K8EK8E
Home
  • What is K8E
  • Getting Started
  • Sandbox Runtime Setup
  • Sandbox CLI
  • Sandbox Examples
  • Sandbox with E2B SDK
  • DeepSeek Harness
  • Architecture
  • Components
  • Advanced Installation
  • K8E vs Alternatives
  • Contributing
Changelog
  • English
  • įŽ€äŊ“中文
GitHub
Home
  • What is K8E
  • Getting Started
  • Sandbox Runtime Setup
  • Sandbox CLI
  • Sandbox Examples
  • Sandbox with E2B SDK
  • DeepSeek Harness
  • Architecture
  • Components
  • Advanced Installation
  • K8E vs Alternatives
  • Contributing
Changelog
  • English
  • įŽ€äŊ“中文
GitHub

Open source ¡ CNCF-conformant ¡ Apache 2.0

Isolated sandboxes for
untrusted agent code

One cluster. Many agents. Zero trust between them. K8E is a Kubernetes distribution in a single binary under 100 MB, with first-class primitives for running AI agents in secure, ephemeral sandboxes — gVisor, Kata or Firecracker, claimed from a warm pool in under 500 ms.

Install K8EView on GitHub ↗ Read the docs →

Already shipping on the official SDKs? Point unmodified e2b clients at K8E ↗

  • Single binary < 100 MB
  • CNCF-conformant
  • Apache 2.0
  • Air-gap ready
LIVEsandbox-matrix ¡ gateway :50051
  1. 01 / CLAIMWarm poolgVisor pod claimed in < 500 ms
  2. 02 / EXECrun "print(1)"streamed over gRPC + mTLS
  3. 03 / SNAPSHOTsha256 ¡ zstdcontent-addressed restore
RECOVERABLE STATEDestroy the session, free the resources. Nothing leaks between agents.
<100MBsingle binaryCNCF-conformant Kubernetes
60sto a running clusterone curl command
<500mswarm-pool claimno cold-start penalty
3isolation runtimesgVisor ¡ Kata ¡ Firecracker

The shift

Agents write the code. Running it still needs a system.

Stronger agents make the sandbox more important, not less.

  1. 01Prompt→Long-running autonomy
  2. 02One agent→Many agents, one cluster
  3. 03Generated code→Executed code
  4. 04Trust the laptop→Zero trust between tenants

How it works

One gateway. Every sandbox.

Agents never touch Kubernetes. They call a single audited gateway that owns the whole session lifecycle — claim, exec, files, terminals, egress and snapshots.

01Agents
k8e-sandbox-cli/k8e-sandbox skille2b SDKs

Your agent speaks tools, not Kubernetes objects.

02Gateway
sessionsexecfilesterminalexposeallow-hosts

One audited door over gRPC + mTLS.

03Runtime
gVisorKataFirecracker

Pick the isolation level per session; nothing escapes the pod.

Recoverable state

Workspaces are ephemeral pods. Snapshots are content-addressed and restorable.

Shipping today

Sandbox primitives, not shell hacks

Everything an agent needs to run real work — exposed as first-class operations on one binary.

  1. 01Isolate

    Every session gets its own pod, filesystem and kernel boundary. Pluggable per session, no KVM required for the default.

    • gVisor
    • Kata
    • Firecracker
  2. 02Govern

    Per-session egress policy enforced in the data path — reconfigure the allowlist live, with no proxy process.

    • Cilium
    • eBPF
    • toFQDNs
  3. 03Expose

    An agent-built web app gets a real URL, reverse-proxied into the pod through the gateway with policy applied.

    • Gateway API
    • expose
    • URL
  4. 04Restore

    Content-addressed workspace snapshots with incremental restore and a server-side registry.

    • sha256
    • zstd
    • --base

Who owns what

Your cluster. Your data. Your models.

K8E is infrastructure you run, not a hosted service. There is no control plane phoning home and no license server to unlock.

ControlKubernetesAPI server ¡ scheduler ¡ etcd
GatewayK8Esessions ¡ policy ¡ mTLS
ExecutionYour nodesruntimes ¡ code ¡ data

Run it your way

Self-host the cluster, or keep your SDK

Two entry points today, both Apache 2.0. Nothing here is a roadmap promise.

