OpenSandbox 1.1.1-rc.1
First release candidate on the 1.1.1 patch line, cut to fix the broken 1.1.0 server wheel: hatchling's VCS-exclude filtering silently dropped the committed FastPath gRPC stubs from the PyPI package, so every 1.1.0 install of opensandbox-server failed at import time — PyPI is immutable, so the patched line is 1.1.1 (#1959). Beyond that fix, this rc carries everything merged since release-1.1.0: agent-sandbox pause/resume, shared-namespace tenant isolation, watch-driven create latency, commands.setEnv and a systematic audit cleanup across all five SDKs, upstream-proxy chaining for egress, and two fast-sandbox pin bumps. Baseline for every section is release-1.1.0. rc releases publish images but hold packages — SDK/CLI artifacts ship at the 1.1.1 stable bump. Please test and report issues.
Highlights
- Fixes the
1.1.0server wheel: FastPath stubs now ship in the package and installs import cleanly (#1959) - Server: pause/resume on the agent-sandbox provider, tenant isolation for sandboxes sharing a Kubernetes namespace, and pool creates woken by watch events instead of 1-second polling (#1975 #1973 #1996)
- SDKs:
commands.setEnvruntime env injection in all five languages, plus a systematic cross-language audit cleanup fixing dozens of correctness bugs (#2013 #2020)
Server
- Implement pause/resume for the agent-sandbox provider by bridging to
spec.operatingMode(Running/Suspended) onagents.x-k8s.io/v1beta1, with state derivation (Paused/Pausing/Resuming/Terminated), resourceVersion preconditions, and 409 on invalid transitions; both endpoints previously returned "not supported" (#1975) - Isolate tenants that share one Kubernetes namespace: creates stamp
opensandbox.io/tenant, and list/get/delete/pause/resume/proxy hide other tenants' labeled sandboxes as 404 while unlabeled legacy sandboxes stay visible until expiry; also addskubernetes.insecure_skip_tls_verifyfor ServiceAccount CA mismatches (#1973) - Heal the silent renew-intent drop after a server restart in multi-tenant mode: the resolver now falls back to a cluster-wide label lookup with a 403 circuit breaker and structured warnings, trusts an ingress-observed namespace from the intent payload when verifiable, and single-tenant deployments never resolve beyond the configured namespace (#1819)
- Add
[docker] publish_hostto publish bridge-mode sandbox ports on one host address (default0.0.0.0unchanged) — with127.0.0.1or the Docker bridge gateway, the tokenless execd port no longer lands on public interfaces (#1954) - Add a typed, admin-only
[egress.upstream_proxy]config section (URL + optional authorization, validated at load) that injects the sidecar's chained upstream CONNECT proxy on both Docker and Kubernetes, with fail-closed 400s when the requestednetworkPolicyis incompatible; secret values are no longer echoed in config-validation errors (#1999) - Accept
envon template create and bake it into the fast-sandbox golden image (/etc/sandbox-init.env, inheriting the source image's OCIConfig.Env), closing the gap whereSandboxTemplate.spec.envsexisted but the lifecycle API rejected it; supported across all SDKs (#1984) - Wake Kubernetes creation waits on informer watch events instead of fixed 1-second polling, cutting prewarmed-pool create latency from ~1 s to tens of milliseconds while keeping the polling fallback (#1996)
- Ship the committed FastPath gRPC stubs in the server wheel by force-including them past hatchling's VCS excludes, and smoke-import the built wheel in the release workflow before publishing — this is the
1.1.0install-time breakage fix (#1959) - Fix the Fast Sandbox snapshot CR plural (
sandboxsnapshots) in Helm RBAC and the fsb snapshot runtime, wheresandboxesnapshotscould fail list/watch with missing RBAC (#1972) - Propagate the underlying FastPath error message through the 429 capacity mapping (keeping status and
Retry-After, adding acausefield) so admission/runtime failures like a broken KVM device are no longer masked as pool exhaustion, and warn-log the raw error before mapping (#2001) - Fix Docker edges: reject a repeated pause of an already-paused sandbox with the documented 409 instead of surfacing Docker's "already paused" as 500 (#2023), and clear Docker masked/read-only system paths only for sandboxes that opt into the isolation extension so nested Bubblewrap can mount a private procfs (#1982)
SDKs
Code changes below ride the 1.1.1 stable release — rc ships no SDK packages.
