Announcing Native Sandboxing in Ray
Blog post from Anyscale
Ray 2.58 introduces experimental native sandboxing for agentic reinforcement learning and other workloads that execute model-generated code at scale, integrating gVisor-based isolated OCI container environments directly into Ray’s scheduling, resource management, autoscaling, and fault-tolerance systems. Users can employ a high-level API to create and manage sandbox actors across a cluster or use lower-level runtime primitives to build custom sandbox services, with controls for CPU, memory, networking, file transfers, environment configuration, privileges, and OCI specifications. Ray reports scaling to 100,000 gVisor sandboxes in 20 seconds on Google Kubernetes Engine, positioning sandbox placement as another distributed scheduling task rather than requiring a separate control plane. The feature supports practical patterns such as configurable network isolation, cross-node artifact transfer, MCP-based tools for safe code execution, and stricter security controls including capability removal and process limits. It also integrates with Harbor for coding-agent benchmark evaluations, although some task types, including Compose, GPU, and allowlist-based workloads, are not yet supported. Planned improvements include a REST service, GPU-backed sandboxes, Docker support within sandboxes, expanded network and filesystem functions, and security configuration guidance.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.