ACS 2026 release notes
Learn about the latest features and updates for Container Compute Service (ACS).
August 2026
|
Category |
Feature |
Description |
Documentation |
|
Agent Sandbox |
Use API key credentials stored in a Kubernetes Secret |
|
Use API Key credentials stored in a Kubernetes Secret by configuring a CredentialProvider |
|
Use API key credentials stored in KMS Secrets Manager |
|
Use API Key credentials stored in KMS Secrets Manager by configuring a CredentialProvider |
|
|
Use RAM role STS temporary credentials |
|
Configure RAM role STS temporary credentials using CredentialProvider |
|
|
Agent Identity-based AgenticFS mounting |
Agent Identity storage authentication now covers AgenticFS (Apsara File Storage NAS) in addition to Object Storage Service (OSS). Each sandbox obtains independent STS temporary credentials that renew automatically, and permissions can be narrowed to the access point that the sandbox declares. When you mount a remote NAS subdirectory that does not exist, the subdirectory is automatically created. |
||
|
Observability |
Monitoring metric sharding for virtual nodes |
The |
July 2026
|
Category |
Feature |
Description |
Documentation |
|
Agent Sandbox |
Agent Identity-based OSS storage mounting |
Declare a persistent volume (PV) that uses Agent Identity authentication, and use SandboxClaim to mount OSS directories. Temporary credentials provide on-demand authorization and eliminate the security risks of long-term keys inside containers. This feature applies to dynamically created sandbox instances that require persistent read/write access to OSS. |
|
|
Store API keys in ApsaraDB RDS for MySQL |
The API key storage backend of Agent Sandbox can be switched from the default Kubernetes Secret to ApsaraDB RDS for MySQL. This suits production environments that have multiple tenants or large numbers of API keys and that need high-concurrency access and centralized key management. |
||
|
API key resource quota |
|
||
|
ACK One multi-cluster fleet management |
Agent Sandbox can be centrally managed and scheduled across clusters by using ACK One fleets. SandboxSet supports multi-cluster distribution with differentiated configurations, and SandboxClaim supports multi-cluster scheduling, which supports large-scale sandbox deployment across regions and clusters. |
June 2026
|
Category |
Feature |
Description |
Documentation |
|
Agent Sandbox |
Egress traffic credential injection |
|
|
|
Network planning and scaling |
The Agent Sandbox network partitioning architecture is documented. Scale sandbox networking by adding vSwitches and security groups to provide the IP addresses and security policies that large-scale sandbox deployments require. |
||
|
Sandbox CRD field reference |
A complete field reference for the Sandbox CustomResourceDefinition (CRD) is available. The reference describes the meaning, type, and value range of each field, helping you precisely define the desired and runtime state of a sandbox in YAML. |
||
|
GPU |
GPU-HPN local disk volume passthrough |
For GPU-HPN capacity reservations, the node's local NVMe disks can be passed through to GPU pods as block devices, bypassing the file system layer. This delivers performance close to that of raw disks for high-frequency read/write workloads such as training data shuffle and inference caching. |
May 2026
|
Category |
Feature |
Description |
Documentation |
|
Agent Sandbox |
Prometheus monitoring |
Managed Service for Prometheus and self-managed Prometheus are supported for collecting Agent Sandbox runtime metrics. Configure a Grafana dashboard to monitor sandbox resources and runtime status in real time. |
|
|
Enhanced egress traffic management |
Fine-grained L7 egress traffic control is available through the |
Configure enhanced egress traffic management for Agent Sandbox |
|
|
Container restart |
The |
||
|
Multi-tenancy management (API key and team) |
|
||
|
Control plane and data plane traffic separation |
|