github opensandbox-group/OpenSandbox release-1.1.1-rc.1
OpenSandbox 1.1.1-rc.1

pre-release3 hours ago

OpenSandbox 1.1.1-rc.1

First release candidate on the 1.1.1 patch line, cut to fix the broken 1.1.0 server wheel: hatchling's VCS-exclude filtering silently dropped the committed FastPath gRPC stubs from the PyPI package, so every 1.1.0 install of opensandbox-server failed at import time — PyPI is immutable, so the patched line is 1.1.1 (#1959). Beyond that fix, this rc carries everything merged since release-1.1.0: agent-sandbox pause/resume, shared-namespace tenant isolation, watch-driven create latency, commands.setEnv and a systematic audit cleanup across all five SDKs, upstream-proxy chaining for egress, and two fast-sandbox pin bumps. Baseline for every section is release-1.1.0. rc releases publish images but hold packages — SDK/CLI artifacts ship at the 1.1.1 stable bump. Please test and report issues.

Highlights

  • Fixes the 1.1.0 server wheel: FastPath stubs now ship in the package and installs import cleanly (#1959)
  • Server: pause/resume on the agent-sandbox provider, tenant isolation for sandboxes sharing a Kubernetes namespace, and pool creates woken by watch events instead of 1-second polling (#1975 #1973 #1996)
  • SDKs: commands.setEnv runtime env injection in all five languages, plus a systematic cross-language audit cleanup fixing dozens of correctness bugs (#2013 #2020)

Server

  • Implement pause/resume for the agent-sandbox provider by bridging to spec.operatingMode (Running/Suspended) on agents.x-k8s.io/v1beta1, with state derivation (Paused/Pausing/Resuming/Terminated), resourceVersion preconditions, and 409 on invalid transitions; both endpoints previously returned "not supported" (#1975)
  • Isolate tenants that share one Kubernetes namespace: creates stamp opensandbox.io/tenant, and list/get/delete/pause/resume/proxy hide other tenants' labeled sandboxes as 404 while unlabeled legacy sandboxes stay visible until expiry; also adds kubernetes.insecure_skip_tls_verify for ServiceAccount CA mismatches (#1973)
  • Heal the silent renew-intent drop after a server restart in multi-tenant mode: the resolver now falls back to a cluster-wide label lookup with a 403 circuit breaker and structured warnings, trusts an ingress-observed namespace from the intent payload when verifiable, and single-tenant deployments never resolve beyond the configured namespace (#1819)
  • Add [docker] publish_host to publish bridge-mode sandbox ports on one host address (default 0.0.0.0 unchanged) — with 127.0.0.1 or the Docker bridge gateway, the tokenless execd port no longer lands on public interfaces (#1954)
  • Add a typed, admin-only [egress.upstream_proxy] config section (URL + optional authorization, validated at load) that injects the sidecar's chained upstream CONNECT proxy on both Docker and Kubernetes, with fail-closed 400s when the requested networkPolicy is incompatible; secret values are no longer echoed in config-validation errors (#1999)
  • Accept env on template create and bake it into the fast-sandbox golden image (/etc/sandbox-init.env, inheriting the source image's OCI Config.Env), closing the gap where SandboxTemplate.spec.envs existed but the lifecycle API rejected it; supported across all SDKs (#1984)
  • Wake Kubernetes creation waits on informer watch events instead of fixed 1-second polling, cutting prewarmed-pool create latency from ~1 s to tens of milliseconds while keeping the polling fallback (#1996)
  • Ship the committed FastPath gRPC stubs in the server wheel by force-including them past hatchling's VCS excludes, and smoke-import the built wheel in the release workflow before publishing — this is the 1.1.0 install-time breakage fix (#1959)
  • Fix the Fast Sandbox snapshot CR plural (sandboxsnapshots) in Helm RBAC and the fsb snapshot runtime, where sandboxesnapshots could fail list/watch with missing RBAC (#1972)
  • Propagate the underlying FastPath error message through the 429 capacity mapping (keeping status and Retry-After, adding a cause field) so admission/runtime failures like a broken KVM device are no longer masked as pool exhaustion, and warn-log the raw error before mapping (#2001)
  • Fix Docker edges: reject a repeated pause of an already-paused sandbox with the documented 409 instead of surfacing Docker's "already paused" as 500 (#2023), and clear Docker masked/read-only system paths only for sandboxes that opt into the isolation extension so nested Bubblewrap can mount a private procfs (#1982)

SDKs

Code changes below ride the 1.1.1 stable release — rc ships no SDK packages.