- Add
commands.setEnvfor persistent runtime env injection in all five sandbox SDKs (Python async/sync, JavaScript, Kotlin/Java, Go, C#): appendsKEY=VALUEto the sandbox env file with runtime-exact serialization, local key/NUL validation, and a loud failure whenEXECD_ENVSis unset (#2013) - Systematic cross-language audit cleanup across sandbox, code-interpreter, and MCP SDKs: Go retry backoff collapsing to zero delay and dropped session
cwd, Python isolated-session ignoringencodingand readiness budgets reporting stale errors, JS resume sharing and killing the source sandbox's transport, Kotlin codes runs dropping every SSE-framed event and never settingexitCode, C# create failing on fresh-sandbox 404 and NREs on empty bodies, and MCP per-call closes tearing down the server-wide shared transport — each fixed with regression tests (#2020) - Support
envon template create across all five SDKs, matching the server-side golden-image baking (#1984) - Align background command stream completion across languages: with execd's fixed completion delay removed, background result collection in Go, Kotlin, and C# now returns on startup acknowledgement like Python and JavaScript instead of waiting for EOF and inferring exit code 0 — query command status for the eventual outcome; foreground calls still read to EOF for older servers (#1825)
Controller
- Fix an image-committer deadlock where pausing the QEMU container via cgroup v2 freeze never completes (KVM worker kernel threads never reach
frozen), by skipping the redundant freeze for the QEMU container already paused over QMP and committing with--pause=false(#1986)
Execd
- Remove the fixed one-second delay after command completion, cutting median terminal-event-to-return latency from ~1000 ms to sub-millisecond while retaining output flushing and heartbeat cleanup (#1825)
- Support multiple independent overlay mounts per session in the bwrap isolation layer (separate uppers for workspace vs system paths, nested shadowing, ephemeral tmpfs uppers); internal foundation with no public API change — the request-level
overlaysfield follows (#2021) - Stop logging every stdout/stderr chunk at info level, which accounted for 99.8% of execd log volume on output-heavy workloads (#1906)
Networking
egress
- Add an opt-in chained upstream CONNECT proxy to the transparent mitmproxy path (
OPENSANDBOX_EGRESS_UPSTREAM_PROXY/_AUTH), routing sandbox egress through corporate forward proxies with SNI/Host-consistent CONNECT authority, fail-closed startup validation, and no behavior change when unset (#1816) - Continue the credential-bound TLS interception foundation (OSEP-0023) [EXPERIMENTAL]: bootstrap authenticated revision sessions on sidecar launch and restart behind an internal gate (#1948), stage unpublished Credential Vault mutation candidates with acknowledge-before-publish commit semantics (#1980), serialize
/policyand Vault writes behind a shared mutation barrier (#1991), stage always-rule reloads before publishing (#1997), retain exact attempt identity across indeterminate coordinator outcomes (#2007), and add post-bootstrap revision updates with exact-attempt reconciliation (#2017) — groundwork only; public Vault writes still 503 under the gate and selective TLS stays disabled
ingress
- Support per-request opt-out of access renew intents via an
OpenSandbox-Access-Renew: skipheader, suppressed before throttle state is touched and stripped on both the gateway and the server proxy paths — for health probes and other heartbeat-style traffic (#1966)
Fast Sandbox
- Chart: add controller tolerations, a
sandboxtemplateBuilderPodSpecPodSpec-fragment ConfigMap merged into golden-image build pods, afastletProxyImageoverride so the injected sidecar no longer has to come from docker.io, and agent/janitor runtime resources for tainted or registry-restricted clusters (#1968) - Bump the pinned fast-sandbox source twice:
