All Products
Search
Document Center

:Create a sandbox function

Last Updated:Aug 22, 2026

Running untrusted code or performing browser automation for AI agents on a host system is a security risk. A sandbox function provides a stateful, secure, and isolated execution environment. Each session has its own dedicated function instance, making it ideal for scenarios like code interpreters and browser automation. This topic describes how to create a sandbox function in the Function Compute console.

Before you begin

Important

Sandbox functions are available only in some regions. To view the supported regions, see Sandbox function usage limits. If the current region is not supported, the Sandbox Function tab is not displayed in the function type selection area of the console.

Required

  1. Activate Function Compute: Activate the service in the Function Compute console.

  2. Service-linked role (SLR): A sandbox function uses the Alibaba Cloud service-linked role (SLR) AliyunServiceRoleForFC (role name: aliyunserviceroleforfc) to create Function Compute functions and sessions. This role is automatically created and managed by Function Compute, so no manual action is typically required.

  3. RAM permissions: Ensure that your current user or role has the necessary permissions to create and manage sandbox functions.

Optional (for custom configurations)

  • VPC configuration (required for mounting NAS or PolarFS): Prepare the VPC ID (vpcId), security group ID (securityGroupId), and vSwitch IDs (vSwitchIds).

  • Execution role ARN (required for mounting OSS): Create a RAM role and obtain its ARN.

  • Container Registry (ACR) access (required for using a custom container image): Ensure you have permission to access the ACR repository.

Quick start

This section guides you through creating a sandbox function using all default settings: the Code Interpreter image, 2 vCPU / 4096 MB memory / 512 MB disk, and cookie-based session affinity.

  1. Log on to the Function Compute console. In the top navigation bar, select a region that supports sandbox functions, such as China (Hangzhou).

  2. In the left navigation bar, select Function Management > Function List, and click Create Function.

  3. In the pop-up window for selecting a function type, click the Sandbox Function tab, and then click the Create Sandbox Function button at the bottom.

  4. In the image configuration section, the Code Interpreter preset image is selected by default. To use both code execution and browser automation capabilities, switch to the All-in-One image.

  5. Enter a Function Name, such as my-first-sandbox, and leave the other settings at their default values.

  6. Click Create and wait for the function to be created.

  7. After the function is created, you are automatically redirected to the function details page. Click the Session Management tab, click Create Session, and wait for the session status to change to Active.

  8. On the session details page, run the following commands in the built-in terminal to verify that the sandbox function is working correctly:

    echo 'Hello, FC Sandbox!'
    python3 -c "print(1 + 1)"

Expected output:

Hello, FC Sandbox!
2

For custom configurations, see Procedure (full configuration).

Procedure (full configuration)

Step 1: Select the function type and enter basic information

  1. Log on to the Function Compute console.

  2. In the left navigation bar, select Function Management > Function List, and click Create Function.

  3. In the function type selection window, click the Sandbox Function tab, and then click the Create Sandbox Function button at the bottom.

  4. Enter a Function Name (required): 1 to 64 characters. It must start with a letter or an underscore and can contain letters, digits, underscores (_), and hyphens (-). The name cannot be changed after creation.

After you select the sandbox function type, the system automatically sets the following parameters. These parameters cannot be modified and are not displayed in the console:

Parameter

Auto-set value

Description

runtime

custom container

A sandbox function always runs from a container image.

instance isolation mode

Session Exclusive (SESSION_EXCLUSIVE)

Each session has a dedicated function instance.

instance concurrency (instanceConcurrency)

200

The maximum number of concurrent requests that a single instance can handle.

session concurrency per instance (sessionConcurrencyPerInstance)

1

Each instance serves only one session at a time.

Step 2: Configure instance specifications

In the Auto scaling and instance specification panel, configure the resource specifications for the sandbox instance. A sandbox function has minimum requirements for instance specifications. The console prevents submission if the values are below the minimums.

Parameter

Default

Minimum

Available values

Description

CPU

2 vCPU

2 vCPU

Select from available specifications

The number of vCPU cores for the sandbox function.

Memory

4096 MB (4 GB)

4096 MB

Select from available specifications

The memory size for the sandbox function.

Disk size

512 MB

—

512 MB, 10240 MB

For sandbox scenarios, we recommend selecting 10240 MB to ensure sufficient temporary storage space.

Note

This panel also includes auto scaling policy settings, where you can configure the number of reserved instances and scheduled scaling rules.

Step 3: Configure container image

In the Code Configuration panel, select an image source. Supported sources include Sample Image, ACR Personal Edition Image, ACR Enterprise Edition Image, Other Public Image, and Custom Image Repository. By default, Sample Image is selected.

The console provides the following pre-built sandbox images (Code Interpreter Sandbox is selected by default):

Image name

Image URL

Default port

Description

Code Interpreter Sandbox

serverless-registry.ap-southeast-1.cr.aliyuncs.com/functionai/sandbox-code-interpreter:v0.9.30

5000

Supports Python/Node.js code execution. Ideal for AI agent code sandboxes, data analysis, and similar scenarios.

