Skip to content

Sandbox provider suggestion: Capsule (WebAssembly-based local alternative) #13

Description

@mavdol

Hi @bidah,

Your project looks great! I saw you're using cloud-based providers like E2B and Daytona to sandbox untrusted code. I've been building Capsule, a local alternative based on WebAssembly that's quite straightforward to implement.

In your current architecture, you could add it like this:

import { run } from '@capsule-run/sdk/runner';

const result = await run({
    file: './sandbox.ts',
    args: [untrustedCode], 
});

And in a separate file (sandbox.ts):

import { task } from "@capsule-run/sdk";

export const executeCode = task({
  name: "executeCode",
  compute: "LOW",         
  timeout: "10s",
  ram: "64MB",  
}, (code: string) => { 
  const fn = new Function(code);
  return fn();
});

export const main = task({
  name: "main", 
  compute: "MEDIUM"
}, async (code: string) => {
  return executeCode(code);
});

You can create tasks for your sandboxed actions and set limits per task: CPU (via compute units), memory, filesystem access, timeouts, and retries.

Here's the repo with more examples and documentation: https://github.com/mavdol/capsule

Hope this could be useful for your project!

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions