Skip to content

Releases: TencentCloud/CubeSandbox

v0.7.2

Choose a tag to compare

@fslongjin fslongjin released this 24 Sep 06:20
f1aaa73

2026.09.24 Release v0.7.2

CubeSandbox 0.7.2 introduces 3 major features along with multiple enhancements and bug fixes. 56 commits from 29 contributors.

🎯 Major Features

Much faster cross-node restore reads

Sandboxes restored cross-node on the S3 backend read disk data from S3 on demand; this release optimizes that read path systematically:

  • New whole-object local cache: immutable data objects on S3 are kept on the local node, so repeated reads after a restore — and re-importing the same snapshot — hit the local cache instead of going back to S3.
  • Reduced read amplification during restore: scattered small reads are coalesced into whole-object GETs, and the concurrent fetch budget is capped.
  • With the default MinIO setup, cross-node restore / create-from-snapshot reaches running in under 1 second.

New JuiceFS volume plugin

New JuiceFS storage plugin: sandboxes can mount a JuiceFS filesystem as a persistent volume, with full POSIX semantics.

Automatic reclaim of idle guest memory

Idle memory inside sandboxes is reclaimed back to the host: node memory usage falls back dynamically with the real usage of the sandboxes, so a single node can host more sandboxes.

✨ Enhancements

Templates & Storage

  • S3lvol hot upgrade: fixes the EIO errors seen inside sandboxes when upgrading the CubeS3lvol storage component.
  • Local-filesystem storage for component repositories and template artifacts (#1749): component repositories and template artifacts can be stored on S3 / local disk / PVC / NFS.
  • Incremental snapshot fix (#1343): fixed data loss in incremental snapshots.
  • Faster virtiofs on the pause / snapshot path (#1748): optimized the state preparation flow before pause.
  • Cubelet can configure the template install path, allowing large templates to be moved to the data disk (#1675).
  • CubeS3lvol object cache: identical objects read during a cross-node restore are served from the local object cache first, and the object cache and dest cache share the same local cache storage (#1756).

Lifecycle & Control Plane

  • sandbox.connect supports a timeout parameter (#1352).

Deployment & Runtime

  • cube-node now runs on the host network by default in K8s deployments (#1815): recreating the cube-node Pod no longer destroys the network namespace, so the network of every sandbox on the node stays up. Switching an existing cluster requires draining compute nodes and explicit confirmation (hostNetworkChangeAck); fresh installs are unaffected.
  • Faster sandbox cold start (#1694): disabled the RAID6 PQ startup benchmark in the guest kernel, which is unrelated to workloads.

Web UI / CubeOps / Other

  • Removed the legacy E2B SDK reference; Python SDK command execution now goes through the envd Connect RPC (#1786).
  • The Python SDK's run_code (E2B-compatible code-interpreter interface) can now read environment variables injected at sandbox creation (#1323), matching the behavior of commands.run; the new sandbox-code example image is required.

🐛 Bug Fixes

Lifecycle & Sandbox

  • Fixed inconsistent memory-snapshot and image-snapshot state when building a template (#1760).
  • Fixed existing snapshots becoming unusable after a template was deleted (#1763).
  • Fixed a race where concurrent image builds left tasks stuck in BUILT with database connection timeouts (#1802).
  • Fixed snapshot creation retries being rejected as a changed request body (#1253).
  • Fixed paused sandboxes not returning a timeout (end_at=0) in Info / List queries (#1801).
  • Fixed an explicit timeout passed to Connect not taking effect for already-running sandboxes; a shorter timeout no longer shortens an existing longer deadline, and the Python SDK now passes the parameter through (#1352).
  • Fixed PVM detection: the upstream PVM ABI removed the CPUID signature, so detection now relies on the MSR list supported by KVM, compatible with both old and new ABIs (#1781).
  • Fixed a kernel panic when PVM guests booted on Intel hosts because GMI sm3/sm4 probing was misdetected (#1725).
  • Fixed resume failing after pause on ARM (Could not restore GICv3ITS state): the vgic state save was incorrectly optimized to all zeros by the compiler (#1658).

Networking & Security

  • Fixed sandboxes having a guest MTU larger than the node uplink NIC under overlay CNI, which left the network broken out of the box: guest MTU now follows the node NIC automatically (it only decreases), and can be pinned with cubeNode.network.mtu (#1674).

