- request_timeout_seconds: How long to wait for API responses (client-side)
- max_lifetime_seconds: How long the sandbox runs before auto-termination (server-side) If not set, the backend controls the default lifetime.
container_image(str) : Docker image for the sandbox container. Default:DEFAULT_CONTAINER_IMAGE.command(str) : Entrypoint command to run. Default:DEFAULT_COMMAND.args(tuple[str, ...]) : Arguments passed to the command. Default:DEFAULT_ARGS.base_url(str) : CWSandbox API endpoint URL. Default:DEFAULT_BASE_URL.auth(AuthConfig | None) : Authentication selection. Accepts anAuthStrategy, resolvedAuthHeaders, or anAuthProvider.Nonepreserves a legacy process-global override when installed and otherwise usesAuthStrategy.COREWEAVE_API_KEY. Default:field(default=None, repr=False).request_timeout_seconds(float) : Client-side HTTP timeout in seconds for most RPCs. Poll Get RPCs usepoll_rpc_timeout_secondsinstead. Default:DEFAULT_REQUEST_TIMEOUT_SECONDS.poll_retry_budget_seconds(float) : Wall-clock budget per retry burst (one trip to a stable status). The budget resets on any successful response, so a long-lived sandbox that hits a transient error, recovers, then hits another much later gets a fresh budget each time. Retryable transient codes are UNAVAILABLE, DEADLINE_EXCEEDED, and RESOURCE_EXHAUSTED. Set to 0.0 to disable retries entirely. Default:DEFAULT_POLL_RETRY_BUDGET_SECONDS.poll_rpc_timeout_seconds(float) : Per-call timeout for poll Get RPCs. Kept separate fromrequest_timeout_secondsso a wedged poll fails fast instead of blocking on the broader request timeout. Default:DEFAULT_POLL_RPC_TIMEOUT_SECONDS.max_lifetime_seconds(float | None) : Server-side sandbox lifetime limit in seconds. None lets the backend control the default. Default:DEFAULT_MAX_LIFETIME_SECONDS.temp_dir(str) : Temp directory path inside the sandbox. Default:DEFAULT_TEMP_DIR.tags(tuple[str, ...]) : Tags for filtering and organizing sandboxes. Default:field(default_factory=tuple).runner_ids(tuple[str, ...] | None) : Restrict to specific runner IDs (CKS). Pass an empty list to explicitly clear any default; pass None (the default) to inherit any configured default. Incompatible with serverless placement.placement_mode(PlacementMode | str | None) :PlacementMode(serverless/cks) or string.placement_spillover(PlacementSpillover | str) :PlacementSpilloverpolicy for a one-shot create retry on the alternate mode when the primary fails with a spillable capacity/placement reason. DefaultSTRICT(no spill). Template sandboxes requireSTRICT. Default:PlacementSpillover.STRICT.resources(ResourceOptions | dict[str, Any] | None) : Resource configuration. AcceptsResourceOptionsfor separate requests/limits, or a flat dict for backward-compatible Guaranteed QoS.network(NetworkOptions | None) : Deny-flag network options and optional create-time hostname grants viaNetworkOptions.services(tuple[Service, ...] | None) : Typed service ports (Service) for PUBLIC/PRIVATE/CUSTOM.volumes(tuple[ScratchVolumeOptions | RegisteredVolumeOptions, ...] | None) : Scratch or registered volumes (ScratchVolumeOptionsorRegisteredVolumeOptions).runtime_class(str | None) : Optional runtime-class pin (e.g."gvisor").security_context(SecurityContext | dict[str, Any] | None) : In-guest privilege for the single-container path. Not applied whencontainers=ordefaults.containersis used.working_dir(str | None) : Working directory for the single-container path. Not applied when a container list is used.object_storage_access(ObjectStorageAccess | dict[str, Any] | None) : Temporary object-storage credentials.file_system_snapshot(FileSystemSnapshotOptions | dict[str, Any] | None) : Convenience single-mount FSS options viaFileSystemSnapshotOptions. Shareable mount defaults (mount_path, size); an explicitrun()value replaces it wholesale. Prefervolumes=for multi-volume setups.containers(tuple[Container, ...] | None) : Optional multi-container spec (Container). Mutually exclusive with single-container fields onSandbox.run(). When this list is used,secrets,environment_variables,security_context, andworking_diron these defaults are not applied; set them on eachContainer.secrets(tuple[Secret, ...] | None) : Secrets for the single-container path. Not applied whencontainers=ordefaults.containersis used.environment_variables(dict[str, str]) : Environment variables for the single-container path. Not applied when a container list is used. Default:field(default_factory=dict).annotations(dict[str, str]) : Kubernetes pod annotations (key-value string pairs). Merged with per-sandbox annotations; explicit values override defaults. Use for non-sensitive metadata only. Default:field(default_factory=dict).data_plane_mode(DataPlaneMode | str) : Transport policy for exec, logs, and file operations.auto(default) prefers direct mTLS and falls back to the gateway;gatewaydisables direct access;directrequires it. Default:DataPlaneMode.AUTO.
Methods
merge_tags
merge_environment_variables
merge_annotations
with_overrides
from_dict
SandboxDefaults from a mapping, coercing nested fields.
Accepts plain dicts or OmegaConf DictConfig objects. Unknown
keys are silently ignored so callers can pass a config section
that may contain extra fields.
Coercions applied:
networkdict ->NetworkOptionssecretslist of dicts -> tuple ofSecretserviceslist of dicts -> tuple ofServicevolumeslist of dicts -> tuple of scratch/registered volume optionscontainerslist of dicts -> tuple ofContainersecurity_contextdict ->SecurityContextobject_storage_accessdict ->ObjectStorageAccessargs,tags,runner_ids,services,volumes,containerslists -> tuplesresources,environment_variables-> plaindict