Stable cut of the 1.1.1 patch line: fixes the broken 1.1.0 server wheel — hatchling's VCS-exclude filtering silently dropped the committed FastPath gRPC stubs from the PyPI package, so every 1.1.0 install of opensandbox-server failed at import time; PyPI is immutable, so the fix ships on this line (#1959). SDK/CLI/server packages publish at 1.1.1 (1.1.1-rc.1 shipped images only). Everyone on 1.1.0 should upgrade. Baseline for every section below: release-1.1.0.
Highlights
- Fixes the
1.1.0server wheel: FastPath stubs now ship in the package and installs import cleanly; SDK/CLI/server packages publish at1.1.1(#1959) - Identity-bound filesystem operations: execd executes file APIs as an explicit Linux UID/GID, with
FilesWithIdentity/files_with_identityin all five SDKs; isolated sessions gain multiple independent overlay mounts (#2070 #2093 #2094 #2095 #2096 #2097 #2032) - Server hardening: snapshot creation submits the runtime object before persisting so early reads can't map to
Failed, proxied backend failures map to 502/504 instead of a generic 500, and diagnostics work for pooled sandboxes (#2098 #2077 #2084 #2104)
Server
- Implement pause/resume for the agent-sandbox provider by bridging to
spec.operatingMode(Running/Suspended) onagents.x-k8s.io/v1beta1, with state derivation (Paused/Pausing/Resuming/Terminated) and 409 on invalid transitions; both endpoints previously returned "not supported" (#1975) - Isolate tenants that share one Kubernetes namespace: creates stamp
opensandbox.io/tenant, and list/get/delete/pause/resume/proxy hide other tenants' labeled sandboxes as 404 while unlabeled legacy sandboxes stay visible until expiry; also addskubernetes.insecure_skip_tls_verifyfor ServiceAccount CA mismatches (#1973) - Heal the silent renew-intent drop after a server restart in multi-tenant mode: the resolver now falls back to a cluster-wide label lookup with a 403 circuit breaker and structured warnings, trusts an ingress-observed namespace from the intent payload when verifiable, and single-tenant deployments never resolve beyond the configured namespace (#1819)
- Add
[docker] publish_hostto publish bridge-mode sandbox ports on one host address (default0.0.0.0unchanged) — with127.0.0.1or the Docker bridge gateway, the tokenless execd port no longer lands on public interfaces (#1954) - Add a typed, admin-only
[egress.upstream_proxy]config section (URL + optional authorization, validated at load) that injects the sidecar's chained upstream CONNECT proxy on both Docker and Kubernetes, with fail-closed 400s when the requestednetworkPolicyis incompatible; secret values are no longer echoed in config-validation errors (#1999), plusca_cert_path(Docker) andca_secret_name(Kubernetes) sohttps://proxies signed by a private CA are trusted without replacing the system trust store — the PEM augments/etc/ssl/certsin the sidecar (#2030) - Make snapshot creation race-free for early readers on k8s/fsb:
POST /sandboxes/{id}/snapshotsnow creates the runtime object (SandboxSnapshot CR / fsb submit) before persisting theCreatingrow and returns without queueing a worker, so read-time sync can no longer map a not-yet-created object toFailed— including on other HA replicas; recovery resubmits stuck rows inline (#2098), fixing the window where a client polling right after create flipped the row to a permanentFailed(#2077) - Map proxied backend failures to meaningful statuses: read/write timeouts return 504
BACKEND_TIMEOUT, mid-response resets and protocol errors return 502BACKEND_RESPONSE_FAILED, keeping 502BACKEND_CONNECTION_FAILEDfor connect failures — a sandbox that dies mid-request no longer looks like a server bug (#2084) - Find pool-allocated pods for k8s diagnostics: pooled BatchSandboxes don't carry the
opensandbox.io/idpod label, so every logs/events/inspect call returned 404; the lookup now falls back to the pods listed in the workload'salloc-statusannotation (#2104) - Remove auto-created Docker volumes when create fails before the provisioning block runs (image pull, credential/upstream-proxy checks, Windows prerequisites, OSSFS prep) — a mistyped image name no longer leaks the PVC it triggered (#2103)
- Report deleting pooled/task-mode BatchSandboxes as