Shipping today ¡ self-hosted

Run the cluster yourself

One binary, one command, any Linux host — x86_64, ARM64 or RISC-V.

  • Single binary under 100 MB, no external control plane
  • Air-gapped and on-prem friendly
  • Warm pool sized adaptively to your load
Install K8E

Today ¡ zero code change

Bring your existing agent stack

Keep the harness you already use. K8E speaks the protocols it speaks.

  • Official e2b Python & JavaScript SDKs, unmodified
  • A /k8e-sandbox skill for Claude Code, Codex and Pi
  • Compatible with kubernetes-sigs/agent-sandbox
Read the E2B guide
One binaryNo control plane, no license server, no per-session fee.Apache 2.0 ¡ self-hosted ¡ bring your own GPUs

The direction ¡ not a shipping claim

Toward an agent sandbox matrix

Where the primitives are heading: a closed loop where every agent workload is submitted, isolated, attested and reclaimed without a human in the path.

  1. 01Submit

    An agent asks for compute, not a cluster.

  2. 02Schedule

    The matrix places the workload on the right node.

  3. 03Isolate

    A runtime boundary is chosen per session.

  4. 04Execute

    Code runs with a live, auditable egress policy.

  5. 05Attest

    Transcripts and events make the run reviewable.

  6. 06Reclaim

    The pod is destroyed and the pool refilled.

The sandbox is not a feature of the agent platform.

It is the platform.

Before you install

Questions people ask before running agents on their infra

01What do I need to run K8E?

A single Linux host — x86_64, ARM64 or RISC-V — with about 2 GB of RAM to start. Everything ships in one binary, and `curl -sfL https://k8e.sh/install.sh | sh -` brings up a CNCF-conformant cluster in about 60 seconds.

02Which isolation runtimes are supported?

gVisor is the default and needs no KVM, so it runs anywhere. Kata Containers gives you VM-grade isolation, and Firecracker provides microVMs. The runtime is pluggable per session through Kubernetes RuntimeClass.

03Is it compatible with the E2B SDK?

Yes. The official e2b Python and JavaScript SDKs work unmodified — sandbox create, exec, file operations, watching and pause/resume map onto K8E sessions. For most stacks it is a two-line endpoint change.

04Who reviews the code the agent ran?

Every exec is recorded. `k8e-sandbox-cli log` replays windowed transcripts, `events` streams NDJSON from the daemon, and `ps` shows the process topology inside the pod — all without leaving the CLI.

05What happens when an agent crashes or hangs?

Sessions are ephemeral pods. The warm pool replaces a dead pod, and workspace state is recovered from content-addressed snapshots (`snapshot save` / `snapshot restore`, with `--base` for incremental restores).

06Is it really free?

K8E is Apache 2.0 and self-hosted. There is no per-seat pricing, no token metering and no license server — your infrastructure, your models, your data.

One command

Bring up your sandbox matrix

A CNCF-conformant Kubernetes distribution in a single binary. Isolated agent execution from the first command.

curl -sfL https://k8e.sh/install.sh | sh -

Needs a Linux host (x86_64 / ARM64 / RISC-V). gVisor is detected at startup.

Show the manual four-step install
# 1. install an isolation runtime (gVisor shown)
wget https://storage.googleapis.com/gvisor/releases/release/latest/$(uname -m)/runsc
chmod +x runsc && sudo mv runsc /usr/local/bin/
# 2. install k8e (one binary)
curl -sfL https://k8e.sh/install.sh | sh -
# 3. verify the cluster
export KUBECONFIG=/etc/k8e/k8e.yaml && kubectl get nodes
# 4. connect your agent
k8e-sandbox-cli --endpoint <server-ip>:50051 --apikey <key> connect
Read the getting started guideView the source ↗ Compare the alternatives →
K8E
K8EOpen Source Agentic AI Sandbox Matrix
DocsArchitectureSandbox CLIChangelogGitHub ↗

Copyright Š 2021-2026 xiaods ¡ Apache 2.0 ¡ Privacy Policy

Site design inspired by Orbi