Sandbox Next

作者 cloudflareb052c32bab7d無授權條款3K 個星標收錄於 2026年10月8日更新於 2026年10月8日儲存庫7 天前更新

Build or maintain Cloudflare Sandbox apps on @cloudflare/sandbox@next (SDK 1.0 preview). Use sandbox-migrate-to-next when porting a stable app.

AI 產生的概覽

指導在 @cloudflare/sandbox@next 1.0 預覽版 SDK 上建置或維護 Cloudflare Sandbox 應用程式。

功能
提供確認應用程式是否位於 @next 套件與容器映像線路的檢查關卡,列出不可違背的 API 約定(例如以 argv 為基礎的 exec 與行程控制代碼),並給出指向相關預覽文件頁面的檢索地圖。也列出出貨前檢查項目,涵蓋 lockfile 與 Dockerfile 的一致性、依已安裝型別進行的型別檢查、機密處理以及預覽主機名稱 DNS。它產出的是指引與程式碼形態慣例,而非可直接執行的產物。
適用情境
適用於撰寫或維護依賴 @next 預覽套件與相符容器映像的 Cloudflare Sandbox 應用程式。不適用於使用預設穩定套件的應用程式,也不適用於移轉穩定版應用程式,技能會將這些情況導向其他技能。出貨前也可用它核對套件線路一致性與機密處理。
執行需求
不附帶指令碼,僅提供說明。前提是使用 @cloudflare/sandbox@next 預覽套件與相符容器映像的 Cloudflare Workers 專案,已安裝 @next 型別以供型別檢查,並能存取 Cloudflare 文件與範例儲存庫。

Sandbox SDK — @next (1.0 preview)

Isolated Linux environments on Cloudflare Containers, driven from Workers.

Prefer preview docs and installed @next types over memory. APIs change; this skill is a gate, a contract, and a retrieval map—not a full manual.

We recommend new projects on this line. Apps still on the default package use sandbox-stable. Port only when asked, via sandbox-migrate-to-next.

1. Gate — confirm the package line

Before writing code, inspect the app:

CheckMust match
npm dependency@cloudflare/sandbox@next (or another preview tag)
Container imageSame line (e.g. cloudflare/sandbox:next, next-python)
If you find…Action
Default @cloudflare/sandbox (no @next)Stop. Load sandbox-stable. Do not apply this skill’s APIs.
User wants to port stable → @nextStop. Load sandbox-migrate-to-next.
Self-deployed bridge onlyBridge is not on the 1.0 preview line yet. Keep bridge on stable package + image. Bridge (stable)

Never mix an @next Worker package with a stable container image (or the reverse).

Skills install: Agent setup · cloudflare/skills

2. Contract — non-negotiables

  • sandbox.exec(argv) takes an argv list and resolves when the process starts. It returns a handle, not a finished command result.
  • Collect results with handle methods: output(), logs(), waitForExit(), waitForPort(), waitForLog(), kill(signal?).
  • No implicit shell. Shell syntax needs an explicit shell, e.g. ["/bin/bash", "-lc", script].
  • Each launch is independent. A cd / export in one exec is not visible to the next. Pass cwd and env per launch, or one shell script.
  • Process handles have no stdin. Interactive use → terminals (createTerminal + connect).
  • Local wait timeout / AbortSignal cancel the wait only. They do not kill the process. Use kill or exec’s remote timeout.
  • getProcess / listProcesses / getTerminal / listTerminals do not start a container; they return null / [] when none is up.
  • Process and terminal IDs belong to the current container, not forever to a sandbox ID. For work that must survive replace, store the full job (argv, cwd, env, app state)—not only an id.
  • Non-secret config only in setEnvVars / launch env. Live credentials stay in the Worker; use outbound handlers when the sandbox calls external APIs.
  • Do not invent removed stable APIs (gitCheckout on core, string-exec completion, session execution, sandbox.terminal(request)).
  • Do not use one retry loop for every error (see Errors docs).

Minimal shape:

ts
import { getSandbox, proxyToSandbox, Sandbox } from "@cloudflare/sandbox";
export { Sandbox };
const sandbox = getSandbox(env.Sandbox, "user-123");const process = await sandbox.exec(["python3", "-c", "print(2 + 2)"]);const result = await process.output({ encoding: "utf8" });// result.stdout, result.exitCode

Task-specific API documentation: references/api-quick-ref.md [blocked]

Examples index (next branch): references/examples.md [blocked]

3. Retrieve — open the doc for the task

Fetch the page before implementing. Installed @next types win over guesses.

You need to…Open
Orient / choose preview1.0 preview overview
First Worker, wrangler, DockerfileGet started
exec, handles, readiness, durabilityProcess execution
Process API signaturesProcesses API
Sandbox ID vs container vs sleep/destroyLifecycle
cwd / env / setEnvVarsEnvironment
Interactive PTY / browser terminalTerminals · Terminals API
Python/JS code interpreterInterpreter · Interpreter API
Extensions modelExtensions
Error classes and recoveryErrors · Errors API
Common failuresTroubleshooting
API hubAPI reference
Files, mounts, backups, ports, tunnels, proxyToSandboxMain docs for shared surfaces (ignore stable-only session/transport/sandbox.terminal): Files · Storage / mounts · Ports · Tunnels · Backups · Outbound traffic · Expose services · Production
Example appsexamples on next
Still on stable packagesandbox-stable · Main Sandbox docs
Porting an existing stable appsandbox-migrate-to-next · Migrate

4. Before you ship

  • Lockfile and Dockerfile on the same @next line
  • Typecheck against installed @next types
  • No live secrets in sandbox env
  • Production preview hostnames need wildcard DNS on a custom domain when using those URL patterns

來源與署名

來源:cloudflare/skills位於skills/sandbox-next提交b052c32

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架