Skip to content
AI News HubLIVE
More
Source content · Analysis pending1 min read

Sidecars: A low-latency trust boundary for Sandboxes

Summary

Sidecars are isolated containers that run alongside your main Sandbox on the same host.

Sidecars: A low-latency trust boundary for Sandboxes
Report an error

The correction channel is not available yet. You can copy the article reference below for later.

Correction instructions
Read article

At Modal, our customers rely on Sandboxes to execute untrusted code written by their downstream users or, almost exclusively now, by agents. Running untrusted code isn’t a new problem: every cloud provider has to do this from day 1 to isolate their platform from their user and their users from each other. Fortunately, technologies like gVisor and Firecracker “solved” “isolation” nearly eight years ago. Unfortunately for us, they solved it for an now-outdated unit of trust. How do you protect users from their “own” code?

Today we’re excited to introduce Sidecars, which are our broader answer to this problem. Sidecars are isolated containers that run alongside your main Sandbox on the same host and provide a real security boundary between trusted or untrusted code. Sidecars enable 3x faster communication across trust boundaries than using separate Sandboxes — which is particularly helpful for operation-heavy workloads.

import modal

app = modal.App.lookup("sidecar-example", create_if_missing=True) image = modal.Image.debian_slim().build(app) sb = modal.Sandbox.create("sleep", "600", app=app, image=image, timeout=300)

sidecar = sb._experimental_sidecars.create( "python", "-m", "http.server", "8080", name="web", image=image, )

Key points and analysis

Article intelligence

EngineersAdvanced

Key points

  • AI generation is temporarily unavailable; this entry was preserved with deterministic fallback metadata.
  • Sidecars are isolated containers that run alongside your main Sandbox on the same host.

Highlights and analysis are generated automatically and may contain errors. Check the original source.