  • Add commands.setEnv for persistent runtime env injection in all five sandbox SDKs (Python async/sync, JavaScript, Kotlin/Java, Go, C#): appends KEY=VALUE to the sandbox env file with runtime-exact serialization, local key/NUL validation, and a loud failure when EXECD_ENVS is unset (#2013)
  • Systematic cross-language audit cleanup across sandbox, code-interpreter, and MCP SDKs: Go retry backoff collapsing to zero delay and dropped session cwd, Python isolated-session ignoring encoding and readiness budgets reporting stale errors, JS resume sharing and killing the source sandbox's transport, Kotlin codes runs dropping every SSE-framed event and never setting exitCode, C# create failing on fresh-sandbox 404 and NREs on empty bodies, and MCP per-call closes tearing down the server-wide shared transport — each fixed with regression tests (#2020)
  • Support env on template create across all five SDKs, matching the server-side golden-image baking (#1984)
  • Align background command stream completion across languages: with execd's fixed completion delay removed, background result collection in Go, Kotlin, and C# now returns on startup acknowledgement like Python and JavaScript instead of waiting for EOF and inferring exit code 0 — query command status for the eventual outcome; foreground calls still read to EOF for older servers (#1825)

Controller

  • Fix an image-committer deadlock where pausing the QEMU container via cgroup v2 freeze never completes (KVM worker kernel threads never reach frozen), by skipping the redundant freeze for the QEMU container already paused over QMP and committing with --pause=false (#1986)

Execd

  • Remove the fixed one-second delay after command completion, cutting median terminal-event-to-return latency from ~1000 ms to sub-millisecond while retaining output flushing and heartbeat cleanup (#1825)
  • Support multiple independent overlay mounts per session in the bwrap isolation layer (separate uppers for workspace vs system paths, nested shadowing, ephemeral tmpfs uppers); internal foundation with no public API change — the request-level overlays field follows (#2021)
  • Stop logging every stdout/stderr chunk at info level, which accounted for 99.8% of execd log volume on output-heavy workloads (#1906)

Networking

egress

  • Add an opt-in chained upstream CONNECT proxy to the transparent mitmproxy path (OPENSANDBOX_EGRESS_UPSTREAM_PROXY/_AUTH), routing sandbox egress through corporate forward proxies with SNI/Host-consistent CONNECT authority, fail-closed startup validation, and no behavior change when unset (#1816)
  • Continue the credential-bound TLS interception foundation (OSEP-0023) [EXPERIMENTAL]: bootstrap authenticated revision sessions on sidecar launch and restart behind an internal gate (#1948), stage unpublished Credential Vault mutation candidates with acknowledge-before-publish commit semantics (#1980), serialize /policy and Vault writes behind a shared mutation barrier (#1991), stage always-rule reloads before publishing (#1997), retain exact attempt identity across indeterminate coordinator outcomes (#2007), and add post-bootstrap revision updates with exact-attempt reconciliation (#2017) — groundwork only; public Vault writes still 503 under the gate and selective TLS stays disabled

ingress

  • Support per-request opt-out of access renew intents via an OpenSandbox-Access-Renew: skip header, suppressed before throttle state is touched and stripped on both the gateway and the server proxy paths — for health probes and other heartbeat-style traffic (#1966)