f45bc60drops CRD CEL validations for older API servers, makes P2P optional behind a peer-gateway seam, and lets template guests inherit the source image's OCI env (#1989);2b5e840drops the node-side guest kernel asset (kernelPathbecomes optional), adds snapshot CPU-template compatibility admission, and rebinds jailed/dev/kvmto host device numbers before restore (#2028); the intermediatefb87a53pin bumps the builder's default guest kernel to 6.18.36 (#1992)
Misc
- CLI: add template and snapshot management (
osb template create|get|list|delete,osb snapshot ..., plus--template/--snapshot-idonsandbox create) (#2002), kubectl-style-f/--filerequest files forsandbox createandtemplate createcovering the full wire format with strict unknown-field rejection (#2019), and fixsandbox metrics --watchfailing on execd's raw SSE field names (#1970) - Charts: correct chart metadata, unify image tag defaults on
release-<appVersion>fallbacks, makeimagePullPolicyconfigurable, keep the dataplane Namespace onhelm.sh/resource-policy: keep, and rewrite the deployment guide around the umbrella release flow with an explicit install order (#2006) - Fast-sandbox tooling: add a self-hosted KVM integration-test workflow (#1978 #1985), a helper that provisions preallocated reflink-XFS state disks for Firecracker (#1995), a realistic golden-image test workload (#1983), and replace MinIO with RustFS in the integration environment (#2009)
- Docs: publish fast-sandbox performance pages with measured create/snapshot/restore figures (#1951 #1992), sharpen the README intro and Features (#1960), repair links broken by the docs restructure (#1957), mark OSEP-0016 as implemented (#1955), add a DeerFlow integration example (#2011), and remove the unmaintained NullClaw example (#2016)
- release: bump platform version to
1.1.1-rc.1across charts and image references
Upgrade & Compatibility
- The
1.1.0server package on PyPI is broken at import time and cannot be replaced (PyPI is immutable) — upgrade to this line; see #1959 - Behavior change: background command result collection in Go, Kotlin, and C# returns on startup acknowledgement and no longer infers exit code 0 — query command status for the eventual outcome (#1825)
- Behavior change: in multi-tenant mode, another tenant's labeled sandboxes in a shared namespace now resolve as 404; unlabeled legacy sandboxes stay visible until expiry (#1973)
- Fast-sandbox operators: the
2b5e840pin removes the bundled node-side guest kernel — restores never boot a kernel and direct boot requires an explicit operatorkernelPathpin (#2028); the integration environment readsRUSTFS_*/RC_IMAGEinstead ofMINIO_*/MC_IMAGEwith no legacy alias (#2009) - Images:
opensandbox/<component>:release-1.1.1-rc.1(all three registries) - Packages: unchanged — SDK/CLI artifacts publish at the
1.1.1stable release - Charts: render from this tag (
helm template ./manifests/charts/opensandbox) - Kubernetes: supported range v1.21 – v1.34 (charts declare
kubeVersion: ">=1.21.1-0") - Skew: server ↔ CLI/SDK same line supported; ±1 minor warns
👥 Contributors
Thanks to these contributors ❤️
- @alahaiyo
- @comqx
- @cwj2001
- @dcaminos
- @gau1991
- @hittyt
- @hpliStartAgain
- @jianpingpei
- @jiawen7777
- @kittimzhe
- @mengdehong
- @mpu
- @Pangjiping
- @ruirui6946
- @TuGou-a
- @YxinMiracle
- @y4ney
Artifacts
- Images:
opensandbox/<component>:release-1.1.1-rc.1(Docker Hub / GHCR / ACR)
Installation
# Platform (Kubernetes) — render the chart at this tag and apply
git clone https://github.com/opensandbox-group/OpenSandbox
git checkout release-1.1.1-rc.1
helm dependency build manifests/charts/opensandbox # package file:// sub-charts (not committed)
helm template ./manifests/charts/opensandbox | kubectl apply -f -
# or point your GitOps platform (Argo / Flux) at the repo path + tagVerify what you installed against the BOM: see
Release Verification.