Deployment & Upgrade

  • Fixed the CUBE_SANDBOX_CUBE_EGRESS_IMAGE environment variable not being updated in .one-click.env for one-click deployments (#1788).
  • Fixed CubeOps failing to connect when the MySQL password contains special characters; invalid configuration now fails at startup (#1617).
  • Fixed one-click install failing silently on snap-packaged Docker; it now tells users to switch to docker-ce (#1789).
  • Fixed inconsistent Redis logical-DB configuration across components in one-click deployments, which made CubeOps write metrics to the wrong database (#1705).
  • Fixed PVM installation failing on Ubuntu (#1770).
  • Fixed the template artifact cache not being movable to the data disk on its own (#1675).
  • Fixed CubeS3lvol being pinned to CPU0/CPU1 by default; another CPU is now picked automatically when unconfigured (#1713).

Other

  • Fixed PostgreSQL template-alias duplicate errors being misclassified by error text and occasional template status publish failures; classification now uses SQLSTATE (#1724).
  • Fixed compatibility issues in the cubebench CPU topology report (#1757).
  • Added an Ubuntu desktop sandbox example and integration guide (#1746).
  • Added an OpenCode integration: a plugin hook redirects bash into the sandbox so commands no longer run directly on the developer's machine (#1238).
  • Added a CI status page (#1737).
  • Corrected the PVM expansion: Pagetable-based, not Parallel (#1772).
  • Added a documentation security warning: injecting credentials over HTTP is unsafe, limited to controlled internal networks; prefer HTTPS (#1818).

v0.7.2-rc3

v0.7.2-rc3 Pre-release
Pre-release

Choose a tag to compare

@fslongjin fslongjin released this 24 Sep 03:28
0a0d45f

v0.7.2-rc3

v0.7.2-rc2

v0.7.2-rc2 Pre-release
Pre-release

Choose a tag to compare

@fslongjin fslongjin released this 23 Sep 04:03
e31abac

v0.7.2-rc2

v0.7.2-rc1

v0.7.2-rc1 Pre-release
Pre-release

Choose a tag to compare

@fslongjin fslongjin released this 21 Sep 15:26
285b812

v0.7.2-rc1

kernel-release-260921-1

Choose a tag to compare

@github-actions github-actions released this 21 Sep 14:23
dcb2dcb

Dedicated kernel assets release (BM + PVM guest + PVM host).

v0.7.1

Choose a tag to compare

@fslongjin fslongjin released this 11 Sep 09:51
31d911e

2026.09.11 Release v0.7.1

CubeSandbox 0.7.1 introduces 1 major feature along with multiple enhancements and bug fixes. 70 commits from 24 contributors.

🎯 Major Features

End-to-end high availability for Cube control-plane services

  • A standalone template-center service enables multi-replica CubeMaster deployment.
  • The lifecycle management service now supports active/standby deployment.

✨ Enhancements

Templates & Storage

  • Snapshot support for Host Mount and Volume Plugin: snapshot, restore, rollback, and clone now work for sandboxes with external mounts (#1654, #1656).
  • Standalone CubeTemplateCenter: template build / delete / reclaim is split out of CubeMaster into an independently scalable multi-replica service. Build artifacts are persisted to S3/MinIO (AWS S3 compatible). Also fixes long-standing issues around concurrent build races, inconsistent artifact table names, and ephemeral local-disk storage (#1659).
  • Faster same-bucket cross-node snapshot restore (#1663): restoring a snapshot from the same bucket now uses object-storage server-side copy, which is significantly faster. Also improves delayed-delete reclamation and adds snapshot cancellation.

Lifecycle & Control Plane

  • CLM now supports active/standby disaster recovery.
  • Running sandboxes no longer block snapshot deletion (#1620): deleting a still-referenced snapshot takes effect immediately; underlying storage is reclaimed after the last reference is released.

Security

  • virtiofsd hardening (#1612): after a directory whitelist is set, root-directory mutation operations are rejected, as are forged readdirplus requests.

Deployment & Runtime

  • CubeS3lvol on Kubernetes (#1637): use the S3 backend for cross-node pause/resume and snapshots in K8s deployments.
  • One-click deployment supports external PostgreSQL (#1644): choose MySQL / PostgreSQL via CUBE_DATABASE_DRIVER and connect to a self-managed database instance.
  • CubeS3lvol is now opt-in (#1622, #1633): set [cow.s3] enable = true (or ONE_CLICK_ENABLE_S3LVOL=1 for one-click deploy); it is disabled by default. Also fixes the switch not taking effect during one-click upgrades. Upgrade note: nodes that were using S3 without an explicit setting must enable it after upgrade.
  • Unified Helm Redis logical-DB config (#1638): new top-level redis.db applies to CubeMaster / CubeProxy / CLM, so multiple clusters sharing one Redis instance can isolate logical databases per cluster.

