Shipping today ¡ self-hosted
Run the cluster yourself
One binary, one command, any Linux host â x86_64, ARM64 or RISC-V.
- Single binary under 100 MB, no external control plane
- Air-gapped and on-prem friendly
- Warm pool sized adaptively to your load
Open source ¡ CNCF-conformant ¡ Apache 2.0
One cluster. Many agents. Zero trust between them. K8E is a Kubernetes distribution in a single binary under 100 MB, with first-class primitives for running AI agents in secure, ephemeral sandboxes â gVisor, Kata or Firecracker, claimed from a warm pool in under 500 ms.
Already shipping on the official SDKs? Point unmodified e2b clients at K8E â
The shift
Stronger agents make the sandbox more important, not less.
How it works
Agents never touch Kubernetes. They call a single audited gateway that owns the whole session lifecycle â claim, exec, files, terminals, egress and snapshots.
Your agent speaks tools, not Kubernetes objects.
One audited door over gRPC + mTLS.
Pick the isolation level per session; nothing escapes the pod.
Workspaces are ephemeral pods. Snapshots are content-addressed and restorable.
Shipping today
Everything an agent needs to run real work â exposed as first-class operations on one binary.
Every session gets its own pod, filesystem and kernel boundary. Pluggable per session, no KVM required for the default.
Per-session egress policy enforced in the data path â reconfigure the allowlist live, with no proxy process.
An agent-built web app gets a real URL, reverse-proxied into the pod through the gateway with policy applied.
Content-addressed workspace snapshots with incremental restore and a server-side registry.
Who owns what
K8E is infrastructure you run, not a hosted service. There is no control plane phoning home and no license server to unlock.
Run it your way
Two entry points today, both Apache 2.0. Nothing here is a roadmap promise.
Shipping today ¡ self-hosted
One binary, one command, any Linux host â x86_64, ARM64 or RISC-V.
Today ¡ zero code change
Keep the harness you already use. K8E speaks the protocols it speaks.
The direction ¡ not a shipping claim
Where the primitives are heading: a closed loop where every agent workload is submitted, isolated, attested and reclaimed without a human in the path.
An agent asks for compute, not a cluster.
The matrix places the workload on the right node.
A runtime boundary is chosen per session.
Code runs with a live, auditable egress policy.
Transcripts and events make the run reviewable.
The pod is destroyed and the pool refilled.
The sandbox is not a feature of the agent platform.
It is the platform.
Before you install
A single Linux host â x86_64, ARM64 or RISC-V â with about 2 GB of RAM to start. Everything ships in one binary, and `curl -sfL https://k8e.sh/install.sh | sh -` brings up a CNCF-conformant cluster in about 60 seconds.
gVisor is the default and needs no KVM, so it runs anywhere. Kata Containers gives you VM-grade isolation, and Firecracker provides microVMs. The runtime is pluggable per session through Kubernetes RuntimeClass.
Yes. The official e2b Python and JavaScript SDKs work unmodified â sandbox create, exec, file operations, watching and pause/resume map onto K8E sessions. For most stacks it is a two-line endpoint change.
Every exec is recorded. `k8e-sandbox-cli log` replays windowed transcripts, `events` streams NDJSON from the daemon, and `ps` shows the process topology inside the pod â all without leaving the CLI.
Sessions are ephemeral pods. The warm pool replaces a dead pod, and workspace state is recovered from content-addressed snapshots (`snapshot save` / `snapshot restore`, with `--base` for incremental restores).
K8E is Apache 2.0 and self-hosted. There is no per-seat pricing, no token metering and no license server â your infrastructure, your models, your data.
One command
A CNCF-conformant Kubernetes distribution in a single binary. Isolated agent execution from the first command.
curl -sfL https://k8e.sh/install.sh | sh -Needs a Linux host (x86_64 / ARM64 / RISC-V). gVisor is detected at startup.
# 1. install an isolation runtime (gVisor shown)
wget https://storage.googleapis.com/gvisor/releases/release/latest/$(uname -m)/runsc
chmod +x runsc && sudo mv runsc /usr/local/bin/
# 2. install k8e (one binary)
curl -sfL https://k8e.sh/install.sh | sh -
# 3. verify the cluster
export KUBECONFIG=/etc/k8e/k8e.yaml && kubectl get nodes
# 4. connect your agent
k8e-sandbox-cli --endpoint <server-ip>:50051 --apikey <key> connect