An AI coding agent needs somewhere to run its commands. Once it can install packages, execute generated code, or drive a browser, that environment becomes part of your application's design.
We're the team behind Lizard. Our latest sandbox announcement focuses on three parts of that environment: a separate kernel for each sandbox, templates for different workloads, and the ability to pause and resume work.
One Firecracker microVM per sandbox
The announced architecture runs each sandbox in its own Firecracker microVM with its own kernel.
That distinction matters when evaluating execution environments. With conventional container isolation, workloads can share the host kernel. A microVM introduces a guest kernel and a virtualization boundary. Firecracker is designed around lightweight virtual machines; you can read about its architecture in the Firecracker project documentation.
An isolation boundary does not replace application-level access controls. If you give an agent a production credential, its sandbox can still use that credential. Scope the permissions you pass into the environment to the task the agent needs to complete.
Choose a template around the workload
A sandbox is more useful when the dependencies you need are already present. The announcement includes these templates:
| Template | Included environment | Example workload |
|---|---|---|
base |
Python 3.11 | A small Python script or a custom setup |
interpreter |
Python, Node, pandas, numpy, matplotlib, scipy, Jupyter | Data analysis and notebook execution |
desktop |
Linux desktop with Chromium | Browser and computer-use tasks |
claude, codex, opencode, pi, prime
|
The corresponding coding agent installed | A coding task using your chosen agent |
These are starting environments, not claims that every task needs the same stack. A data-analysis job and an agent interacting with a browser have different requirements. Picking the closest template reduces the setup you need to manage yourself.
An installed agent may still need credentials and configuration for the services it uses. Treat those as part of your integration, rather than assuming a template includes access to a model provider.
Pause a task without rebuilding its environment
The update also announces pause and resume: files and running processes stay where you left them.
Consider a coding agent that has installed dependencies, started a process, and then reached a point where it needs human input. Preserving the environment means the next step can continue from that state instead of repeating setup.
There are several different requirements here that are worth keeping separate:
- Pausing and resuming execution preserves a working session.
- Persisting files keeps the outputs you want to retain.
- Exporting an artifact makes that output available outside the sandbox.
Choose which of these your workflow needs. A resumable session is useful, but it is not a substitute for explicitly saving the final result of a job.
Compute starts at $0.009 per hour
The announced starting rate is $0.009 per hour, billed per second, with $10 in free credits to start.
At that starting compute rate, ten minutes works out to $0.0015. That's a compute-only illustration, not a quote for every configuration or associated service. Check the current plan and resource details for your workload.
What to try first
Start with one representative task: a Python analysis, a browser interaction, or a coding-agent run. Choose the matching template, give it only the access it needs, and save a useful output. If your workflow involves waiting for human input, include a pause/resume step in your evaluation.
You can explore the offering on the Lizard sandboxes page.
Which part of your agent workflow creates the most friction today: environment setup, execution isolation, or continuing a task after a wait?
Top comments (0)