Start with the image and resources you need
Create a service with the tools, working directory, and connections required for the task. Enable the sandbox plugin to expose process, file, and terminal access inside its main container. CPU and GPU sessions use the same resource and placement settings as other Polyaxon workloads.
Keep reusable environment choices in a component or preset. An engineer can then investigate a dataset, profile code, or debug a model using the intended image and storage connections instead of rebuilding the setup on a laptop.
Use the right interface for the task
Use the Python client or CLI for commands and file transfer. Stream a long command's output, or start a background process and retain its execution ID to inspect it later. Use the PTY interface when you need terminal behavior rather than a single command result.
Notebook servers can run in the same service with sandbox access enabled. Add the SSH plugin for native terminals and IDE access, or the tmux plugin for reconnectable shell sessions. Enable only the interfaces your workflow needs.
Automate with Python or CLI · Use notebooks · Choose interactive access plugins
Inspect a running Python environment
The sandbox quick start uses a python:3.11 service with a writable /workspace directory. After the run reaches a running state, a client bound to that run executes python -V and retrieves its output. It can then inspect files or open a terminal in the same container.
This small session separates the two lifecycles: a command can finish while the service stays available for the next command. The workspace is scratch storage for the pod's lifetime; download useful files or save them to configured output storage, then stop the service to release its resources.
Keep the results, not an abandoned session
Download useful scratch files or write them to the run's synced outputs path before stopping the service. Logging an artifact reference records metadata; it does not copy an arbitrary file into durable storage. Move lasting code changes into Git and repeated dependency changes into your image.
Stop the service when work finishes. Disconnecting a client or closing a terminal does not release the resources held by the backing run. Configure a service timeout, and use an appropriate activity probe if you need idle-based cleanup.
Set permissions for the code that will run
Sandbox commands execute with the service container's user, mounts, credentials, and network access. Attach only the required connections and configure the Kubernetes security and network settings for the workload's trust level.
Polyaxon authenticates access to the selected run. The sandbox plugin itself is not a microVM runtime or a guarantee that arbitrary hostile code is safe. If an agent will invoke commands, its host application also needs to decide which tools it exposes and which actions require approval.
Secrets and connections · Network access · Agent code execution