Skip to content

Runtime

One AgentRun object becomes a fully isolated, fully attributed run. The agent in the loop is not trusted, so every control on this page sits outside the sandbox. This page describes the design; what runs today is on the status page.

The agent runtime. An AgentRun claim goes through a Crossplane composition, which renders a ServiceAccount with projected tokens, a default-deny CiliumNetworkPolicy and a Sandbox. The Sandbox pod runs under gVisor on a dedicated pool, GKE Sandbox on gcp-0 or Karpenter on aws-0. Inside it, the OpenHands harness never holds the run token: the Envoy identity-proxy sidecar attaches it to every call to the agent gateway, and the room-bridge sidecar holds the room token. The gateway’s token exchange reaches octo-sts, which mints a short-lived GitHub token for the agents’ App, confined by rulesets to agent/** branches and no tags. OpenBao and External Secrets hold the platform’s secrets, none of which reach the sandbox

Source: docs/architecture/ai-platform.drawio, page 3.

Components and software

ComponentSoftwareWhat it doesWhy this software
Run APICrossplane v2 composition, written in KCLTurns one AgentRun claim into everything a run needs: ServiceAccount, task ConfigMap, network policy, Sandbox. Projects the run’s phase, PR and token usage back into its statusThe platform’s standard for self-service APIs; one claim, one lifecycle, deleted as a whole
Sandbox lifecycleagent-sandboxA Sandbox resource: one pod with a stable identity and a clean start, and no restarts that hide failuresKubernetes-native and built for agent workloads; the same building block as AWS’s agents-on-EKS blueprint
IsolationgVisor (runsc) on a dedicated pool: GKE Sandbox agents-gvisor on gcp-0, Karpenter agents-gvisor on aws-0Runs the agent’s commands against gVisor’s user-space kernel, so an exploit has to break gVisor before it reaches the node’s kernelStrong isolation without VMs, and it runs on ordinary nodes (Kata would need bare metal or nested virtualisation)
HarnessOpenHands agent-server and SDK, wrapped by a small agent-run entrypointThe agent loop: shell, editor, git, MCP tools. agent-run clones the repository, starts the conversation, prints the step log and revokes the GitHub token at the endOpen source, headless (an HTTP API rather than an IDE), model-agnostic, with MCP support
Identity proxyEnvoy sidecarAttaches the run’s own short-lived token to every model, tool and token-exchange call. The harness never sees that tokenThe agent cannot leak a gateway token it never sees. The one credential it holds is its GitHub token: in memory, one repository, one role, ≤ 1 h, revoked when the run ends
Network policyCilium CiliumNetworkPolicyDefault deny, per run: egress only to named hosts (GitHub, the router, optional package registries)FQDN-aware policy, plus Hubble to see every dropped flow
GitHub accessocto-sts and a GitHub App, plus a repository rulesetExchanges the run’s identity for a GitHub token scoped to one repository and its role’s permissions, valid ≤ 1 h and revoked when the run ends. The rulesets let the App push only agent/** branches, and no tagsNo long-lived GitHub token anywhere; the rules live in each repository’s trust policies
SecretsOpenBao and External SecretsHolds the few platform secrets (App keys, provider keys); none reaches a sandboxThe platform’s secret store, nothing agent-specific

Security boundaries

BoundaryMechanism
Code executiongVisor sandbox, restricted pod security, no service-account token in the harness
NetworkDefault-deny CNP per run; egress only to named FQDNs and the gateway
IdentityTwo projected tokens per run, for the gateway and for token exchange, valid until the deadline; each audience names the run’s role and its data class or repository. A room run adds a third, audience room-broker, refreshed every 600 s and held only by the room-bridge sidecar
GitHubShort-lived installation tokens from octo-sts, scoped to one repository and the role’s permissions; rulesets let the agents’ App push only agent/** branches, and no tags

Spend, merge and stop are the factory’s controls: see Factory → Controls.