Running untrusted code or performing browser automation for AI agents on a host system is a security risk. A sandbox function provides a stateful, secure, and isolated execution environment. Each session has its own dedicated function instance, making it ideal for scenarios like code interpreters and browser automation. This topic describes how to create a sandbox function in the Function Compute console.
Before you begin
Sandbox functions are available only in some regions. To view the supported regions, see Sandbox function usage limits. If the current region is not supported, the Sandbox Function tab is not displayed in the function type selection area of the console.
Required
-
Activate Function Compute: Activate the service in the Function Compute console.
-
Service-linked role (SLR): A sandbox function uses the Alibaba Cloud service-linked role (SLR)
AliyunServiceRoleForFC(role name:aliyunserviceroleforfc) to create Function Compute functions and sessions. This role is automatically created and managed by Function Compute, so no manual action is typically required. -
RAM permissions: Ensure that your current user or role has the necessary permissions to create and manage sandbox functions.
Optional (for custom configurations)
-
VPC configuration (required for mounting NAS or PolarFS): Prepare the VPC ID (
vpcId), security group ID (securityGroupId), and vSwitch IDs (vSwitchIds). -
Execution role ARN (required for mounting OSS): Create a RAM role and obtain its ARN.
-
Container Registry (ACR) access (required for using a custom container image): Ensure you have permission to access the ACR repository.
Quick start
This section guides you through creating a sandbox function using all default settings: the Code Interpreter image, 2 vCPU / 4096 MB memory / 512 MB disk, and cookie-based session affinity.
-
Log on to the Function Compute console. In the top navigation bar, select a region that supports sandbox functions, such as China (Hangzhou).
-
In the left navigation bar, select Function Management > Function List, and click Create Function.
-
In the pop-up window for selecting a function type, click the Sandbox Function tab, and then click the Create Sandbox Function button at the bottom.
-
In the image configuration section, the Code Interpreter preset image is selected by default. To use both code execution and browser automation capabilities, switch to the All-in-One image.
-
Enter a Function Name, such as
my-first-sandbox, and leave the other settings at their default values. -
Click Create and wait for the function to be created.
-
After the function is created, you are automatically redirected to the function details page. Click the Session Management tab, click Create Session, and wait for the session status to change to Active.
-
On the session details page, run the following commands in the built-in terminal to verify that the sandbox function is working correctly:
echo 'Hello, FC Sandbox!' python3 -c "print(1 + 1)"
Expected output:
Hello, FC Sandbox!
2
For custom configurations, see Procedure (full configuration).
Procedure (full configuration)
Step 1: Select the function type and enter basic information
-
Log on to the Function Compute console.
-
In the left navigation bar, select Function Management > Function List, and click Create Function.
-
In the function type selection window, click the Sandbox Function tab, and then click the Create Sandbox Function button at the bottom.
-
Enter a Function Name (required): 1 to 64 characters. It must start with a letter or an underscore and can contain letters, digits, underscores (_), and hyphens (-). The name cannot be changed after creation.
After you select the sandbox function type, the system automatically sets the following parameters. These parameters cannot be modified and are not displayed in the console:
|
Parameter |
Auto-set value |
Description |
|
runtime |
custom container |
A sandbox function always runs from a container image. |
|
instance isolation mode |
Session Exclusive ( |
Each session has a dedicated function instance. |
|
instance concurrency ( |
200 |
The maximum number of concurrent requests that a single instance can handle. |
|
session concurrency per instance ( |
1 |
Each instance serves only one session at a time. |
Step 2: Configure instance specifications
In the Auto scaling and instance specification panel, configure the resource specifications for the sandbox instance. A sandbox function has minimum requirements for instance specifications. The console prevents submission if the values are below the minimums.
|
Parameter |
Default |
Minimum |
Available values |
Description |
|
CPU |
2 vCPU |
2 vCPU |
Select from available specifications |
The number of vCPU cores for the sandbox function. |
|
Memory |
4096 MB (4 GB) |
4096 MB |
Select from available specifications |
The memory size for the sandbox function. |
|
Disk size |
512 MB |
— |
512 MB, 10240 MB |
For sandbox scenarios, we recommend selecting 10240 MB to ensure sufficient temporary storage space. |
This panel also includes auto scaling policy settings, where you can configure the number of reserved instances and scheduled scaling rules.
Step 3: Configure container image
In the Code Configuration panel, select an image source. Supported sources include Sample Image, ACR Personal Edition Image, ACR Enterprise Edition Image, Other Public Image, and Custom Image Repository. By default, Sample Image is selected.
