Comparison
This one isn't either/or. agent-sandbox is the Kubernetes SIG Apps project that defines the Sandbox resource: one stateful pod with stable identity and storage. Containarium's Kubernetes backend creates agent-sandbox Sandbox resources and adds the layer an agent needs on top: SSH access with no cluster credentials, an MCP server, a hostname, and egress policy.
agent-sandbox is the primitive; Containarium is a runtime built on it.
| Dimension | Containarium | agent-sandbox |
|---|---|---|
| What it is | An agent runtime: CLI, daemon, SSH gateway, MCP server, cloud | A Kubernetes controller and CRDs (Sandbox, SandboxTemplate, SandboxClaim, SandboxWarmPool) |
| Relationship | The K8s backend creates agent-sandbox Sandbox resources | — |
| How clients connect | SSH through the sentinel (sshpiper); no cluster credentials in the agent | Go and Python SDKs, a sandbox router, or Kubernetes access |
| Agent interface | MCP server in every box | None built in |
| Isolation | Pod under the cluster default runtime, or gVisor via RuntimeClass; LXC on non-K8s hosts | Delegates to the runtime (gVisor, Kata Containers) |
| Networking | Hostname + TLS per box; per-tenant eBPF egress allowlists | Kubernetes Service; NetworkPolicy |
| Backends | Kubernetes or Incus/LXC behind one CLI | Kubernetes |
| License | Apache 2.0 | Apache 2.0 |
agent-sandbox details checked against its public docs and pricing pages in September 2026. Check agent-sandbox's own docs for current specifics.
agent-sandbox gives Kubernetes the right shape for an agent: a singleton, stateful pod with stable identity that survives restarts. Rather than reinvent that, Containarium's Kubernetes backend creates a Sandbox resource per box and lets the agent-sandbox controller own the pod. We benchmarked the two side by side: 373 vs. 373 sandboxes per node, after fixing a bug the benchmark exposed on our side.
The part agent-sandbox deliberately leaves out is how an untrusted agent gets in. Reaching a pod through the Kubernetes API means handing the agent credentials to your control plane. Containarium's agents hold an SSH key scoped to one box; the sentinel routes it to the pod. We wrote up one consequence of that choice in gVisor breaks kubectl, not SSH.
Yes. Containarium's Kubernetes backend creates agent-sandbox Sandbox resources for each box and lets the agent-sandbox controller manage the pod. Containarium adds SSH access, an MCP server, hostnames and egress policy on top.
No. Agents connect over SSH through Containarium's sentinel and hold a key scoped to their own box, with no path to the kube-apiserver.
Use agent-sandbox directly if you are building your own platform on Kubernetes and want the bare primitive. Use Containarium if you want a finished agent runtime on top of it, or the same experience on non-Kubernetes LXC hosts.
Start free on the hosted cloud, or self-host the open source on your own VM.
Also comparing? vs E2B · vs Modal · vs Daytona · vs Runloop · vs Morph Cloud · vs Sprites · vs Docker Sandboxes · vs GitHub Codespaces · vs AWS Lambda · vs Cloudflare Containers