跳到正文
北京时间
原文
蚂蚁 inclusionAI:GitHub 新仓库· inclusionAI·· 2026-07-11精选AI 评分60

蚂蚁 inclusionAI 开源沙箱生命周期服务 sandboxd

inclusionAI/sandboxd

AI 导读

蚂蚁集团 inclusionAI 在 GitHub 开源 sandboxd,这是 AKernel 使用的 Linux 沙箱生命周期服务,通过 gRPC API 管理沙箱资源,当前基于 gVisor 运行沙箱,并计划近期开源 Kata Containers 支持。

推荐理由

蚂蚁把 AKernel 用的沙箱生命周期管理开源了,对需要安全执行代码的 AI 推理/评测场景有参考价值,但仅限底层基础设施人员,非目标受众不必深究。

正文 · 原文

sandboxd

sandboxd is the Linux sandbox lifecycle service used by AKernel. It exposes a small gRPC API, manages sandbox resources, and currently runs sandboxes with gVisor. Kata Containers support will be open-sourced soon.

Responsibilities

  • Start, wait for, inspect, measure, and delete sandboxes.
  • Prepare local, OCI, Nydus, and S3-backed rootfs and mounts.
  • Allocate cgroups (currently v1 only) and veth interfaces and configure iptables for NAT.

Architecture

gRPC service
    |
sandbox lifecycle manager
    ├── sandbox runtime adapter ──> gVisor
    ├── image manager ────────────> distill-fs / OCI
    └── resource managers ────────> cgroup v1 / veth / iptables

API / CLI

The public protobuf contract is api/runtime/v1/sandbox-api.proto.

The sbox binary is an administrative CLI for managing sandboxes.

Build and test

make
make test
make vet

The privileged E2E suite requires Docker, cgroup v1, iptables, and the tested runsc release:

RUNSC_BINARY=/usr/local/bin/runsc make e2e

See test/e2e/README.md for the developer test environment. AKernel integration is validated through the all-in-one node image and standalone deployment in the AKernel repository.

Protobuf development

Protobuf generation uses a pinned Docker image defined by the Makefile and tools/protobuf.Dockerfile, independent of host-installed protobuf tools:

make protos
make check-protos

Commit the generated Go bindings with the corresponding protobuf change.

Project layout

api/                 public protobuf API and generated Go code
cmd/sandboxd/        sandboxd daemon
cmd/sbox/            administrative CLI
config/              configuration types and defaults
configs/             AKernel integration configuration templates
internal/server/     gRPC service and daemon orchestration
pkg/runtime/         sandbox runtime abstraction and gVisor adapter
pkg/imagemanager/    rootfs and mount integration
pkg/networkmanager/  veth and iptables integration
pkg/cgroupmanager/   cgroup v1 integration
test/e2e/            privileged runsc E2E
tools/               pinned protobuf code-generation image

Known limitations

  • Only gVisor, cgroup v1, netstack sandbox networking, and iptables are supported in v0.1.0.
  • The direct OCI registry client currently skips TLS certificate verification and should only be used with trusted registries.

License

Copyright (c) 2026 Ant Group Corporation.

Licensed under the Apache License, Version 2.0. See LICENSE. Third-party Go modules are declared in go.mod and retain their respective licenses.

来源:蚂蚁 inclusionAI:GitHub 新仓库 · github.com