Production checklist
Before relying on sandboxes in production:
- Set an explicit
timeout_sec. Interactive app-building workflows should usually use1h; short one-shot commands can use less. - Keep the default
persistent=Truefor agent workspaces so timeout preserves/workspaceand dependency installs. - Set
idle_timeout_secfor user-facing dev environments so abandoned sessions stop compute and preserve state. - Pass
idempotency_keyonsandboxes.createcalls in agent retry loops. The platform deduplicates creates with the same key within a 24-hour window, and the key also makes an uncertain placement outcome retryable: the API answers a retryable503 SANDBOX_PLACEMENT_RECONCILINGinstead of a terminal409. - Use a published template instead of reinstalling the same dependencies for every sandbox.
- Fork before destructive operations when you need an independent branch of the current running state.
- Subscribe to
sbx.events.stream()to detect unexpected exits and trigger retries. - Never store long-lived secrets in
env; pass them per-exec or use the Secrets API. - Filter by
external_workspace_idin your list calls to avoid scanning your entire tenant’s sandbox set.