History
- Aug 6, 2026Volumes attach to environments directly.
- Aug 3, 2026The agent runtime moved onto the environment — leaving it unset makes an environment sandbox-only.
How ready are your agents for a bad day? Get your scoreHow ready are your AI agents for a bad day? Get your security readiness score in 2 minutes.
Get my score →One definition of a runtime — image, tools, secrets, egress — that agents and sandboxes both run.
Introduced Jul 16, 2026 · updated Aug 6, 2026
An agent runs in an environment; a sandbox runs the same one. What an engineer tries by hand and what runs unattended are the same thing.
ram-2gb from the runner's catalog, not a YAML block — resolved when the workload starts. Image tags resolve at start too, so pushing a new build rolls out on the next run.
Leave the agent runtime unset and the environment hosts sandboxes but never an agent — the mistake fails at write time, not in production at night.
internal opens the environment to the whole organization; private only to identities you grant. Running in one reaches its secrets, egress credentials, and volumes — so who may run is a real decision.
Thirty minutes, your infrastructure, your stack. Or skip the call — it is one Helm release onto a cluster you already run.