Stopping/DELETING:metadata.deletionTimestampnow wins over runtime status publication, so a sandbox whose pods go not-ready during finalization no longer flips back toPending/CREATING(#2122) - Stop Docker metadata PATCHes from resurrecting deleted keys:
patch()now starts from the override file (asget()does) instead of re-merging container labels, so{"env": null}stays deleted and an emptied override file doesn't restore the original labels (#2065) - Accept
envon template create and bake it into the fast-sandbox golden image (/etc/sandbox-init.env, inheriting the source image's OCIConfig.Env), closing the gap whereSandboxTemplate.spec.envsexisted but the lifecycle API rejected it; supported across all SDKs (#1984) - Wake Kubernetes creation waits on informer watch events instead of fixed 1-second polling, cutting prewarmed-pool create latency from ~1 s to tens of milliseconds while keeping the polling fallback (#1996)
- Ship the committed FastPath gRPC stubs in the server wheel by force-including them past hatchling's VCS excludes, and smoke-import the built wheel in the release workflow before publishing — this is the
1.1.0install-time breakage fix (#1959) - Fix the Fast Sandbox snapshot CR plural (
sandboxsnapshots) in Helm RBAC and the fsb snapshot runtime, wheresandboxesnapshotscould fail list/watch with missing RBAC (#1972) - Propagate the underlying FastPath error message through the 429 capacity mapping (keeping status and
Retry-After, adding acausefield) so admission/runtime failures like a broken KVM device are no longer masked as pool exhaustion, and warn-log the raw error before mapping (#2001) - Clarify the renewal contract:
renew-expirationmay shorten, preserve, or extend expiration (any future target is valid) andmax_sandbox_timeout_secondscaps only creation, not renewal or total lifetime — documentation and SDK references aligned, with regression coverage across Docker, Kubernetes, and FastSandbox (#2087) - Fix Docker edges: reject a repeated pause of an already-paused sandbox with the documented 409 instead of surfacing Docker's "already paused" as 500 (#2023), and clear Docker masked/read-only system paths only for sandboxes that opt into the isolation extension so nested Bubblewrap can mount a private procfs (#1982)
SDKs
- Add identity-bound filesystem operations end to end: execd gains additive
/v1/filesystem/{uid}/{gid}routes backed by a per-request worker process running with explicit credentials and account-derived supplementary groups (fail-closed, existing routes unchanged), and every sandbox SDK exposes it — Pythonfiles_with_identity, JavaScriptfilesWithIdentity, KotlinfilesWithIdentity, C#FilesWithIdentity, GoFilesWithIdentity— so Linux checks the selected user's permissions during actual access; identity selection belongs in the trusted backend, this enforces filesystem permissions and is not a tenant boundary (#2070 #2093 #2094 #2095 #2096 #2097) - Expose multiple independent overlay mounts per isolated session across the API and all five SDKs:
CreateIsolatedSessionRequest.overlays({path, mode, persist}) with separate host-tracked or ephemeral tmpfs uppers,workspacekept as sugar, andSessionStateechoing the canonical list — completing the internal foundation from #2021 (#2032) - Add
commands.setEnvfor persistent runtime env injection in all five sandbox SDKs (Python async/sync, JavaScript, Kotlin/Java, Go, C#): appendsKEY=VALUEto the sandbox env file with runtime-exact serialization, local key/NUL validation, and a loud failure whenEXECD_ENVSis unset (#2013) - Systematic cross-language audit cleanup across sandbox, code-interpreter, and MCP SDKs: Go retry backoff collapsing to zero delay and dropped session
cwd, Python isolated-session ignoringencodingand readiness budgets reporting stale errors, JS resume sharing and killing the source sandbox's transport, Kotlin codes runs dropping every SSE-framed event and never settingexitCode, C# create failing on fresh-sandbox 404 and NREs on empty bodies, and MCP per-call closes tearing down the server-wide shared transport — each fixed with regression tests (#2020) - Support
