ack-sandbox-manager
ack-sandbox-manager is an API server and agent sandbox proxy add-on compatible with the E2B protocol. You can use it to create, pause, and resume agent sandboxes.
Overview
The ack-sandbox-manager add-on manages sandboxes through their entire lifecycle, including creation, pausing, and resumption. It serves as the API server and the traffic proxy for sandboxes.
The add-on deploys the following workloads in the sandbox-system namespace:
-
sandbox-manager — Contains the controller and envoy containers. The controller exposes the E2B HTTP API (including the
/healthand/metricspaths), synchronizes routes with peer replicas, and uses Memberlist gossip for replica discovery. The envoy container serves as the external data plane and API entry point. -
sandbox-gateway — Contains the gateway container, which serves as the external data plane and API entry point. The gateway also exposes a Prometheus metrics endpoint, synchronizes route tables with sandbox-manager, and uses Memberlist gossip for multi-replica discovery.
When you enable enhancedTrafficManagement for the add-on, the following workloads are created in the sandbox-traffic-system namespace:
-
gateway-controller — Provides xDS authentication and certificate issuance, watches workload and configuration resources, and resolves hostnames used by egress policies.
-
egress-gateway — Receives workload tunnel traffic and forwards policy-allowed traffic to the original external targets.
-
traffic-proxy — Runs as a ztunnel sidecar in business Pods. It receives xDS configuration, requests workload certificates, and sends selected client traffic to the egress gateway.
-
traffic-extension — Performs Envoy external processing for Layer 7 policy enforcement. It watches SecurityProfile resources, retrieves sandbox identity tokens, and sends configured audit events.
Port matrix
The add-on creates different workloads based on the enabled features. The sandbox-manager and sandbox-gateway workloads are deployed in the sandbox-system namespace. When you enable enhancedTrafficManagement for the add-on, the egress-gateway, gateway-controller, traffic-proxy, and traffic-extension workloads are created in the sandbox-traffic-system namespace. If you enable NetworkPolicy or security groups, allow the corresponding traffic based on the port matrix of each workload in your deployment. In the outbound tables, the Condition column indicates whether a connection always applies or applies only under a specific feature, configuration, or deployment topology.
Usage
For information about how to use ACS Agent Sandbox, see Create Agent Sandbox.
Changelog
August 2026
|
Version number |
Date |
Description |
Impact |
|
v0.6.11 |
August 19, 2026 |
|
After the upgrade, HTTP egress traffic managed by enhancedTrafficManagement is resolved through DNS based on the request Host and connects to the resolved address, instead of using the original destination address of the client. If you use self-managed DNS or the request Host is inconsistent with the original destination address, traffic access may fail. Read the changes carefully before upgrading. |
|
v0.6.9 |
August 13, 2026 |
|
This upgrade does not affect your services. However, custom clients that use the old default traffic token request header must adjust accordingly or explicitly retain the old configuration. |
July 2026
|
Version number |
Date |
Description |
Impact |
|
v0.6.8 |
July 29, 2026 |
|
This upgrade does not affect your services. |
|
v0.6.7 |
July 22, 2026 |
|
This upgrade does not affect your services. |
|
v0.6.6 |
July 7, 2026 |
|
This upgrade does not affect your services. |
June 2026
|
Version number |
Date |
Description |
Impact |
|
v0.6.5 |
June 17, 2026 |
|
This upgrade does not affect your services. |
|
v0.6.4 |
June 11, 2026 |
|
This upgrade does not affect your services. |
|
v0.6.3 |
June 9, 2026 |
|
This upgrade does not affect your services. |
|
v0.6.2 |
June 5, 2026 |
|
This upgrade does not affect your services. |
|
v0.6.1 |
June 1, 2026 |
|
This upgrade does not affect your services. |
May 2026
|
Version number |
Date |
Description |
Impact |
|
v0.6.0 |
May 15, 2026 |
|
This upgrade does not affect your services. |
April 2026
|
Version number |
Date |
Description |
Impact |
|
v0.5.2 |
April 29, 2026 |
|
This upgrade does not affect your services. |
|
v0.5.0 |
April 2, 2026 |
|
This upgrade does not affect your services. |
March 2026
|
Version number |
Date |
Description |
Impact |
|
v0.4.3 |
March 23, 2026 |
|
This upgrade does not affect your services. |
|
v0.4.2 |
March 13, 2026 |
|
This upgrade does not affect your services. |
|
v0.4.1 |
March 12, 2026 |
|
This upgrade does not affect your services. |
|
v0.4.0 |
March 2, 2026 |
|
This version contains breaking changes. Read the changes carefully before upgrading. |
January 2026
|
Version number |
Date |
Description |
Impact |
|
v0.3.1 |
January 20, 2026 |
|
This upgrade does not affect your services. |
|
v0.3.0 |
January 13, 2026 |
|
This upgrade does not affect your services. |
December 2025
|
Version number |
Date |
Description |
Impact |
|
v0.2.0 |
December 16, 2025 |
|
This upgrade does not affect your services. |
|
v0.1.0 |
December 4, 2025 |
|
This upgrade does not affect your services. |