The console provides the following pre-built sandbox images (Code Interpreter Sandbox is selected by default):
|
Image name |
Image URL |
Default port |
Description |
|
Code Interpreter Sandbox |
|
5000 |
Supports Python/Node.js code execution. Ideal for AI agent code sandboxes, data analysis, and similar scenarios. |
|
Browser Tool Sandbox |
|
3000 |
A browser automation environment. Suitable for web scraping, taking screenshots, page interactions, and other browser-related tasks. |
|
All-in-One Sandbox |
|
5000 |
Integrates the code interpreter and browser tools. Ideal for scenarios that require both capabilities. |
The pre-built image URL is automatically selected based on the region. The serverless-registry.cn-hangzhou.cr.aliyuncs.com registry is used for regions in the Chinese mainland (Hangzhou, Shanghai, Beijing, and Shenzhen). The serverless-registry.ap-southeast-1.cr.aliyuncs.com registry is used for the Singapore and China (Hong Kong) regions. The current image version is v0.9.30.
This panel also includes the Timeout setting (default: 60 seconds, range: 1 to 86,400 seconds), which defines the timeout for a single request. This is independent of the session lifecycle.
Image selection guide: The first image (Code Interpreter Sandbox) is selected by default. Use Code Interpreter Sandbox for code execution only. Use Browser Tool Sandbox for browser automation only. If you need both capabilities or are unsure, select All-in-One Sandbox. To use your own sandbox image, select ACR or a custom image repository as the image source.
Step 4: Configure session isolation and lifecycle
The session settings for a sandbox function are located in a dedicated Session Isolation and Affinity panel, which is different from the Advanced Configuration collapsible panel used for regular functions.
Instance isolation mode: This is fixed to Session Exclusive (SESSION_EXCLUSIVE) and cannot be modified.
Session affinity: Session affinity is enforced for sandbox functions, and the default is Cookie affinity (GENERATED_COOKIE). The system automatically generates and manages a cookie to identify the session, ensuring that requests from the same session are routed to the same sandbox instance. You can also select Header field affinity (HEADER_FIELD), which uses a custom header field to identify the session. Supported affinity types:
|
Affinity type |
Description |
|
Cookie Affinity (Default) |
Uses a system-generated cookie. No extra configuration is needed. This is suitable for browser access, web applications, and similar scenarios. |
|
Header Field Affinity |
Uses a custom HTTP header for session affinity. You must configure a Header Name that starts with a letter, contains 5 to 40 characters (letters, digits, underscores, and hyphens), and does not start with |
Session lifecycle configuration:
|
Parameter |
Default |
Range |
Description |
|
Session lifecycle ( |
86,400 seconds (24 hours) |
60 to 86,400 seconds |
The maximum lifetime of a session. After this period, the system automatically terminates the session and its bound instance. |
|
Session idle timeout ( |
1,800 seconds (30 minutes) |
60 seconds to the session lifecycle duration |
The period of inactivity before the system automatically terminates an idle session. This value cannot exceed the session's maximum lifetime. |
Step 5: Configure advanced options (optional)
In the Advanced Configuration panel, configure the following options as needed.
RAM role and network
-
RAM role: Select the role the function uses to access other cloud resources.
-
Network configuration: Configure VPC network access to private resources. This is required when mounting NAS or PolarFS.
Storage mounting
A sandbox function supports mounting the following storage types to provide persistent or shared data storage for sandbox instances.
|
Storage type |
Max mount points |
Prerequisites |
|
NAS |
5 |
VPC configuration |
|
OSS |
5 |
execution role ARN |
|
PolarFS |
5 |
VPC configuration |
-
Mounting NAS or PolarFS requires a complete VPC configuration (VPC ID, security group ID, and vSwitch IDs).
-
When you mount NAS and PolarFS simultaneously, their
UserIDandGroupIDmust be identical. -
The
mountDirmust be unique across all mounted storage types.
Observability
-
Log configuration: Configure Log Service to collect function execution logs. Automatic log collection is enabled by default.
-
Tracing: Configure tracing to monitor call chains.
Other configurations
-
Resource group: Select a resource group for resource categorization and permission control.
-
Time zone: Set the runtime time zone for the function. The default is UTC.
-
Environment variables: Configure key-value pairs that can be read as environment variables at runtime.
-
Idle timeout: Set the time after which idle instances are reclaimed.
Step 6: Complete the creation
After you confirm that all configurations are correct, click Create. After the function is successfully created, the system automatically redirects you to the function details page.
Quotas and limits
|
Limit |
Constraint |
|
instance isolation mode |
Fixed to |
|
instance concurrency |
Fixed to 200 and cannot be modified. |
|
session concurrency per instance |
Fixed to 1 and cannot be modified. |
|
Number of mount points |
A maximum of 5 mount points for each storage type. The |
|
Function name |
1 to 64 characters. Must start with a letter or an underscore. |
|
Timeout |
1 to 86,400 seconds |
|
Single Session Lifecycle |
60 to 86,400 seconds |
|
Session idle timeout |
60 seconds to the configured session lifecycle duration |