envon template create across all five SDKs, matching the server-side golden-image baking (#1984) - Align background command stream completion across languages: with execd's fixed completion delay removed, background result collection in Go, Kotlin, and C# now returns on startup acknowledgement like Python and JavaScript instead of waiting for EOF and inferring exit code 0 — query command status for the eventual outcome; foreground calls still read to EOF for older servers (#1825)
Python
- Raise on error responses from
create_sessionanddelete_session: both passed the parsed model to the error handler (which needs the raw status), so 400/404/500 returnedNoneas success and unknown statuses raised with a bogusstatus_code=200— the CLI could print "Deleted session" for a session that never existed (#2066) - Expose
follow_redirectsonConnectionConfig/ConnectionConfigSync, propagated to all handwritten async/sync httpx clients including SSE clients and generated-client wrappers (#1123) - Keep the last real endpoint error when the readiness deadline expires mid-request: the budget no longer records its own
SandboxReadyTimeoutExceptionaslast_error, so causes likeKUBERNETES::POD_IP_NOT_AVAILABLEaren't masked as a plain timeout (#2121) - Authenticate Code Interpreter requests in server-proxy mode: context creation and streamed execution now attach the API key like sandbox file requests, fixing 401s from the same proxy (#2125)
- Serialize
SandboxPoolSync.shutdown()teardown: concurrent shutdown (or shutdown racingstart()) could close the warmup event loop twice; teardown is now idempotent under a dedicated lock (#2041) - Orphan the shared warmup event loop instead of closing it over an in-flight warmup: when the bounded drain wait ends with warmups still running, shutdown leaves the loop alive so the in-flight warmup finishes and cleans up its sandbox, instead of destroying the pending task and skipping cleanup (#2142)
- MCP: map expected OpenSandbox validations to MCP 2.x
ToolErrorso clients get the actionable message instead of a generic "Error executing tool" (#2108)
JavaScript
- Treat empty-body non-2xx responses as errors: openapi-fetch sets no
errorforContent-Length: 0/204/HEAD responses, so an empty 404/502/503 from a gateway madedeleteSandbox,pauseSandbox, and file deletes look successful in both the sandbox and code-interpreter packages (#2101)
Kotlin
- Identity-bound filesystem operations via
sandbox.filesWithIdentity(uid, gid)— see the cross-SDK entry above (#2095)
C#
- Identity-bound filesystem operations via
sandbox.FilesWithIdentity(uid, gid)— see the cross-SDK entry above (#2096)
Go
- Identity-bound filesystem operations via
sandbox.FilesWithIdentity(uid, gid)— see the cross-SDK entry above (#2097) - Document previously uncovered surfaces: file operations, volume mounts (
host/pvc/ossfs), the full template workflow,WaitUntilReadywith custom health checks, andSandboxManager(#2024)
Controller
- Add OpenTelemetry allocator-path metrics on the
opensandbox/controllermeter: pool-allocation schedule, alloc-state persist, and alloc-result sync duration histograms with namespace/pool/success attributes, exported over OTLP (#2014) - Prepare the pool-assign surface for custom extension: the
Predicateinterface and predicate methods underpoolassignare now exported — the package remains underkubernetes/internal/, so external Go modules cannot import it yet (#2037) - Auto-replace BatchSandbox pods stuck in provisioning failures during initial startup: never-Ready pods waiting in
ImagePullBackOff/ErrImagePullare deleted after a threshold so the scheduler can escape a broken node (a full disk had left one production fleet with 114 stuck sandboxes), with a per-sandbox, per-generation replacement budget and aPodRecoveryLimitReachedwarning; permanently broken images are skipped (#1961) - Support custom snapshot image URI templates:
--snapshot-image-uri-template/controller.snapshot.imageURITemplatename rootfs and QEMU VM-state targets with snapshot/sandbox/container/namespace metadata anddate/dateInZonehelpers, validated (invalid refs, duplicate targets) before Job creation; empty keeps existing naming (#2004) - Fix the free-pod predicate admitting pods on a non-empty IP alone: the task scheduler bound tasks to pods Kubernetes marked
NotReady(still starting or restarting), the assignment POST failed with no retry, and a healthy sibling was skipped; readiness is now required like every other predicate (#2138) - Keep the last-known task status when a status query fails during release: a single timed-out
