ACS 2026 release notes

Updated at:

Learn about the latest features and updates for Container Compute Service (ACS).

August 2026

Category

Feature

Description

Documentation

Agent Sandbox

Use API key credentials stored in a Kubernetes Secret

CredentialProvider centrally manages the API keys stored in Kubernetes Secrets. The platform issues credentials to workloads on demand based on Agent Identity, so applications do not need to embed plaintext keys in code or images.

Use API Key credentials stored in a Kubernetes Secret by configuring a CredentialProvider

Use API key credentials stored in KMS Secrets Manager

CredentialProvider manages the API keys stored in Key Management Service (KMS) Secrets Manager. The ack-agent-identity add-on retrieves each key from a dedicated KMS instance through OpenID Connect (OIDC) and delivers it based on Agent Identity, so your pods do not need to embed plaintext keys or connect to KMS directly.

Use API Key credentials stored in KMS Secrets Manager by configuring a CredentialProvider

Use RAM role STS temporary credentials

CredentialProvider centrally manages Resource Access Management (RAM) roles. Based on Agent Identity, the platform assumes these roles through RAM Roles for Service Accounts (RRSA) and issues instance-scoped, short-lived Security Token Service (STS) credentials. You can use policy to narrow permissions and targetRoleArn to enable cross-account access, so applications do not need to embed long-lived AccessKey pairs in code or images.

Configure RAM role STS temporary credentials using CredentialProvider

Agent Identity-based AgenticFS mounting

Agent Identity storage authentication now covers AgenticFS (Apsara File Storage NAS) in addition to Object Storage Service (OSS). Each sandbox obtains independent STS temporary credentials that renew automatically, and permissions can be narrowed to the access point that the sandbox declares. When you mount a remote NAS subdirectory that does not exist, the subdirectory is automatically created.

Mount AgenticFS for an Agent Sandbox

Observability

Monitoring metric sharding for virtual nodes

The ack-virtual-node add-on v2.7.3 or later supports the metricsShardSize parameter (maximum value: 48) in the acs-profile ConfigMap. This parameter distributes the cAdvisor metrics exposed by virtual nodes across multiple Prometheus scrape targets. This resolves the issue where a single scrape target handles too many metrics when thousands of serverless pods run in a cluster.

Enable monitoring metric sharding for virtual nodes

July 2026

Category

Feature

Description

Documentation

Agent Sandbox

Agent Identity-based OSS storage mounting

Declare a persistent volume (PV) that uses Agent Identity authentication, and use SandboxClaim to mount OSS directories. Temporary credentials provide on-demand authorization and eliminate the security risks of long-term keys inside containers. This feature applies to dynamically created sandbox instances that require persistent read/write access to OSS.

Mount OSS storage for an Agent Sandbox

Store API keys in ApsaraDB RDS for MySQL

The API key storage backend of Agent Sandbox can be switched from the default Kubernetes Secret to ApsaraDB RDS for MySQL. This suits production environments that have multiple tenants or large numbers of API keys and that need high-concurrency access and centralized key management.

Store API keys with RDS MySQL

API key resource quota

ack-sandbox-manager supports per-API key quotas on the number of sandboxes and on CPU and memory usage. Quota-based admission control uses Redis for strong consistency across replicas, preventing a single API key from consuming excessive cluster resources and causing resource contention in multi-tenant scenarios.

Set resource quotas for API keys by using the Quota feature

ACK One multi-cluster fleet management

Agent Sandbox can be centrally managed and scheduled across clusters by using ACK One fleets. SandboxSet supports multi-cluster distribution with differentiated configurations, and SandboxClaim supports multi-cluster scheduling, which supports large-scale sandbox deployment across regions and clusters.

Manage Agent Sandbox by using ACK One multi-cluster fleet

June 2026

Category

Feature

Description

Documentation

Agent Sandbox

Egress traffic credential injection

SecurityProfile tokenTransformation rules automatically replace placeholder credentials with real API keys when sandbox egress traffic passes through the Egress Gateway. This allows applications to make secure external API calls without storing credentials locally.

Configure credential injection for Agent Sandbox

Network planning and scaling

The Agent Sandbox network partitioning architecture is documented. Scale sandbox networking by adding vSwitches and security groups to provide the IP addresses and security policies that large-scale sandbox deployments require.

Agent Sandbox network planning and scaling

Sandbox CRD field reference

A complete field reference for the Sandbox CustomResourceDefinition (CRD) is available. The reference describes the meaning, type, and value range of each field, helping you precisely define the desired and runtime state of a sandbox in YAML.

Sandbox CRD field reference

GPU

GPU-HPN local disk volume passthrough

For GPU-HPN capacity reservations, the node's local NVMe disks can be passed through to GPU pods as block devices, bypassing the file system layer. This delivers performance close to that of raw disks for high-frequency read/write workloads such as training data shuffle and inference caching.

Use local disk volumes for GPU-HPN capacity reservation

May 2026

Category

Feature

Description

Documentation

Agent Sandbox

Prometheus monitoring

Managed Service for Prometheus and self-managed Prometheus are supported for collecting Agent Sandbox runtime metrics. Configure a Grafana dashboard to monitor sandbox resources and runtime status in real time.

Enable Prometheus monitoring for ACS Agent Sandbox

Enhanced egress traffic management

Fine-grained L7 egress traffic control is available through the SecurityProfile CRD. Define traffic-blocking rules based on attributes such as domain names and URL paths to improve network isolation for sandboxes.

Configure enhanced egress traffic management for Agent Sandbox

Container restart

The ContainerRecreateRequest CRD allows you to restart a specific container in a pod without recreating the entire pod, minimizing the impact of maintenance operations on workloads.

Restart an Agent Sandbox container

Multi-tenancy management (API key and team)

ack-sandbox-manager supports API key and team management. Each team maps to a Kubernetes namespace for tenant isolation. Administrators can create and manage API keys for all teams, while regular tenants can only manage their own keys.

Multi-tenancy management

Control plane and data plane traffic separation

SandboxGateway enables independent forwarding of data plane traffic, separate from the control plane. This prevents control plane failures from affecting data plane stability.

Separate control and data planes in Agent Sandbox