystem of a stopped sandbox as a portable on-disk artifact.
  • Sandbox Configuration - Inspects full sandbox configuration and runtime state, outputting as formatted text or JSON.
  • Sandboxed Shell Executions - Runs commands inside active sandboxes with TTY, environment, workdir, timeouts, and resource limits.
  • Execution Sandboxes - Creates temporary sandboxes for single commands and removes them automatically after completion.
  • Sandbox Lifecycle Management - Terminates sandboxes gracefully with configurable timeout or force-kills immediately.
  • Snapshot Capture and Restoration Managers - An artifact manager that captures, exports, imports, and boots sandboxes from filesystem snapshots for state preservation and replication.
  • Host-Side Network Proxies - Routes all sandbox traffic through a host-side stack for firewall enforcement, TLS inspection, and secret injection.
  • Network Policy Enforcement - The sandbox platform controls sandbox network traffic through allow/deny rules with configurable defaults and first-match-wins evaluation.
  • Sandbox SSH Servers - The sandbox platform serves a sandbox over SSH protocol, enabling external clients to connect, transfer files, or tunnel TCP connections.
  • SSH Client Connections - Establishes SSH connections to microVMs for interactive shells and remote command execution.
  • OCI Image Root Filesystems - Boots each sandbox from a standard OCI container image pulled from any registry, using copy-on-write layers.
  • CBOR-Framed Relay Protocols - Communicates with an in-VM agent over a relay socket using raw CBOR messages with correlation IDs.
  • Host-Side Sandbox Proxies - A host-side firewall that controls network access, intercepts DNS, inspects TLS traffic, and injects secrets without exposing them to the sandbox.
  • Daemonless SSH Proxies - A microVM that exposes SSH protocol for commands, interactive shells, and file transfers without requiring an SSH daemon inside the guest.
  • Hardware-Level Isolation - Runs each untrusted workload inside a dedicated VM with its own kernel, filesystem, and network stack.
  • MicroVM Spawners - Spawns hardware-isolated VMs as child processes directly from application code without a daemon.
  • Network Boundary Secret Injections - Injecting secrets into sandboxes by swapping placeholders with real values only when traffic reaches allowed hosts, keeping secrets outside the VM.
  • MicroVM Attachments - The sandbox platform mounts a prebuilt disk image as a block device inside the sandbox for dedicated persistent storage.
  • Host Transfers - The sandbox platform transfers files in either direction between the host and a sandbox, including same-sandbox and cross-sandbox copies.
  • Host-Guest Channels - The sandbox platform reads from and writes to files inside a running sandbox using the dedicated host-guest channel.
  • MicroVM Volume Attachments - The sandbox platform attaches a named volume to a microVM so files written inside are retained across executions.
  • Multi-Backend Storage Mounts - The sandbox platform mounts host directories, named volumes, tmpfs, or disk images to specified paths inside a sandbox.
  • Named Volume Lifecycles - The sandbox platform creates, accesses, and deletes named storage volumes that persist independently of any sandbox run.
  • Real-Time Output Streaming - Streams command stdout and stderr as real-time events instead of buffering output.
  • SFTP Subsystems - The sandbox platform performs file operations such as reading, writing, creating directories, and managing symlinks over SFTP to a sandbox.
  • Docker-in-VM Launchers - Starts a Docker daemon inside a hardware-isolated VM for running Docker commands.
  • PTY Session Attachers - Attaches local terminals to processes inside sandboxes for fully interactive PTY sessions.
  • Sandbox - Sends a shutdown signal allowing pending writes to flush before terminating a sandbox.
  • Host-Guest Mounts - The sandbox platform attaches a host directory at a guest path so the sandbox can read and write files that persist on the host.
  • Service Port Forwarding - Forwards local TCP connections into sandbox networks using OpenSSH port forwarding.
  • Pre-Boot Filesystem Patchers - Modifies the root filesystem before boot to add, replace, or remove files without altering the base image.
  • Root Filesystem Source Selectors - Sets the sandbox's root filesystem from an OCI image, host bind mount, or pre-made disk image.
  • Virtual Disk Image Booting - Boots sandboxes directly from disk image files, giving the guest raw block device access.
  • Public Internet Only Outbound Policies - The sandbox platform restricts outbound network traffic from untrusted workloads to the public internet, blocking host or private networks.
  • Sandbox State Logs - Lists all sandboxes with current status and reads captured output from any sandbox.
  • Snapshot-Based Boots - Boots new sandboxes from saved filesystem snapshots, restoring state for reuse or replication across hosts.
  • SSH - Maps standard SSH sessions into the sandbox by proxying the protocol directly, no guest daemon required.
  • Sandbox Exclusion Lists - Lists running, stopped, and crashed sandboxes and retrieves handles to specific ones.
  • Authorized Key Injectors - Adds public keys to sandbox authorized_keys files for passwordless SSH authentication.
  • Sandbox - Captures the writable disk state of a stopped sandbox as a portable artifact for later reuse or transfer.
  • Init Systems - Launches systemd as PID 1 inside microVMs so services expecting a session bus work normally.
  • Metrics Export Health Monitors - The sandbox platform emits export success/failure counters and staleness timestamps from the sidecar into the telemetry pipeline.
  • Metric Tagging Utilities - The sandbox platform attaches resource fields, sandbox identity, and user-defined labels to every datapoint for backend filtering.
  • OTLP Collector Forwarding - The sandbox platform forwards sandbox metrics in OTLP format to an OpenTelemetry Collector for real-time debug inspection.
  • Datadog Exporters - The sandbox platform sends runtime metrics to Datadog via the OpenTelemetry Protocol over HTTP or gRPC.
  • OpenTelemetry Exporters - The sandbox platform continuously reads sandbox metrics and pushes them via OTLP to any OpenTelemetry-compatible backend.

