What you will build
A migration preflight for a hypothetical task. This is a document-only exercise; cloud creation, provider usage and public endpoint publication require their own authorized run.
- Classify task and data
- Compare backend capabilities
- Approve budget and exposure
- Run with explicit cleanup
Conceptual flow. Follow the lesson for prerequisites, exact commands and verification limits.
Read the mechanism
Local and cloud sandboxes share a CLI family but not every capability or store. Host mounts and local clone mode do not exist in the cloud in the same form. Credentials, templates, policies and MCP registration have separate scopes.
A local loopback mapping and a cloud published port have very different audiences: cloud publication creates a public HTTPS endpoint. An unauthenticated teaching server that was acceptable on host loopback may expose data when moved.
Cloud compute is metered under a separate subscription. Time-to-live and timeout actions affect lifetime, but a timeout does not replace a verified cleanup record. A move copies filesystem state rather than process memory and leaves a source resource behind; do not describe it as a transparent live migration.
Worked example · migration decision table
| Concern | Local question | Cloud question |
|---|---|---|
| Input | Which host paths are shared? | Which bytes are uploaded or cloned remotely? |
| Credentials | Which host proxy services exist? | Which cloud credentials and permissions exist? |
| Network | Which local L7/destination rules apply? | Which cloud destination policy applies? |
| Ports | Is the listener loopback-only? | Is public HTTPS exposure intentional? |
| Lifetime | Which sessions keep it running? | What TTL and timeout action are configured? |
| Storage | What persists in this VM? | What snapshots/volumes exist and who writes them? |
| Cost | What local resources are consumed? | What account, shape, quota and budget apply? |
Use chapter 15’s Compose stack as the case. Write a decision before running anything: which parts are supported, which need a replacement, and which cannot currently be treated as equivalent?
Current Docker docs warn of a cloud Docker exec / Compose exec / health-check filesystem targeting limitation. A successful local redis-cli ping via Compose exec is therefore not a cloud acceptance result. The limitation must be checked against the version you intend to use.
Expected observations
The preflight should identify at least one non-portable assumption. Record the source date and whether each fact is documented, measured or unknown.
Experimental cloud volumes are snapshot-backed, with updates saved on exit. Concurrent writers can result in last-exit-wins behavior. If a workload needs a shared transactional database, choose storage with those semantics rather than assuming “persistent volume” provides them.
Troubleshooting
If cloud authentication fails despite a working local agent, inspect the cloud-specific credential path. If a template is missing, verify that it exists in the relevant cloud registry. If network behavior differs, compare policy stores and supported controls rather than copying local rules verbatim.
Local API credentials and model-provider credentials solve different authentication problems. Neither proves that cloud compute is activated or affordable for the planned workload.
Interview practice
What is the most dangerous port-migration assumption?
Assuming a local private listener remains private in cloud. Confirm the public endpoint audience and application authentication before publishing.
Does a move eliminate the source sandbox?
Do not assume so. The documented move copies filesystem state and leaves the source. Track both identities and verify the lifecycle of each.
Completion check
Produce a supported/unsupported/unknown matrix, identify the billing boundary and state exactly which evidence would be needed before a cloud trial.
Sources and version notes
Checked 6 October 2026; current baseline: sbx v0.46.0. Compare local and cloud sandboxes · Manage cloud network policy · Install Docker Sandboxes
Make the understanding yours.
Use the completion check above. Mark this chapter when you can explain the mechanism and its limits.
Self-assessed reading progress. This does not certify that a lab ran or a system is secure.