CoreWeave sandboxes are in public preview. For access, contact your CoreWeave account team, CoreWeave Support, or email support@coreweave.com.
Before you begin
Both the CLI and thecurl examples on this page authenticate with a CoreWeave API access token. Generate one from the Tokens page in the cloud console and copy the Token Secret value. For more on tokens, see Manage API access tokens.
CLI: install the CoreWeave Intelligent CLI (cwic), then run cwic auth login and paste the token when prompted. The token is stored in your local cwic config. Subsequent commands read it automatically. You don’t need to set an environment variable.
curl: export the token in your shell so the examples on this page can pick it up:
Runner commands
Thecwic sandbox runner group manages runners. The following table maps each lifecycle task to the command that performs it. Later sections walk through these commands in context.
All input accepts YAML or JSON.
Deploy a runner
Each CKS cluster hosts at most one managed runner. To deploy one, supply:- Runner ID: a client-assigned human-readable ID, unique within your organization.
- Zone: the geographic zone the cluster belongs to.
- Cluster ID (or cluster name): which CKS cluster the runner runs on. You can find both on the Clusters page in the cloud console.
- Policy: the rules the runner enforces for sandboxes on its cluster. Required, and it must bound sandbox lifetime. See Configure a sandbox policy.
- CLI
- curl
The wizard collects cluster, release channel, and maintenance windows interactively, then opens your editor with a pre-filled spec before submitting:File mode accepts YAML or JSON, which makes it the preferred path for repeatable setups and a good fit for agents like Claude Code or Codex that generate runner specs on your behalf. The CLI also reads from stdin with Submit the spec:
-f -.runner.yaml
maintenance_policy.windowsis optional. When set, automatic updates apply only during the specified cron windows.runner_group_idis optional. Use it for scheduling affinity when you have multiple runners in the same zone.
Common validation errors
Check runner status
After creation, check the runner’s status to confirm it rolled out successfully and to diagnose problems if it did not.- CLI
- curl
get:prod-us-east-1) or the server-assigned UUID.installStatus: progress of the runner deployment into your cluster (PENDING,PROVISIONING,READY, orFAILED).connectionStatus: live connectivity (CONNECTEDorDISCONNECTED). The runner’s heartbeat updates this value. Expect up to 30 seconds of lag.
installStatus == FAILED, the response includes a structured installError:
remediationHints are the actions you should take. diagnosticDetail also contains internal logs that are useful to attach if you open a support ticket.
Update a runner
The runner edit command supports both an interactive wizard and a file-driven patch. Internally, updates use a field mask: only the fields you change are applied. Everything else is read-only, includinginstallStatus, connectionStatus, timestamps, and the resolved deployment spec.
The following paths are mutable:
identity.zoneidentity.runner_group_idmanaged_spec(whole object)managed_spec.release_channelmanaged_spec.maintenance_policymanaged_spec.overridesmanaged_spec.allow_privileged_profile_annotationspolicy(whole document)profile_bindings(whole list, legacy,v1beta2only)
Common runner updates
The following examples show the most frequent edits applied to a runner: switching release channels, replacing the policy it carries, tuning where the runner pod lands in your cluster, and allowing legacy profile templates to carry a privileged posture.Example: switch release channel
- CLI
- curl
Apply a one-line patch from stdin:Or write the patch to a file and submit it:
patch.yaml
Example: replace the policy
The policy is replaced as a whole document. Read the current one, change what you need, and send it back. There is no field-level mask insidepolicy, so a partial body clears the groups you leave out.
- CLI
- curl
Example: pin node placement through deployment overrides
Themanaged_spec.overrides field tunes the runner’s own pod, not sandbox pods. Use it when the runner pod requires specific tolerations, node selectors, or runtime classes to land on the right nodes.
A common case is routing the runner pod through the SUNK Pod Scheduler so it can run in your SUNK cluster alongside Slurm jobs. Set the scheduler name and the SUNK annotations on the runner overrides. See SUNK Pod Scheduler integration for the available annotations and required setup.
- CLI
- curl
overrides.yaml
Example: allow a privileged profile posture
allow_privileged_profile_annotations controls whether the legacy profile templates bound to a runner may carry a privileged posture. It applies to runners that still use profile bindings rather than a policy, so the request goes to the v1beta2 surface. It defaults to false, and a template that carries one is rejected on a runner where the flag is not set.
Despite the name, the flag governs two kinds of content:
- Privileged pod annotations, meaning the runtime and scheduler prefixes.
- Privileged structured pod-spec fields, such as
serviceAccountName, host namespaces,hostPathvolumes, and privileged or escalating containers.
permission_denied and names the offending fields. For example, a template that sets securityContext.appArmorProfile and securityContext.seccompProfile fails with the following:
Example output
- CLI
- curl
Trigger an on-demand runner update
WhenupdateAvailable is true on the runner, you can apply the update immediately rather than wait for the next maintenance window:
- CLI
- curl
target_revision. The in-cluster controller rolls it out.
List runners
To see every runner in your organization, or to narrow the view to a specific zone, cluster, or connection state, use the following list commands.- CLI
- curl
Delete a runner
Remove a runner when you no longer need sandbox capacity on its cluster, or before you redeploy a fresh runner on the same cluster.- CLI
- curl
--yes to skip the prompt for scripted use:See also
- Sandboxes architecture: the resource model, control plane compared to data plane, and multi-cluster topology.
- Policies overview: how a sandbox resolves against a policy.
- Configure a sandbox policy: every constraint group, with worked examples.
- Control plane API overview: authentication, field masks, and the request and response shapes for every endpoint.
- Policy reference: every field you can set in a policy.