Skip to lesson
supraj.dev THE ENGINEERING HANDBOOKS
LEARN / BUILD / VERIFY2026 edition · checked 06 Oct

CHAPTER 24 / 30 · Connect and coordinate

Understand what a sandbox actually isolates

Distinguish an in-process shell, a container adapter and a microVM before making security claims.

4 min read + practiceWorked exerciseInterview practice

The mechanism

“Sandbox” is not a single isolation guarantee. A component may mediate operations inside one process, execute commands in an existing container, connect to a remote host or create a stronger virtualized boundary. The name alone does not tell you which files, network paths, credentials or kernel interfaces are reachable.

Strands Shell’s official security model calls it a mediation layer rather than a hardened sandbox. Its boundary applies to operations initiated inside that shell, not unrelated tools registered with the same agent. The SDK’s DockerSandbox adapter executes against an already running container; it does not itself create Docker Sandboxes microVMs. Keep these products and guarantees distinct.

Agent tool request
Chosen execution adapter
Actual process / container / VM boundary
Host and destination permissions

A worked boundary comparison

MechanismWhat to inspectWhat not to assume
Strands ShellBound paths, network policy, credential mediationThat other agent tools inherit its controls
SDK DockerSandboxExisting container, user, mounts, network and host accessThat the adapter creates a microVM
Remote execution adapterRemote identity, host policy and transportThat “remote” implies isolated
Docker Sandboxes productWorkspace mode, microVM, engine and network policyThat shared writable files cannot affect the host

This is a reasoning aid, not a certification table. Follow each product’s current documentation and test the actual deployment configuration. The companion Docker Sandboxes handbook develops the microVM and workspace model in more depth.

Practice: trace a file write

Offline architecture exercise. Draw an agent with two tools: a mediated shell and a direct Python function that writes a local file. The shell is configured to expose only a fixture directory. Where does the direct Python function write?

Expected observation: the shell’s policy does not automatically constrain arbitrary code in another tool. A secure design must review every execution path. Remove the direct writer or place the whole process inside an appropriate execution boundary with scoped mounts and credentials.

Now trace a container adapter that mounts a host project read-write. A write inside the container can change that shared project. Container placement does not make the mount harmless. Use disposable fixtures for tests, and never mount sensitive host directories or the Docker socket merely to make a lesson convenient.

A proposed verification record

{
  "execution_kind": "not_selected",
  "runtime_version": null,
  "workspace_mode": null,
  "allowed_paths": [],
  "allowed_destinations": [],
  "credential_scope": "none",
  "negative_tests": [],
  "status": "design_only"
}

Populate this record only from observed configuration and permitted tests. An empty allowed-destinations list here is a template value, not evidence that a real runtime blocks all egress. Record the test method and result separately from the desired policy.

Troubleshooting and trade-offs

If a command cannot find a file, determine which filesystem it is actually using before broadening mounts. If a network request fails, separate name resolution, routing, policy and application response. If a credential is missing, prefer a scoped integration over copying a broad host environment into the execution process.

Stronger isolation can increase startup cost and operational complexity. Choose it according to the threat model: trusted narrow functions, untrusted generated code and multi-tenant workloads have different needs. State residual risks and avoid describing one successful negative test as proof of complete isolation.

Interview practice

Does adding a safe shell tool constrain every other tool?

No. Its mediation applies to its own operation path. Other tools retain their own permissions and security properties unless a broader process or runtime boundary constrains them.

Why distinguish SDK DockerSandbox from Docker Sandboxes?

The SDK adapter targets an existing container, while Docker Sandboxes is a separate product with its own runtime and workspace model. Similar names do not establish equivalent isolation.

Completion check

Trace one read, write, network call and credential use through the actual boundary. Identify a bypass path created by another tool and redesign it. Keep all runtime experiments disposable and explicitly authorized.

Sources and version notes

Checked 6 October 2026. Python examples target strands-agents==1.58.0 unless labelled otherwise. Live documentation can change; compare your installed version before adapting an example.

YOUR NEXT STEP

Make the understanding yours.

Use the completion check above. Mark this chapter when you can explain the mechanism and its limits.

Self-assessed reading progress. This does not certify that a lab ran or a system is secure.