Skip to content

AWS, Google Cloud, Microsoft Azure, and Cloudflare now all offer agent sandboxes. None built them the same way.

7.6 relevance
Score Breakdown
technical depth
8
novelty
8
actionability
7
community
6
strategic
7
personal
9

Scored daily by a customisable AI persona to surface the most relevant engineering leadership news.

Direct comparison of agent sandboxes across major cloud providers is highly relevant and actionable for platform engineers.

Cloud thenewstack.io
AWS, Google Cloud, Microsoft Azure, and Cloudflare now all offer agent sandboxes. None built them the same way.
Summary

AWS, Google Cloud, Microsoft Azure, and Cloudflare now all offer native agent sandboxes for isolated code execution, but each uses a fundamentally different isolation stack: AWS relies on Firecracker MicroVMs with up to eight-hour sessions, Google uses gVisor kernel interception for GKE and a lightweight boundary within Cloud Run instances, Microsoft runs Hyper-V-based dynamic sessions (Copilot alone consumes 400,000+ daily), and Cloudflare isolates sandboxes in per-VM containers via Workers. The architectural disagreements center on where the security boundary lives, and vendor-specific constraints—like Graviton-only regions, eight-hour caps, or shared CPU/memory with the parent instance—mean commoditization remains incomplete, leaving room for neutral multi-cloud sandbox solutions.

Author

Janakiram MSV

More from Janakiram MSV →