we_are_coded.by CODE · The world, decoded
БГ
Google Cloud

Google released a sandbox for agent-written code, with the network closed by default

Google Cloud BlogInfra

Cloud Run sandboxes entered public preview on July 10. You run code written by an AI agent, and it doesn't touch the rest of your system. What matters is in the default: zero outbound network access, zero visibility into the service's keys.

In short
  • Cloud Run sandboxes entered public preview on July 10, 2026, announced at the WeAreDevelopers World Congress.
  • By default: zero outbound network access and no visibility into the service's environment variables and metadata.
  • They start in milliseconds on the service's already-allocated CPU and memory, at no extra charge.
Checked on11 July 2026Responsible editorTsvetelin IvanovHow we workMethod · Corrections

Google announced Cloud Run (Google's hosting service) sandboxes - a room where you run code written by an AI agent, without it reaching the rest of your system. The announcement's headline says it plainly: how to safely run code generated by AI.

The facts: by default the sandbox has zero outbound network access. According to Google, if the agent is tricked into running a script that tries to exfiltrate data to an outside server, the request is blocked at the system level; outbound access can be allowed explicitly. The second mechanism is credentials: the environment has no access to either the service's own environment variables or Google Cloud's metadata server, meaning the agent's code doesn't see your keys. The sandbox starts in milliseconds on the service's already-allocated CPU and memory, with no separate infrastructure and no extra charge; Google's example is 1000 sandboxes with an average latency of 500 milliseconds. The three scenarios the company describes: a model that writes and runs code for data analysis; an agent that drives a headless browser and automates; and executing code uploaded by your platform's users.

Here's the value - in the order things are arranged. Closed by default and opened deliberately, not the other way around. Until now, everyone drew this boundary themselves, with manual rules and attention to how far the keys reach. Now a big cloud provider hands it over ready-made, without charging for it. The admission inside the product is more interesting than the feature itself: code an agent writes is treated as untrusted code.

The code an agent writes is now officially somebody else's code.

The landing is practical. If agents write code for you - for analysis, for a headless browser, for third-party plugins - this is the protection you'd otherwise have to build yourself. Just don't take it on faith. Preview isn't production. Check exactly what's allowed in your configuration, and try to exfiltrate a file from the sandbox yourself before you believe it can't be done.

The visual is generated code art. No third-party images.
Follow usFacebookLinkedIn
Official primary sources
→Google Cloud Blog
Original: https://wearecoded.com/en/articles/google-cloud-run-sandboxes.html
ShareFacebookXLinkedInTelegramWhatsApp
← Back to all news