Star history

Star history chart for zerocore-ai/microsandboxStar history chart for zerocore-ai/microsandbox

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Frequently asked questions

What does zerocore-ai/microsandbox do?

microsandbox is a platform that runs untrusted code inside hardware-isolated microVMs, each with its own kernel, filesystem, and network stack. It boots directly from standard OCI container images, supports copy-on-write filesystem layers, and integrates with AI agents to execute tool calls and generated code in isolated environments with secret protection.

What are the main features of zerocore-ai/microsandbox?

The main features of zerocore-ai/microsandbox are: Code Execution Sandboxes, MicroVM Sandboxes, AI Agent Tooling, AI Agent Integrations, MicroVM Agent Sandboxes, Sandbox Environment Snapshots, Sandbox Configuration, Sandboxed Shell Executions.

What are some open-source alternatives to zerocore-ai/microsandbox?

Open-source alternatives to zerocore-ai/microsandbox include: superradcompany/microsandbox — Microsandbox is a runtime for creating and managing lightweight, hardware-isolated virtual machines — called sandboxes… tencentcloud/cubesandbox — CubeSandbox is a Kubernetes-based platform for executing AI agents in secure, lightweight environments. It provides a… memodb-io/acontext — Acontext is an LLM orchestration backend and agent memory framework designed to manage session state and knowledge for… microsandbox/microsandbox — Microsandbox is a microVM sandbox runtime and hardware-isolated code executor designed for running untrusted code. It… e2b-dev/code-interpreter — This project is an infrastructure platform designed to provide secure, isolated, and ephemeral cloud-based Linux… ericlbuehler/mistral.rs — mistral.rs is an inference engine for large language models that runs locally and exposes models behind OpenAI and…

Open-source alternatives to Microsandbox

Similar open-source projects, ranked by how many features they share with Microsandbox.
  • superradcompany/microsandboxsuperradcompany avatar

    superradcompany/microsandbox

    6,570View on GitHub↗

    Microsandbox is a runtime for creating and managing lightweight, hardware-isolated virtual machines — called sandboxes — that boot directly from standard OCI container images. Each sandbox runs as its own host process with a separate kernel, filesystem, and network stack, providing process-per-sandbox isolation. The project includes a command-line tool and multi-language SDKs (Rust, TypeScript, Python, Go) for programmatic lifecycle control, and it communicates with sandbox agents over Unix sockets using a CBOR-encoded protocol. What distinguishes Microsandbox is its combination of host-manag

    Rust
    View on GitHub↗6,570
  • tencentcloud/cubesandboxTencentCloud avatar

    TencentCloud/CubeSandbox

    6,519View on GitHub↗

    CubeSandbox is a Kubernetes-based platform for executing AI agents in secure, lightweight environments. It provides a code execution sandbox that uses hardware isolation and dedicated guest kernels to run untrusted code without risking the host system. The project features a network egress firewall that restricts outbound communication via domain allowlists and audit logging. It also includes a container snapshotting manager capable of capturing the runtime memory and disk state of environments to enable instant cloning and recovery. The platform covers cluster orchestration through a web-ba

    Rust
    View on GitHub↗6,519
  • memodb-io/acontextmemodb-io avatar

    memodb-io/Acontext

    3,035View on GitHub↗

    Acontext is an LLM orchestration backend and agent memory framework designed to manage session state and knowledge for AI agents. It functions as a context manager and orchestration layer that integrates model providers with a secure code sandbox and a zero-knowledge data store. The project is distinguished by its approach to knowledge distillation, capturing agent learnings as reusable Markdown skills and structured memory files. It provides a secure execution environment where shell commands and scripts run in isolated containers with the ability to mount these persistent skill files direct

    TypeScriptagentagent-development-kitagent-observability
    View on GitHub↗3,035
  • e2b-dev/code-interpretere2b-dev avatar

    e2b-dev/code-interpreter

    2,348View on GitHub↗

    This project is an infrastructure platform designed to provide secure, isolated, and ephemeral cloud-based Linux environments for AI agents and automated code execution. It functions as an orchestrator that provisions on-demand virtual machines, allowing developers to run arbitrary code generated by large language models within hardware-level security boundaries. The platform distinguishes itself through its ability to manage stateful, long-lived sessions that persist across multiple execution calls, enabling complex, multi-step workflows. It supports high-concurrency scaling, allowing for th

    Pythonaiai-data-analysisanthropic
    View on GitHub↗2,348
  • See all 30 alternatives to Microsandbox→