policy field, and because a cluster hosts at most one runner, one policy governs one cluster.
For the task-oriented walkthrough, see Configure a sandbox policy. For worked examples, see Policy examples.
CoreWeave Serverless sandboxes are in public preview.
Top-level fields
An empty policy is valid and declares a fully permissive posture. Both
base and constraints are optional, so a cluster’s posture is always stated rather than inherited by accident.
Resolution order
A sandbox resolves in two stages:- Base. Runtime defaults, then
base, then the sandbox spec. The sandbox wins for individual values. List attachments frombaseare always applied. - Constraints. Clamps are validated against the fully resolved spec. A violation is rejected, never silently rewritten.
base supplied is checked on the same terms as a value the sandbox supplied.
base
A fragment of runtime defaults and attachments. On a Kubernetes runner, this is a pod specification fragment.
base is where infrastructure settings live that a sandbox has no business declaring: the scheduler, node selectors, tolerations, priority class, topology spread, service accounts, image pull secrets, platform volumes, DNS configuration, and pod metadata such as pinned annotations. Security-sensitive fields are rejected outright, including affinity, pod and container securityContext, runtimeClassName, and initContainers.
constraints
PolicyConstraints groups the typed clamps a policy enforces. Every group is optional, and an omitted group applies no restriction.
ResourceConstraints
The ceilings differ from the maximums:
max_cpu bounds one container’s request, while cpu_ceiling bounds the resolved total, which matters when base contributes containers of its own.
ImageConstraints
NetworkConstraints
Network constraints define allowlists for the access a sandbox can request. When a sandbox declares egress, the policy accepts or rejects that declaration without widening it. When the sandbox declares no egress, the policy applies default_egress, unless the sandbox sets deny_egress. Platform DNS and storage access are granted separately.
When an allowlist is non-empty, containment is checked by destination or source type and port. A declared CIDR must fit the combined allowed CIDR ranges or an
any rule. A declared tenant scope requires a matching tenant rule or an any rule, while declaring any requires an any rule.
EgressRule
Each rule names exactly one destination, optionally narrowed by port.
Hostname rules authorize HTTPS access, not DNS queries. When
allowed_egress is non-empty, a declared hostname must fit an allowed hostname pattern, after its exclusions, or an any rule. A CIDR-only allowlist does not permit hostname declarations. Put reusable hostname grants in a sandbox template, not in default_egress.
dns_egress controls outbound UDP/TCP port 53 independently. DNS_EGRESS_MODE_ALLOW permits access to the platform resolver; other resolvers require an egress rule. DNS_EGRESS_MODE_DENY blocks outbound port 53 even when another rule permits it. It does not block locally answered lookups or DNS over other permitted transports, such as HTTPS.
IngressRule
Ingress rules never name a source, because inbound packets carry no name.
CidrBlock
PortRange
TenantScope
SelectorBlock
Matching uses exact label pairs, but declarations may add labels. When the egress allowlist is non-empty, a declared selector must carry every label pair in a matching selector rule. Both selectors must omit namespace labels, or both must include them, with the declaration carrying every required namespace label pair. An
any rule never covers selectors, but an empty allowlist permits selector declarations.
SecurityConstraints
allowed_runtime_classes is the one list where empty means “nothing,” not “anything.” A sandbox can only select a runtime class you name explicitly.
Host-reaching settings are policy-only and never appear on a sandbox spec, whatever the isolation in use.
InstanceConstraints
LifecycleConstraints
The policy carries no lifetime cap. The platform maximum, currently 30 days, bounds every sandbox: a create request above it is rejected. The
max_lifetime_seconds field was removed from the policy document, and cwic rejects a policy that still carries it.
MetadataConstraints
VolumeConstraints
StorageMedium
Omit
STORAGE_MEDIUM_MEMORY from allowed_media to forbid RAM-backed volumes.
Validation rules
A policy is rejected when any of the following hold:- The encoded document exceeds 256 KiB.
- The policy is null. A configured policy cannot be cleared, only replaced.
default_egresscontainshttps_hostnamerules.- Default egress or ingress rules fall outside the corresponding allowlist.
See also
- Configure a sandbox policy: the task-oriented walkthrough for every group on this page.
- Policy examples: five complete policies for common cluster postures.
- Policies overview: how a sandbox resolves against a policy.
- Deploy and manage a runner: where the policy lives and how to set it.