Web UI / CubeOps / Other

  • cubemastercli batch template deletion (#1549): tpl delete accepts multiple template IDs in one call.

🐛 Bug Fixes

Lifecycle & Sandbox

  • Fixed sandboxes set to never expire (NEVER_TIMEOUT) being immediately treated as expired (#1401).
  • Fixed invalid CPU / memory specs in create requests being treated as 0, allowing sandboxes to bypass node resource filters and be scheduled onto any node (#1463).
  • Fixed a new timeout passed on Resume being discarded, so the sandbox kept its pre-pause timeout (#862).
  • Fixed snapshots after an S3-backend restore falling back to a full memory dump; snapshots stay incremental (#1688).
  • Fixed no log output from cubecli logs for sandboxes created from a template (#1616).
  • Fixed template creation hanging indefinitely when a compute node is unresponsive; added a configurable timeout (default 300 seconds) (#994).
  • Fixed gRPC connections not being closed promptly after a node is taken offline or deleted (#1585).
  • Fixed S3 volume mount failures with newer s3fs (1.97+ / FUSE3) (#1647).

Networking & Security

  • Fixed the transparent proxy returning 504 after 60 seconds when talking to slow-TTFB upstreams such as LLMs; proxy send/receive timeout is now 2 hours (#1655).
  • Fixed CubeEgress failures caused by oversized credential values injected via network rules; the per-entry injection limit is aligned with E2B at 2048 bytes (#1606).
  • Fixed TAP device names silently truncated past the kernel length limit, causing network device lookup failures (#1552).
  • Fixed intermittent Cubelet network-plugin init failures on K8s when the gateway ARP cache is not ready early in node startup (#1609).
  • Image-registry credentials no longer appear in component logs (#1600).

Deployment & Upgrade

  • Fixed Helm upgrades failing because Redis StatefulSet PVC labels changed (#1604).
  • Fixed global.imageRegistry overwriting explicitly configured private / third-party registry addresses (#1605).
  • Fixed helm test pods remaining Pending on tainted nodes (#1388).
  • Fixed Terraform deployments skipping validation and template creation when node queries returned 0 healthy nodes (#1602).
  • Fixed CubeOps ignoring the logical-DB number when using a standalone Redis config, which hid node metrics and caused scheduling-metric update timeouts (#1607).
  • Fixed lowercase log-level values (e.g. info) not taking effect and falling back to DEBUG (#1597).
  • Fixed builder image builds failing on Ubuntu 20.04 (#1588).

Other

  • Node / Python SDK: fixed command execution never returning when timeout is 0 or NEVER_TIMEOUT (#1485).
  • Fixed cubeopscli reporting a hardcoded 0.1.0 version and the version subcommand being unavailable (#1596).
  • Fixed cubemastercli version producing no output by default (#1657).
  • Fixed the Web UI runtime config page showing deprecated settings (#1573).

v0.7.1-rc2

v0.7.1-rc2 Pre-release
Pre-release

Choose a tag to compare

@fslongjin fslongjin released this 11 Sep 02:45
5e9c2e0

v0.7.1-rc2

v0.7.1-rc1

v0.7.1-rc1 Pre-release
Pre-release

Choose a tag to compare

@fslongjin fslongjin released this 09 Sep 03:13
62da018

v0.7.1-rc1

v0.7.0

Choose a tag to compare

@fslongjin fslongjin released this 28 Aug 07:45
d008164

2026.08.28 Release v0.7.0

CubeSandbox 0.7.0 introduces 4 major features along with multiple enhancements and bug fixes. 239 commits from 57 contributors.

🎯 Major Features

Cross-Node Pause & Resume

With an S3 backend, sandboxes support pause/resume across nodes as well as creating sandboxes from snapshots. This feature is currently in preview.

Component Multi-Versioning

  • Newly created templates and snapshots now record the versions of the components they depend on. After components on compute nodes are upgraded, historical templates and snapshots remain usable, and upgrades no longer affect pause/resume of existing instances — improving stability for running workloads.

