airflow.providers.common.ai.sandbox.opensandbox¶
OpenSandbox backend for SandboxToolset.
Attributes¶
Classes¶
Run sandbox tools through an OpenSandbox server. |
Module Contents¶
- class airflow.providers.common.ai.sandbox.opensandbox.OpenSandboxBackend(opensandbox_conn_id='opensandbox_default', *, image='python:3.12-slim', cpu='1', memory='2Gi', sandbox_timeout=3600.0, ready_timeout=120.0, use_server_proxy=None)[source]¶
Bases:
airflow.providers.common.ai.sandbox.base.SandboxBackendRun sandbox tools through an OpenSandbox server.
Note
Experimental: this can change or be removed in a minor release of this provider. See Stable and experimental features.
OpenSandbox supports Docker and Kubernetes runtimes behind the same API. Airflow workers need only network access to that API; the OpenSandbox deployment owns container provisioning and isolation.
A generic Airflow connection supplies the server configuration.
hostandportidentify the lifecycle API,schemaselectshttporhttps, andpasswordcarries the optional API key. Connection extras may setrequest_timeoutanduse_server_proxy.For a deny-by-default spec, the create API accepts a network policy whether or not the server runs the egress sidecar that enforces it, so after creating the sandbox the backend reads the enforced policy back and destroys the sandbox if it differs from what
SandboxSpecasked for. The fail-closed contract is this backend’s to keep, not the server’s.Command deadlines are enforced by execd. If its event stream stalls, the call is abandoned
_EXEC_GRACEseconds past the budget, the sandbox is destroyed to end it, and the result reportstimed_outwithsandbox_terminatedso the toolset provisions a fresh one. Output is streamed and each stream is kept tomax_output_byteson the worker, with one caveat: the SDK reassembles a whole output line before handing it over, so a single line with no newline in it is resident in full first.- Parameters:
opensandbox_conn_id (str | None) – Generic Airflow connection ID.
Nonelets the SDK resolveOPEN_SANDBOX_DOMAINandOPEN_SANDBOX_API_KEY.image (str) – Container image used for each sandbox.
cpu (str) – OpenSandbox CPU resource limit.
memory (str) – OpenSandbox memory resource limit.
sandbox_timeout (float) – Server-side sandbox lifetime in seconds.
ready_timeout (float) – Seconds to wait for a newly created sandbox to become healthy.
use_server_proxy (bool | None) – Route sandbox service calls through the lifecycle server.
Nonereads the connection extra and otherwise defaults toTrue.
- create(*, spec=None)[source]¶
Provision one sandbox and return its handle (name or id).
specofNonemeans “no requirements stated”: the backend applies its own defaults and makes no guarantee. It is not the same as a defaultSandboxSpec, which is an explicit request for an isolated sandbox. The toolset always sends a concrete spec, soNoneonly reaches a backend a caller drives directly.Raise
SandboxTerminalErrorifspecasks for something this backend cannot enforce, rather than provisioning something weaker than was asked for. It is terminal rather than recoverable because it states a configuration fact the model cannot see and cannot fix by retrying.Every failure raised here is terminal, whichever class carries it. The model has no input into provisioning, so a
SandboxErrorfromcreateis not something it can work around; the toolset re-raises one asSandboxTerminalErrorand fails the task, so Airflow’s retry attempts the provisioning again.
- run_command(sandbox, command, *, timeout, max_output_bytes)[source]¶
Run
commandthrough a shell in the sandbox, bounded bytimeoutseconds.max_output_bytesbounds what the backend retains per stream while reading, so unbounded command output cannot exhaust worker memory before the toolset gets a chance to format it.
- read_file(sandbox, path, *, max_bytes)[source]¶
Read a file from the sandbox.
Raise
SandboxFileTooLargeErrorinstead of transferring a file larger thanmax_bytes.
- export_file(sandbox, path, dest, *, max_bytes)[source]¶
Override: stream the file through the SDK’s ranged download, one chunk at a time.