Browser Tool Sandbox

serverless-registry.ap-southeast-1.cr.aliyuncs.com/functionai/sandbox-browser-tool:v0.9.30

3000

A browser automation environment. Suitable for web scraping, taking screenshots, page interactions, and other browser-related tasks.

All-in-One Sandbox

serverless-registry.ap-southeast-1.cr.aliyuncs.com/functionai/sandbox-all-in-one:v0.9.30

5000

Integrates the code interpreter and browser tools. Ideal for scenarios that require both capabilities.

Note

The pre-built image URL is automatically selected based on the region. The serverless-registry.cn-hangzhou.cr.aliyuncs.com registry is used for regions in the Chinese mainland (Hangzhou, Shanghai, Beijing, and Shenzhen). The serverless-registry.ap-southeast-1.cr.aliyuncs.com registry is used for the Singapore and China (Hong Kong) regions. The current image version is v0.9.30.

This panel also includes the Timeout setting (default: 60 seconds, range: 1 to 86,400 seconds), which defines the timeout for a single request. This is independent of the session lifecycle.

Note

Image selection guide: The first image (Code Interpreter Sandbox) is selected by default. Use Code Interpreter Sandbox for code execution only. Use Browser Tool Sandbox for browser automation only. If you need both capabilities or are unsure, select All-in-One Sandbox. To use your own sandbox image, select ACR or a custom image repository as the image source.

Step 4: Configure session isolation and lifecycle

The session settings for a sandbox function are located in a dedicated Session Isolation and Affinity panel, which is different from the Advanced Configuration collapsible panel used for regular functions.

Instance isolation mode: This is fixed to Session Exclusive (SESSION_EXCLUSIVE) and cannot be modified.

Session affinity: Session affinity is enforced for sandbox functions, and the default is Cookie affinity (GENERATED_COOKIE). The system automatically generates and manages a cookie to identify the session, ensuring that requests from the same session are routed to the same sandbox instance. You can also select Header field affinity (HEADER_FIELD), which uses a custom header field to identify the session. Supported affinity types:

Affinity type

Description

Header Field Affinity

Uses a custom HTTP header for session affinity. You must configure a Header Name that starts with a letter, contains 5 to 40 characters (letters, digits, underscores, and hyphens), and does not start with x-fc-. This is suitable for API calls, SDK integrations, and other server-side scenarios.

Session lifecycle configuration:

Parameter

Default

Range

Description

Session lifecycle (sessionTTLInSeconds)

86,400 seconds (24 hours)

60 to 86,400 seconds

The maximum lifetime of a session. After this period, the system automatically terminates the session and its bound instance.

Session idle timeout (sessionIdleTimeoutInSeconds)

1,800 seconds (30 minutes)

60 seconds to the session lifecycle duration

The period of inactivity before the system automatically terminates an idle session. This value cannot exceed the session's maximum lifetime.

Step 5: Configure advanced options (optional)

In the Advanced Configuration panel, configure the following options as needed.

RAM role and network

  • RAM role: Select the role the function uses to access other cloud resources.

  • Network configuration: Configure VPC network access to private resources. This is required when mounting NAS or PolarFS.

Storage mounting

A sandbox function supports mounting the following storage types to provide persistent or shared data storage for sandbox instances.

Storage type

Max mount points

Prerequisites

NAS

5

VPC configuration

OSS

5

execution role ARN

PolarFS

5

VPC configuration

Important
  • Mounting NAS or PolarFS requires a complete VPC configuration (VPC ID, security group ID, and vSwitch IDs).

  • When you mount NAS and PolarFS simultaneously, their UserID and GroupID must be identical.

  • The mountDir must be unique across all mounted storage types.

Observability

  • Log configuration: Configure Log Service to collect function execution logs. Automatic log collection is enabled by default.

  • Tracing: Configure tracing to monitor call chains.

Other configurations

  • Resource group: Select a resource group for resource categorization and permission control.

  • Tags: Add tags to classify and manage the function.

  • Time zone: Set the runtime time zone for the function. The default is UTC.

  • Environment variables: Configure key-value pairs that can be read as environment variables at runtime.

  • Idle timeout: Set the time after which idle instances are reclaimed.

Step 6: Complete the creation

After you confirm that all configurations are correct, click Create. After the function is successfully created, the system automatically redirects you to the function details page.

Quotas and limits

Limit

Constraint

instance isolation mode

Fixed to SESSION_EXCLUSIVE and cannot be modified.

instance concurrency

Fixed to 200 and cannot be modified.

session concurrency per instance

Fixed to 1 and cannot be modified.

Number of mount points

A maximum of 5 mount points for each storage type. The mountDir must be unique.

Function name

1 to 64 characters. Must start with a letter or an underscore.

Timeout

1 to 86,400 seconds

Single Session Lifecycle

60 to 86,400 seconds

Session idle timeout

60 seconds to the configured session lifecycle duration