/getTasksno longer marks areleasingtask as gone, which skippedSet(nil), skipped the postStop hook, and let the controller drop the cleanup finalizer or return the pod to the pool while the task still ran (#2067) - Skip pause dispatch for an already-
PausedBatchSandbox: renewing a paused sandbox bumped its generation and re-triggeredhandlePause, which needs a running source pod and drove the sandbox toFailed/PauseFailed(#2082) - Fix an image-committer deadlock where pausing the QEMU container via cgroup v2 freeze never completes (KVM worker kernel threads never reach
frozen), by skipping the redundant freeze for the QEMU container already paused over QMP and committing with--pause=false(#1986)
Execd
- Execute ordinary filesystem operations under an explicit Linux identity: additive
/v1/filesystem/{uid}/{gid}routes spawn a per-request worker process with the selected uid/gid and account-derived supplementary groups, fail-closed on unsupported platforms; existing routes keep their current identity — the SDK-facing follow-ups ship in the same release (#2070) - Expose the public isolated-session overlays API (validation, canonical merge with legacy
workspace, per-overlay allocator assignment) — details and SDK support under SDKs (#2032) - Give overlay sessions a durable cleanup identity outside their removable subtree (
<upper_root>/.execd-cleanup/<session-id>): startup recovery removes only exact matching directories, and partial deletion or lost records are retried within the process or across restarts instead of orphaning upper dirs (#2107) - Let children of a finished background command keep running: the post-
Waitcontext cancel no longer SIGKILLs the whole process group, so a backgroundednohup ./server &survives its script — cancellation and timeouts still kill the group (#2074) - Kill the whole process group when a bash session run times out: only bash itself was killed, so
(sleep 2; …)children kept the run hanging past its deadline (#2079) - Preserve
\n/\rbytes in foreground/commandstdout/stderr event text, so concatenated events reconstruct the command's line endings including blank lines and a trailing unterminated fragment; the Python SDK's display-orientedExecution.textand stderr summary no longer insert extra blank lines when CRLF arrives across events, while rawlogs.stdout/logs.stderrkeep their original text (#2033) - Remove the per-run bash session script file (
execd_bash_*.sh), which retained a copy of every session environment variable — secrets included — readable by any later command as the same user (#2076) - Clamp the HTTP
Rangeend before computing length:bytes=0-9223372036854775807overflowed into a negative length and answered 206 with a brokenContent-Range/Content-Lengthand no body, on both regular and isolated-session downloads (#2089) - Remove the fixed one-second delay after command completion, cutting median terminal-event-to-return latency from ~1000 ms to sub-millisecond while retaining output flushing and heartbeat cleanup (#1825)
- Stop logging every stdout/stderr chunk at info level, which accounted for 99.8% of execd log volume on output-heavy workloads (#1906)
Networking
egress
- Continue the credential-bound TLS interception foundation (OSEP-0023) [EXPERIMENTAL] across the line: generation-pinned live revision-session callbacks held under the mitmproxy lifecycle lock (#2036), credential-free ClientHello classification of ECH/SNI/static pass-through with
needs_registryadmission requests (#2046), a bounded connection-admission registry that denies on exhaustion instead of downgrading to opaque pass-through (#2062) and flags admissions uncovered by selector cutovers (#2072), request admission pinned to one immutable snapshot with no old-credential fallback and permanent fences for removed hosts (#2088), bounded request-handle lifecycles with a global budget and paginated inspection (#2091), monotonic retirement deadlines for uncovered connections (#2100), joint Receiver/TLS-Registry publication with prepare/commit/abort retry semantics (#2106) wired into the authenticated revision IPC via an internal InstallationReceiver (#2120), revision-backed Vault mutation transactions with exact-attempt reconciliation and readiness fencing (#2124), frozen effective-policy revision candidates revalidating every binding including HTTP-only ones (#2139), guarded revision recovery and readiness publication with exact bootstrap identity and quarantined uncertain outcomes (#2151), and cross-language IPC recovery coverage against the production endpoint (#2136) — groundwork only; public Vault writes still 503 under the gate and selective TLS stays disabled - Extend the chained upstream CONNECT proxy: trust
