Forkable Sandboxes: The Runtime Layer for AI Software Factories

About this session

AI agents now run thousands of ephemeral coding tasks a day, and each one needs a clean, fast, trustworthy environment to execute in. At Incredibuild and islo.dev I build secure execution infrastructure for AI workloads: CI runners, sandboxes, snapshots, caching, and reproducible environments. I built the sandbox backend for LangChain Deep Agents (langchain-islo) and presented a new ephemeral task isolation sandbox provider at an Apache Airflow Monthly Town Hall. A meta-harness loop running on islo.dev sandboxes moved from zero passing tasks to five out of five in about two seconds across four proposer steps, using forkable snapshots instead of full environment rebuilds. Drawing on earlier container security work at Twistlock, this talk covers what it actually costs to run agent-generated code safely at CI speed, what breaks first, and what a forkable snapshot buys you that a fresh container doesn't.

Speaker

Key takeaways

  • Why cloning a fresh container per agent task doesn't scale, and what forkable snapshots buy you instead
  • Concrete numbers from a real meta-harness loop: 0/5 to 5/5 passing tasks in about two seconds across four proposer steps
  • Lessons from container security work at Twistlock, applied to today's agent tool-calling deployments

Related sessions