Sandboxes
Create and manage KVM-backed microsandbox VMs
Requires KVM on Linux (/dev/kvm) or Virtualization.framework on macOS. Each node’s cellard drives VMs through the official microsandbox Go SDK. On first use it runs EnsureInstalled to fetch the microsandbox CLI and firmware if needed.
Isolation is hardware virtualization — sandboxes do not share the host kernel like containers.
# Create (does not start unless --start)
sudo cellar sandbox create --name demo --image alpine:3.20
sudo cellar sandbox create --name demo --image alpine:3.20 --memory-mib 1024 --vcpus 2 --start
sudo cellar sandbox ls
sudo cellar sandbox ls --all
sudo cellar sandbox inspect <id>
sudo cellar sandbox start <id>
sudo cellar sandbox logs -f <id>
sudo cellar sandbox stop <id>
sudo cellar sandbox rm <id>Managers and workers both run sandboxes. Desired state lives in Raft; the leader schedules onto the least-loaded live node (nodes with availability pause or drain are skipped).
How create works. sandbox create writes desired state to Raft and returns immediately. Each node's runtime agent pulls assigned sandboxes and reconciles them with the local microsandbox driver.
Application workloads should use the official microsandbox SDKs against cellar-gateway, not the CLI.