https://proxies signed by a private CA via an append-styleOPENSANDBOX_EGRESS_MITMPROXY_UPSTREAM_EXTRA_CAbundle that augments the system trust store for all upstream TLS verification, configured from the server'sca_cert_path/ca_secret_name(#2030); support the chained proxy under the fast-sandbox profile with profile-wide endpoint drops so sandbox workloads cannot reach the upstream proxy directly, infrastructure DNS seeding resolved concurrently through dnsproxy upstreams and the Pod resolver, and atomic nft table seeding with drop elements permanent across daemon downtime (#2003) - Add an opt-in chained upstream CONNECT proxy to the transparent mitmproxy path (
OPENSANDBOX_EGRESS_UPSTREAM_PROXY/_AUTH), routing sandbox egress through corporate forward proxies with SNI/Host-consistent CONNECT authority, fail-closed startup validation, and no behavior change when unset (#1816) - Roll back the persisted policy file when an nft apply fails, so a restart never loads a policy the caller was told had failed — potentially looser than the one actually running (#2075)
- Tolerate nested percent-encoded slashes in the credential proxy path guard: the single-layer
%2frelaxation now applies at any decode depth, sopipdownloads from internal PyPI proxies no longer fail with 403request path contains ambiguous segmentswhile Credential Vault is active; dot-segments, backslashes at every depth, and non-converging decodes are still rejected (#2153) - Continue the earlier credential-bound groundwork: bootstrap authenticated revision sessions on sidecar launch and restart behind an internal gate (#1948), stage unpublished Credential Vault mutation candidates with acknowledge-before-publish commit semantics (#1980), serialize
/policyand Vault writes behind a shared mutation barrier (#1991), stage always-rule reloads before publishing (#1997), retain exact attempt identity across indeterminate coordinator outcomes (#2007), and add post-bootstrap revision updates with exact-attempt reconciliation (#2017)
ingress
- Fail at chart render time when
providerType=fast-sandboxis set without a secure-access key ring: the gateway previously passedhelm templateand then CrashLoopBackOff'd onFastPath routing requires --secure-access-keys; the deployment guide now also documents the gateway as required on Kubernetes (sandbox Pods are ClusterIP-only) and installed before the server (#2047) - Support per-request opt-out of access renew intents via an
OpenSandbox-Access-Renew: skipheader, suppressed before throttle state is touched and stripped on both the gateway and the server proxy paths — for health probes and other heartbeat-style traffic (#1966)
Fast Sandbox
- Bump the pinned fast-sandbox source twice more:
83139ccmakes the Firecracker runtime require XFS with reflink at startup (#2123);b702fbepreserves the guest gateway MAC across snapshot restores with a committed-cache recheck before delivery retry and ARP-cache regression coverage, and the vendored CRD bundle drops theboxliteruntime enum that upstream removed (#2145); the earlier2b5e840pin drops the node-side guest kernel asset (kernelPathbecomes optional), adds snapshot CPU-template compatibility admission, and rebinds jailed/dev/kvmto host device numbers before restore (#2028), with the intermediatefb87a53bumping the builder's default guest kernel to 6.18.36 (#1992) andf45bc60dropping CRD CEL validations for older API servers, making P2P optional, and letting template guests inherit the source image's OCI env (#1989) - Create the shared system namespace in the
basechart (fastSandbox.namespaces.createSystem, defaulttrue,helm.sh/resource-policy: keep): the fast-sandbox control-plane ServiceAccounts previously assumed the namespace was bootstrapped later, breaking the documented base-first install order and every rendered-manifest/GitOps flow (#2044) - Chart: add controller tolerations, a
