Skip to main content
Sandboxes runs workloads in VM-level isolation. Treat the sandbox as a boundary for workload execution, while controlling which data and credentials enter it.

Network boundary

networking.enabled=false starts the VM without a guest network interface. The setting defaults to true and must be supplied on every relevant spawn. If a workload requires destination allowlists, private networking, ingress, specific DNS controls, or customer network logs, confirm support with the Sandboxes team before deployment.

Handle credentials

Keep the Sandboxes API token outside guest code. Use short-lived, least-privilege workload credentials, pass them only when needed, and avoid retained files, preserved environment metadata, command lines, and output. Do not place registry passwords in Dockerfile build arguments or source. A disposable filesystem result only prevents the run’s filesystem changes from becoming a continuation image. It does not confirm deletion of uploads, operation records, or platform logs. Contact contree@nebius.com before using data that requires a specific encryption-at-rest, residency, deletion, or retention guarantee. For support, share operation and image UUIDs, timestamps, client versions, terminal status, and redacted errors. Remove tokens, customer files, environment values, and unredacted output.