本文にスキップ
AI News HubLIVE
その他
原典の内容 · 翻訳・分析待ち1 分で読了

翻訳待ち:Sidecars: A low-latency trust boundary for Sandboxes

記事の要約

AI サービスが一時的に利用できないため、復旧後に翻訳を補完します。ソース概要:Sidecars are isolated containers that run alongside your main Sandbox on the same host.

ソースModal Blog
翻訳待ち:Sidecars: A low-latency trust boundary for Sandboxes
誤りを報告

訂正窓口はまだ利用できません。記事情報をコピーして保存できます。

訂正案内
本文へ

AI サービスが一時的に利用できないため、復旧後に翻訳を補完します。

At Modal, our customers rely on Sandboxes to execute untrusted code written by their downstream users or, almost exclusively now, by agents. Running untrusted code isn’t a new problem: every cloud provider has to do this from day 1 to isolate their platform from their user and their users from each other. Fortunately, technologies like gVisor and Firecracker “solved” “isolation” nearly eight years ago. Unfortunately for us, they solved it for an now-outdated unit of trust. How do you protect users from their “own” code? Today we’re excited to introduce Sidecars, which are our broader answer to this problem. Sidecars are isolated containers that run alongside your main Sandbox on the same host and provide a real security boundary between trusted or untrusted code. Sidecars enable 3x faster communication across trust boundaries than using separate Sandboxes — which is particularly helpful for operation-heavy workloads. import modal app = modal.App.lookup("sidecar-example", create_if_missing=True) image = modal.Image.debian_slim().build(app) sb = modal.Sandbox.create("sleep", "600", app=app, image=image, timeout=300) sidecar = sb._experimental_sidecars.create( "python", "-m", "http.server", "8080", name="web", image=image, )

要点と分析を開く

記事インテリジェンス

エンジニア上級

要点

  • AI 生成が一時的に利用できないため、ソース内容とフォールバックメタデータを保存しました。
  • Sidecars are isolated containers that run alongside your main Sandbox on the same host.

要点と分析は自動生成され、誤りを含む場合があります。原典をご確認ください。