跳到主要内容
AI News HubLIVE
更多
来源内容 · 翻译待补全1 分钟阅读

待翻译:Sidecars: A low-latency trust boundary for Sandboxes

文章摘要

AI 服务暂时不可用,以下为来源摘要,待恢复后补全翻译:Sidecars are isolated containers that run alongside your main Sandbox on the same host.

待翻译:Sidecars: A low-latency trust boundary for Sandboxes
报告错误

纠错通道尚未开通,可先复制下方文章信息留存。

查看更正说明
直接读正文

AI 服务暂时不可用,以下为来源正文,待恢复后补全翻译。

At Modal, our customers rely on Sandboxes to execute untrusted code written by their downstream users or, almost exclusively now, by agents. Running untrusted code isn’t a new problem: every cloud provider has to do this from day 1 to isolate their platform from their user and their users from each other. Fortunately, technologies like gVisor and Firecracker “solved” “isolation” nearly eight years ago. Unfortunately for us, they solved it for an now-outdated unit of trust. How do you protect users from their “own” code? Today we’re excited to introduce Sidecars, which are our broader answer to this problem. Sidecars are isolated containers that run alongside your main Sandbox on the same host and provide a real security boundary between trusted or untrusted code. Sidecars enable 3x faster communication across trust boundaries than using separate Sandboxes — which is particularly helpful for operation-heavy workloads. import modal app = modal.App.lookup("sidecar-example", create_if_missing=True) image = modal.Image.debian_slim().build(app) sb = modal.Sandbox.create("sleep", "600", app=app, image=image, timeout=300) sidecar = sb._experimental_sidecars.create( "python", "-m", "http.server", "8080", name="web", image=image, )

展开要点与分析

文章情报

工程师进阶

要点

  • AI 服务暂时不可用,系统已先保留来源内容与降级元数据。
  • Sidecars are isolated containers that run alongside your main Sandbox on the same host.

要点与分析由自动化流程生成,可能有误,请结合原始来源核实。