> ## Documentation Index
> Fetch the complete documentation index at: https://docs.tokenfactory.nebius.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Generate and download a binary artifact

> Produce a deterministic binary file, retain it, download it, and verify exact bytes locally.

Captured stdout is intended for process output and is capped. Store a binary deliverable in the filesystem, retain the result image, then download and verify it as bytes.

## Prerequisites and complete source

Complete [Set up access](/sandboxes/start/set-up-access). In a fresh project, run `uv init --python 3.12` and `uv add "contree-sdk==0.3.6"`. Save as `binary_artifact.py`:

```python theme={null}
import asyncio
import gzip
import hashlib
from pathlib import Path

from contree_sdk import Contree

PAYLOAD = b"untrusted input\x00\x01\xff\n"
GENERATE_ARTIFACT = r"""
import gzip
import hashlib
from pathlib import Path

output_directory = Path("/out")
output_directory.mkdir(parents=True, exist_ok=True)
input_bytes = Path("/input.bin").read_bytes()
compressed_bytes = gzip.compress(input_bytes, mtime=0)
(output_directory / "result.bin").write_bytes(compressed_bytes)
digest = hashlib.sha256(compressed_bytes).hexdigest()
(output_directory / "result.sha256").write_text(digest + "\n")
"""


async def main() -> None:
    client = Contree()
    base = await client.images.oci("docker.io/library/python:3.12-alpine")
    run = await base.run(
        shell="python /generate_artifact.py",
        files={
            "/input.bin": PAYLOAD,
            "/generate_artifact.py": GENERATE_ARTIFACT.encode(),
        },
        disposable=False,
        timeout=30,
    )
    if run.exit_code != 0 or run.uuid is None:
        raise RuntimeError('Artifact generation failed or returned no saved image')
    print(f"Artifact saved in image {run.uuid}; downloading")
    destination = Path("downloaded-result.bin")
    await run.download("/out/result.bin", destination)
    remote_digest = (await run.read("/out/result.sha256")).decode().strip()
    actual = destination.read_bytes()
    if actual[:8] != b"\x1f\x8b\x08\x00\x00\x00\x00\x00":
        raise RuntimeError('Downloaded file has an unexpected gzip header')
    if gzip.decompress(actual) != PAYLOAD:
        raise RuntimeError('Downloaded artifact does not contain the original input')
    digest = hashlib.sha256(actual).hexdigest()
    if digest != remote_digest:
        raise RuntimeError('Downloaded bytes do not match the remote SHA-256 digest')
    print(f"Downloaded {destination}: {len(actual)} bytes; contents and digest match")
    print(f"image={run.uuid} bytes={len(actual)} sha256={digest}")


asyncio.run(main())
```

Run `uv run python binary_artifact.py`. The input bytes are injected into the operation, transformed into a deterministic gzip artifact, downloaded, and checked for its gzip header, decompressed content, and SHA-256 digest. The digest checks that the downloaded bytes match the remote file; decompression checks that the file contains the expected input.

The retained result is required because inspection and download happen after execution. A disposable run returns no image to inspect. If generation exits nonzero or the image UUID is absent, do not download from the input image. If download fails after execution, retry the read by the recorded image UUID rather than rerunning untrusted code. The local file remains until removed by the user; the remote image follows image retention. For large inputs or artifacts, confirm the applicable size limits with [support](/sandboxes/operate/troubleshooting#support-bundle) before running the workload.

See [Work with files and artifacts](/sandboxes/guides/work-with-files-and-artifacts).