sandboxtemplateBuilderPodSpecPodSpec-fragment ConfigMap merged into golden-image build pods, afastletProxyImageoverride so the injected sidecar no longer has to come from docker.io, and agent/janitor runtime resources for tainted or registry-restricted clusters (#1968) - Replace MinIO with RustFS in the integration environment (#2009)
Misc
- CLI: add template and snapshot management (
osb template create|get|list|delete,osb snapshot ..., plus--template/--snapshot-idonsandbox create) (#2002), kubectl-style-f/--filerequest files forsandbox createandtemplate createcovering the full wire format with strict unknown-field rejection (#2019), fixsandbox metrics --watchfailing on execd's raw SSE field names (#1970), exit non-zero when a foreground command's SSE stream ends without a completion or error event instead of reporting success (#2099), and reject failed or unconfirmed background starts before printing success metadata (#2109), and editosb config setvalues through a real TOML parser instead of string concatenation, preserving comments and layout with correct escaping so quoted or multiline values no longer corrupt the config (#2146) - Charts: correct chart metadata, unify image tag defaults on
release-<appVersion>fallbacks, makeimagePullPolicyconfigurable, keep the dataplane Namespace onhelm.sh/resource-policy: keep, and rewrite the deployment guide around the umbrella release flow with an explicit install order (#2006) - Docs: publish fast-sandbox performance pages with measured create/snapshot/restore figures (#1951 #1992) and refresh the README performance claims with ACK measurements (#2086 #2115), add an ACK deployment guide and an upstream-proxy operations guide (#2048 #2045), restructure the server, operator, execd, and node-agent architecture pages around verified design decisions with redrawn diagrams (#2058 #2064 #2069 #2137), add an interactive fast-sandbox integration architecture diagram (#2034 #2127), document execd implementation-compatibility boundaries (#2050), multi-runtime Kubernetes deployments (#1684), rclone volume mounts (#2071), snapshot durability after abnormal termination (#2111), sandbox expiration semantics (#2087), and
apply_patchin sandboxes (#2110), add GitHub Copilot CLI, DeerFlow, and scheduled pool-resize examples (#2053 #2011 #2141), sharpen the README intro (#1960), repair links broken by the docs restructure (#1957), mark OSEP-0016 as implemented (#1955), remove the unmaintained NullClaw example (#2016), pin the Compose example to a release image with the proxy fixes (#2073), and refresh the roadmap (#2135) - Security/dependency bumps: fast-uri, undici, and containerd CVEs (#2057), PyJWT (critical), oauthlib, brace-expansion, and fast-uri (#2102), and urllib3, source-map-js, and vue (#2117)
- node-agent/CI: add a nightly full-stack log-collection e2e on Kind proving real sandbox stdout reaches the file sink and finalizes on deletion (#2143), narrow the fast-sandbox integration trigger scope (#2054), and harden the integration scripts' error handling so subshell failures can't tear down the shared environment (#2068)
- Fast-sandbox tooling: add a self-hosted KVM integration-test workflow (#1978 #1985), a helper that provisions preallocated reflink-XFS state disks for Firecracker (#1995), a realistic golden-image test workload (#1983), and a reproducible Kubernetes rootfs resume benchmark (#2113)
- Tests and housekeeping: cover upstream-proxy compatibility against real mitmdump with Vault/proxy credential isolation (#2043) and Authorization on streamed uploads (#1940); harden the Python pool-lifecycle stress tests (#2026 #2144) and fix task-manager test races (#2060 #2061); make the PauseResume e2e status tamper work on pre-1.24 kubectl (#2085); sweep low-value and duplicate tests across the Go and Python suites with no production changes (#2126); apply a zero-behavior-change node-agent cleanup (#2140) and remove dead CLI code (#2018); drop the unused
.pre-commit-config.yaml(#2049); fix a dead docs link (#2118) and a test license-header owner (#1976); and prepare and pin the1.1.1-rc.1pre-release (#2035 #2042) - release: bump platform version to