Network Subsystem Refactor: Faster Sandbox Network Provisioning

  • Architecture: fewer components to deploy — the network-agent component is merged into Cubelet, reducing inter-process RPC calls during sandbox creation; TAP device lifecycle management is redesigned to prevent network rules from leaking across sandboxes, reducing attack surface.
  • Performance: optimized the eBPF network policy provisioning path, significantly reducing sandbox creation latency for sandboxes with network rules; removed unnecessary netlink dump operations so that creating new TAP devices under high concurrency remains stable when idle TAP devices are exhausted.

Separation of Control Plane and Operations

Architecturally, operations capabilities are split out of CubeMaster. Node management logic now lives in CubeOps, which supports multi-replica deployment and ships the cubeopscli tool.

✨ Enhancements

Templates & Storage

  • CubeS3lvol COW (#1490): besides the local XFS COW engine, cubecow now supports remote snapshot storage on S3 object storage, enabling cross-node pause/resume and snapshot cloning.
  • Private HTTP image registry support (#1369): pull images from HTTP image registries to build templates.
  • Built-in MinIO as the default S3 volume backend (#1408): MinIO is deployed by default as the S3 backend for the volume feature and cross-node pause/resume. Users can also specify their own S3 backend.

Lifecycle & Control Plane

  • Node deletion (#1202): support removing a node from the cluster so it no longer participates in scheduling.

Networking & Security Proxy

  • Network subsystem refactor: NetworkAgent is fully embedded into Cubelet, streamlining the network provisioning flow.
  • Support dynamically updating network policies for running sandboxes.
  • CubeEgress L7 forwarding rules now support custom ports.
  • CubeVS learns MAC addresses within the same subnet, avoiding black-holed traffic in non-hairpin networks.
  • CubeProxy supports a custom management port and the gRPC protocol.

SDK

  • Volume support: the Go (#1269) and Node (#1277) SDKs add Volume CRUD and volumeMounts, bringing all three languages to parity.
  • Full template alias support: build-time aliases (#1119) and alias management for existing templates (#1120), covering Go / Node / Python.
  • Go SDK user-level file view (#1348): Files.ForUser isolates file access by user identity.
  • Node SDK runtime timeout (#1251): Sandbox.setTimeout(timeout) supports NEVER_TIMEOUT.
  • Python SDK sandbox scheduling scope (#1144): Sandbox.create(distribution_scope=...) explicitly specifies the nodes/zones a sandbox can be placed on.
  • Go SDK private sandbox dataplane fix (#1185): RunCode / Commands / Files / PTY now correctly pass through the TrafficAccessToken.
  • Node SDK auth header fix (#1360): an Authorization header explicitly set by the caller (including lowercase variants) is no longer overridden by the SDK's default apiKey.
  • Clone snapshot deferred cleanup across all three SDKs (#1095): reference counting ensures the temporary snapshot is deleted only after all clones are destroyed.

Deployment & Runtime

  • Configurable log rotation policy (#1339): users can adjust cubelet's log rotation policy via the configuration file.
  • Kernel / guest images published as separate artifacts (#1324): releases no longer rebuild the kernel and guest images; fixed versions are pulled from dedicated kernel-release-* / guest-image-* releases.

Web UI / CubeOps / Other

  • CubeOps: node management moved into this module; new cubeopscli tool for node management, replacing the cubemastercli node subcommands; two-replica deployment supported by default (#1384, #1494).
  • Web UI: node isolation/unisolation and node operation history viewing (#1384).

🐛 Bug Fixes

Lifecycle & Sandbox

  • Fixed sandbox state inconsistency, zombie processes, and deletion failures caused by failed pause/resume (#978, #985, #1137, #1274).
  • Fixed snapshot performance issues (#1300, #1504).
  • Fixed a template cache data race during concurrent sandbox creation (#1366).

Networking & Security

  • Fixed sandbox state anomalies caused by TAP device recovery failures during pause/resume and node restarts (#930, #987, #1207).

Other

  • Fixed log rotation configuration not taking effect (#1289).
  • Expanded the Python SDK compatibility end-to-end tests with coverage for the filesystem, rollback & cloning, online timeout updates, abnormal lifecycles, and advanced template parameters (#1226).

📚 Documentation

  • New K8s deployment guide covering compute-node cube-node rebuild constraints and hostNetwork guidance (#1495).
  • Community pages (#1344, #1364): sponsors and contributors wall added to the README.

v0.7.0-rc2

v0.7.0-rc2 Pre-release
Pre-release

Choose a tag to compare

@fslongjin fslongjin released this 27 Aug 11:50
5d7e323

v0.7.0-rc2