Hello Vercel team,
I’m evaluating Sandbox Hobby for a personal, non-commercial Python agent. Before account setup, could you clarify the following? Please identify current supported mechanisms/documentation and distinguish native Hobby capabilities from anything requiring custom guest security work.
-
Memory: Can an untrusted task be hard-limited to 256 MiB aggregate RAM, including all descendant/background processes? If unsupported, what is the smallest supported hard limit, and where is it enforced?
-
Processes/threads: Can the workload be restricted to eight total processes/threads, including descendants, or an equivalently strict aggregate limit? How are they counted and the limit enforced?
-
CPU: Can CPU consumption be hard-bounded across the whole workload/process tree? Is vCPU allocation an enforced runtime ceiling or only sandbox sizing? Please clarify enforcement and throttling/burst semantics.
-
Writable storage: Can the task have no more than 1 MiB TOTAL writable storage across every accessible path, with writes denied everywhere else? If unsupported, what is the smallest enforceable total writable quota?
-
Privileges and protected controls: Your repository documents passwordless sudo for the default identity. Is there a supported non-root, non-sudo task identity that cannot regain those privileges, change its enforced limits, modify supervisor/controller state, or access sandbox control credentials/material? Does achieving this require a custom guest security architecture?
-
Complete cleanup: Does successful whole-sandbox stop/destruction guarantee termination of every foreground, background and descendant process? Please distinguish this guarantee from command-level termination and clarify when cleanup is confirmed complete.
-
Network denial: With deny-all, what is blocked or still reachable through IPv4, IPv6 if available, TCP, UDP, DNS, localhost, internal/private destinations, and metadata/platform service endpoints? Please distinguish external egress denial from guest-local/control communications and identify exceptions.
-
Execution evidence: Can the client obtain separate stdout/stderr, the exact process exit code, and an identifiable timeout/cancellation outcome? How is task timeout distinguished from API/lifecycle timeout? Are service/SDK output buffers bounded, including output without newlines, or must the client stream and truncate? Can collection remain bounded before any complete-output buffering?
-
Windows controller: Is the Python API/SDK supported natively on Windows 11/Python 3.14 without local Docker, WSL, Hyper-V or another VM runtime?
-
Hobby activation: Can a new personal Hobby user activate and use Sandbox without adding a credit/debit card or any other payment method?
-
Hard zero spend: Your Hobby documentation states that additional Sandbox usage is not charged. Please confirm whether usage can ever create a payable balance, whether exhausted allowance blocks new starts, and whether already-running or resumed sandboxes stop, finish without charge, or can enter billable usage. Is any automatic/silent plan upgrade possible? Is Hobby’s protection a hard zero-spend guarantee independent of delayed spending alerts or limits?
-
Permitted use: Please confirm that personal, non-commercial execution of my own AI-generated code is permitted on Hobby, without security probing of Vercel infrastructure.
The resource thresholds above are fixed requirements for this evaluation; larger supported minimums would indicate incompatibility. I’m requesting capability and terms clarification only, with no paid-feature request.
Thank you.