{"repo":"isola-run/isola","free":true,"listed":false,"github":"https://github.com/isola-run/isola","clone":"git clone https://github.com/isola-run/isola.git","description":"Self-hosted Kubernetes sandboxing platform","language":"Go","stars":52,"topics":[],"license":"Apache-2.0","category":"self-hosted-apps","readme_excerpt":"Secure sandboxing for Kubernetes --- Isola is an open-source platform for running untrusted and AI-generated code securely on your own Kubernetes cluster. It uses gVisor to isolate each pod behind its own application kernel. Create sandboxes from any OCI image, execute commands, stream output, read and write files, and snapshot the root filesystem for reuse. Isola provides a REST API and SDKs for building AI agents, code interpreters, and other applications that need to run untrusted code safely. It is self-hosted and operates with the tools you already know. Quick start These examples assume a running Isola cluster. See Deployment for production setup, or run hack/setup.sh to get a local development cluster with Kind. Install the SDK for your language: Create a sandbox, run a command, and read files: The same workflow in TypeScript: Snapshot the filesystem and restore it in new sandboxes. Pre-warm an environment once and reuse it, or snapshot a working session and pick it up later: See the Python SDK and TypeScript SDK documentation for the full API reference, and the OpenAPI spec for the REST API. Why Isola? - Open source. Apache 2.0 licensed. The code is yours to audit, modify, and deploy. - Self-hosted. Sandboxes run on your Kubernetes nodes. You control your infrastructure and your data. - Kubernetes-native. Sandboxes and snapshots are Custom Resources managed by a Kubernetes operator. They integrate naturally with your existing RBAC, observability, and cluster operation","default_branch":null,"files":null,"tree":[],"storefront":"/r/isola-run","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/isola-run/isola/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}