Skip to content

OpenSandbox

vsdks/sandbox/go/v1.0.4 Breaking

This release includes 1 breaking change for platform teams planning a safe upgrade.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →

✓ No known CVEs patched in this version

Topics

ai ai-agent ai-infra kubernetes sandbox

Affected surfaces

auth breaking_upgrade

Summary

AI summary

Updates Breaking Changes, What's New, and iptables/nft across a mixed release.

Full changelog

What's New

Breaking Changes

  • The credential vault binding match no longer carries a Ports field. Port is now derived from the scheme (https → 443, http → 80), matching what the intercept layer (iptables/nft) actually redirects. If your Go code constructs credential vault bindings and sets Match.Ports, remove that field on upgrade — port selection is now implicit from the scheme. This removes a field that never provided real flexibility (only 80/443 were ever intercepted). #1189

Features

  • Added a client-side sandbox pool (OSEP-0005) for the Go SDK, enabling millisecond-level sandbox acquisition from pre-warmed idle instances. The new SandboxPool API (via PoolBuilder) provides a background reconcile loop with leader election, fill-deficit / shrink-excess management, exponential backoff on warmup failures, and near-expiry-aware idle reuse. InMemoryPoolStateStore covers single-process deployments; a separate optional poolredis sub-module (go-redis v9) provides RedisPoolStateStore with atomic Lua-script operations for distributed setups. The main SDK module stays on go 1.20 with zero external dependencies — the pool is a fully opt-in, backward-compatible addition. Aligned with the Python and Kotlin pool implementations. #1198
  • Added run_once and withSession isolation convenience helpers to the Go SDK. sandbox.IsolationRunOnce(ctx, req, run, handlers) wraps create → run → delete into a single call with guaranteed cleanup, and sandbox.IsolationWithSession(ctx, req, fn) scopes a multi-run isolated workflow with auto-delete on exit. Cleanup is best-effort so it never masks the original error. These build on the execd-backed isolation support added to the Go SDK (isolated.go, sandbox_isolated.go). #1008 #1222
  • Added an LRU + TTL endpoint cache with in-flight request deduplication. The SDK now caches (sandbox_id, port, use_server_proxy) → Endpoint to avoid repeated resolution round-trips. It is enabled by default (TTL 600s, max size 1024) and tunable via ConnectionConfig; Kill() actively invalidates cached entries for the sandbox. #1133
  • Sandbox lifecycle responses now surface extensions. The Go SDK response models expose opensandbox.extensions.* data returned by create/get/list so callers can read extension values round-tripped from the server. #1112
  • Added the optional resourceRequests field to sandbox creation. Kubernetes-backed sandboxes can now set resource requests separately from limits (enabling Burstable QoS). Omitting the field preserves the existing behavior where requests equal limits. #1074

Misc

  • Updated the Go SDK README GitHub links to the new opensandbox-group/OpenSandbox org (Go module/import paths unchanged). #1197
  • Bumped the Go Sandbox SDK version constant to 1.0.4 and added a regression test that locks the default User-Agent to the release version. #1248

Contributors

  • @GreenShadeZhang
  • @Pangjiping
  • @jianpingpei
  • @jwx0925

Breaking Changes

  • Removed `Ports` field from credential vault binding match; port selection is now implicit based on scheme (`http` → 80, `https` → 443).

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track OpenSandbox

Get notified when new releases ship.

Sign up free

About OpenSandbox

Secure, Fast, and Extensible Sandbox runtime for AI agents.

All releases →

Related context

Earlier breaking changes

Beta — feedback welcome: [email protected]