1.1.1across charts and image references
Upgrade & Compatibility
- The
1.1.0server package on PyPI is broken at import time and cannot be replaced (PyPI is immutable) — upgrade to this line; see #1959 - Behavior change: the HTTP proxy maps backend read/write timeouts to 504 and mid-response failures to 502 with typed error codes instead of a generic 500; SDK default retry configs differ for the new 504 — the Go SDK's
DefaultRetryConfigretries 504 like 502/503, while Python's default retries 502/503 only (#2084) - Behavior change: children left behind by a finished background command keep running after it exits, matching the foreground path; cancellation and timeouts still kill the group (#2074)
- Behavior change: snapshot creation on k8s/fsb submits the runtime object before persisting and recovery resubmits inline; polling clients no longer observe a spurious permanent
Failed(#2098) - Behavior change: background command result collection in Go, Kotlin, and C# returns on startup acknowledgement and no longer infers exit code 0 — query command status for the eventual outcome (#1825)
- Behavior change: in multi-tenant mode, another tenant's labeled sandboxes in a shared namespace now resolve as 404; unlabeled legacy sandboxes stay visible until expiry (#1973)
- Chart: the
basechart now creates the sharedfastSandbox.namespaces.systemnamespace by default — setfastSandbox.namespaces.createSystem=falseif you manage it externally (#2044); the ingress gateway is required on Kubernetes deployments and must be installed before the server, and fast-sandbox mode requires a secure-access key ring at render time (#2047 #2048) - Fast-sandbox operators: restores never boot a kernel and direct boot requires an explicit operator
kernelPathpin (#2028); the Firecracker runtime now requires XFS with reflink at startup — use the provided reflink-XFS state-disk helper on nodes that lack it (#2123); the vendored CRD drops the removedboxliteruntime enum (#2145); the integration environment readsRUSTFS_*/RC_IMAGEinstead ofMINIO_*/MC_IMAGEwith no legacy alias (#2009) - Images:
opensandbox/<component>:release-1.1.1(all three registries) - Packages: server / CLI / SDKs all at
1.1.1 - Charts: render from this tag (
helm template ./manifests/charts/opensandbox) - Kubernetes: supported range v1.21 – v1.34 (charts declare
kubeVersion: ">=1.21.1-0") - Skew: server ↔ CLI/SDK same line supported; ±1 minor warns
👥 Contributors
Thanks to these contributors ❤️
- @Coder-Sang
- @GodBlf
- @Gujiassh
- @Harbor404
- @Pangjiping
- @Spground
- @SuperSgdk
- @TuGou-a
- @YxinMiracle
- @acodercat
- @alahaiyo
- @comqx
- @cwj2001
- @dcaminos
- @drakeo338
- @gau1991
- @hittyt
- @hpliStartAgain
- @JasonBuildAI
- @jianpingpei
- @jiawen7777
- @jwx0925
- @ju123123
- @kinfey
- @kittimzhe
- @lorenzozanee
- @lux-liang
- @mengdehong
- @MincongZhou
- @mpu
- @ninan-nn
- @riversiderig-serves
- @ruirui6946
- @skyser2003
- @y4ney
Artifacts
- BOM: docs/releases/1.1.1.yaml
- Images:
opensandbox/<component>:release-1.1.1(Docker Hub / GHCR / ACR) - Packages: PyPI ×5, npm ×2, Maven Central ×5, NuGet ×2 — all at
1.1.1 - Go module:
github.com/alibaba/OpenSandbox/sdks/sandbox/go@v1.1.1
Installation
# Platform (Kubernetes) — render the chart at this tag and apply
git clone https://github.com/opensandbox-group/OpenSandbox
cd OpenSandbox
git checkout release-1.1.1
helm dependency build manifests/charts/opensandbox # package file:// sub-charts (not committed)
# Before first install, configure the server API key and enable the ingress
# gateway (required on Kubernetes; the bare render disables it, and the server
# refuses to start with an empty api_key) — see the deployment guide:
# https://open-sandbox.ai/deployment/
helm template ./manifests/charts/opensandbox | kubectl apply -f -
# or point your GitOps platform (Argo / Flux) at the repo path + tag
# SDKs
pip install opensandbox==1.1.1 # Python
npm install @alibaba-group/opensandbox@1.1.1 # JavaScript
# Kotlin/JVM: implementation("com.alibaba.opensandbox:sandbox:1.1.1")
dotnet add package Alibaba.OpenSandbox --version 1.1.1
go get github.com/alibaba/OpenSandbox/sdks/sandbox/go@v1.1.1
# Run the server locally
uvx opensandbox-server==1.1.1Verify what you installed against the BOM: see
Release Verification.