Fast Sandbox

  • Chart: add controller tolerations, a sandboxtemplateBuilderPodSpec PodSpec-fragment ConfigMap merged into golden-image build pods, a fastletProxyImage override so the injected sidecar no longer has to come from docker.io, and agent/janitor runtime resources for tainted or registry-restricted clusters (#1968)
  • Bump the pinned fast-sandbox source twice: f45bc60 drops CRD CEL validations for older API servers, makes P2P optional behind a peer-gateway seam, and lets template guests inherit the source image's OCI env (#1989); 2b5e840 drops the node-side guest kernel asset (kernelPath becomes optional), adds snapshot CPU-template compatibility admission, and rebinds jailed /dev/kvm to host device numbers before restore (#2028); the intermediate fb87a53 pin bumps the builder's default guest kernel to 6.18.36 (#1992)

Misc

  • CLI: add template and snapshot management (osb template create|get|list|delete, osb snapshot ..., plus --template/--snapshot-id on sandbox create) (#2002), kubectl-style -f/--file request files for sandbox create and template create covering the full wire format with strict unknown-field rejection (#2019), and fix sandbox metrics --watch failing on execd's raw SSE field names (#1970)
  • Charts: correct chart metadata, unify image tag defaults on release-<appVersion> fallbacks, make imagePullPolicy configurable, keep the dataplane Namespace on helm.sh/resource-policy: keep, and rewrite the deployment guide around the umbrella release flow with an explicit install order (#2006)
  • Fast-sandbox tooling: add a self-hosted KVM integration-test workflow (#1978 #1985), a helper that provisions preallocated reflink-XFS state disks for Firecracker (#1995), a realistic golden-image test workload (#1983), and replace MinIO with RustFS in the integration environment (#2009)
  • Docs: publish fast-sandbox performance pages with measured create/snapshot/restore figures (#1951 #1992), sharpen the README intro and Features (#1960), repair links broken by the docs restructure (#1957), mark OSEP-0016 as implemented (#1955), add a DeerFlow integration example (#2011), and remove the unmaintained NullClaw example (#2016)
  • release: bump platform version to 1.1.1-rc.1 across charts and image references

Upgrade & Compatibility

  • The 1.1.0 server package on PyPI is broken at import time and cannot be replaced (PyPI is immutable) — upgrade to this line; see #1959
  • Behavior change: background command result collection in Go, Kotlin, and C# returns on startup acknowledgement and no longer infers exit code 0 — query command status for the eventual outcome (#1825)
  • Behavior change: in multi-tenant mode, another tenant's labeled sandboxes in a shared namespace now resolve as 404; unlabeled legacy sandboxes stay visible until expiry (#1973)
  • Fast-sandbox operators: the 2b5e840 pin removes the bundled node-side guest kernel — restores never boot a kernel and direct boot requires an explicit operator kernelPath pin (#2028); the integration environment reads RUSTFS_*/RC_IMAGE instead of MINIO_*/MC_IMAGE with no legacy alias (#2009)
  • Images: opensandbox/<component>:release-1.1.1-rc.1 (all three registries)
  • Packages: unchanged — SDK/CLI artifacts publish at the 1.1.1 stable release
  • Charts: render from this tag (helm template ./manifests/charts/opensandbox)
  • Kubernetes: supported range v1.21 – v1.34 (charts declare kubeVersion: ">=1.21.1-0")
  • Skew: server ↔ CLI/SDK same line supported; ±1 minor warns

👥 Contributors

Thanks to these contributors ❤️

Artifacts

  • Images: opensandbox/<component>:release-1.1.1-rc.1 (Docker Hub / GHCR / ACR)

Installation

# Platform (Kubernetes) — render the chart at this tag and apply
git clone https://github.com/opensandbox-group/OpenSandbox
git checkout release-1.1.1-rc.1
helm dependency build manifests/charts/opensandbox  # package file:// sub-charts (not committed)
helm template ./manifests/charts/opensandbox | kubectl apply -f -
# or point your GitOps platform (Argo / Flux) at the repo path + tag

Verify what you installed against the BOM: see
Release Verification.

Don't miss a new OpenSandbox release

NewReleases is sending notifications on new releases.