Register the workspace
The handler registers a sandbox with a checkpoint policy:E2BResource
implements three operations:
create(checkpoint_ref=None)creates a sandbox from the selected snapshot or a fresh checkout, and configures its Git branch.open(binding)connects to the sandbox ID recorded for this execution.checkpoint(handle)creates a snapshot and replaces the handle’s client, since E2B snapshots drop active connections.
on_timeout: "pause" preserves the sandbox when a worker dies. Missing
sandboxes or selected snapshots fail the execution.
Wrap the tools
shell and write_file declare workspace changes. read_file uses the default
of none:
shell to commit and push the branch. These tools use
safe_to_retry, so an interrupted command can run again. See
idempotency when adding commands with effects
that must not repeat.
Keep credentials out of the sandbox
Cloning and pushing need a GitHub token. The driver adds a network rule that sets theAuthorization header on requests to github.com at E2B’s egress
proxy:
github.com, so the sandbox can push a branch but cannot
use that token to call the API. Protect the default branch with a GitHub ruleset
that requires a pull request.
Pause while waiting
The handler pauses the workspace when the model loop finishes or waits for approval:execution().suspension because a framework can catch Blocked
inside its loop. After approval, the next dispatch replays up to the held call
and the driver opens the same sandbox. A dispatch superseded by another worker
leaves the sandbox running for that worker. A completion checkpoint briefly
resumes a paused sandbox and pauses it again after capture.
Sessions
The handler reads the previous completed turn withprevious() and returns its
conversation in Result.state:
Fork the workspace
Write the policy
Run it
examples/integrations/sandbox/e2b
has the full agent, resource driver, policy, and dev kernel config.
Set E2B_API_KEY, REPO (the repository as owner/name), GITHUB_TOKEN,
LLM_MODEL, LLM_BASE_URL, and LLM_API_KEY. The token needs read and write
access to the repository’s contents and pull requests. Start the kernel and
agent from that directory:
open_pr call appears in rebuno exec watch. See
Approvals to approve it. Continue the same session with:
lease_timeout_seconds sets a shorter lease for the agent.