Repository navigation
Releases: TencentCloud/CubeSandbox
Release list
v0.7.2
2026.09.24 Release v0.7.2
CubeSandbox 0.7.2 introduces 3 major features along with multiple enhancements and bug fixes. 56 commits from 29 contributors.
🎯 Major Features
Much faster cross-node restore reads
Sandboxes restored cross-node on the S3 backend read disk data from S3 on demand; this release optimizes that read path systematically:
- New whole-object local cache: immutable data objects on S3 are kept on the local node, so repeated reads after a restore — and re-importing the same snapshot — hit the local cache instead of going back to S3.
- Reduced read amplification during restore: scattered small reads are coalesced into whole-object GETs, and the concurrent fetch budget is capped.
- With the default MinIO setup, cross-node restore / create-from-snapshot reaches running in under 1 second.
New JuiceFS volume plugin
New JuiceFS storage plugin: sandboxes can mount a JuiceFS filesystem as a persistent volume, with full POSIX semantics.
Automatic reclaim of idle guest memory
Idle memory inside sandboxes is reclaimed back to the host: node memory usage falls back dynamically with the real usage of the sandboxes, so a single node can host more sandboxes.
✨ Enhancements
Templates & Storage
- S3lvol hot upgrade: fixes the EIO errors seen inside sandboxes when upgrading the CubeS3lvol storage component.
- Local-filesystem storage for component repositories and template artifacts (#1749): component repositories and template artifacts can be stored on S3 / local disk / PVC / NFS.
- Incremental snapshot fix (#1343): fixed data loss in incremental snapshots.
- Faster virtiofs on the pause / snapshot path (#1748): optimized the state preparation flow before pause.
- Cubelet can configure the template install path, allowing large templates to be moved to the data disk (#1675).
- CubeS3lvol object cache: identical objects read during a cross-node restore are served from the local object cache first, and the object cache and dest cache share the same local cache storage (#1756).
Lifecycle & Control Plane
sandbox.connectsupports atimeoutparameter (#1352).
Deployment & Runtime
- cube-node now runs on the host network by default in K8s deployments (#1815): recreating the cube-node Pod no longer destroys the network namespace, so the network of every sandbox on the node stays up. Switching an existing cluster requires draining compute nodes and explicit confirmation (
hostNetworkChangeAck); fresh installs are unaffected. - Faster sandbox cold start (#1694): disabled the RAID6 PQ startup benchmark in the guest kernel, which is unrelated to workloads.
Web UI / CubeOps / Other
- Removed the legacy E2B SDK reference; Python SDK command execution now goes through the
envdConnect RPC (#1786). - The Python SDK's
run_code(E2B-compatible code-interpreter interface) can now read environment variables injected at sandbox creation (#1323), matching the behavior ofcommands.run; the new sandbox-code example image is required.
🐛 Bug Fixes
Lifecycle & Sandbox
- Fixed inconsistent memory-snapshot and image-snapshot state when building a template (#1760).
- Fixed existing snapshots becoming unusable after a template was deleted (#1763).
- Fixed a race where concurrent image builds left tasks stuck in
BUILTwith database connection timeouts (#1802). - Fixed snapshot creation retries being rejected as a changed request body (#1253).
- Fixed paused sandboxes not returning a timeout (
end_at=0) in Info / List queries (#1801). - Fixed an explicit timeout passed to Connect not taking effect for already-running sandboxes; a shorter timeout no longer shortens an existing longer deadline, and the Python SDK now passes the parameter through (#1352).
- Fixed PVM detection: the upstream PVM ABI removed the CPUID signature, so detection now relies on the MSR list supported by KVM, compatible with both old and new ABIs (#1781).
- Fixed a kernel panic when PVM guests booted on Intel hosts because GMI sm3/sm4 probing was misdetected (#1725).
- Fixed resume failing after pause on ARM (
Could not restore GICv3ITS state): the vgic state save was incorrectly optimized to all zeros by the compiler (#1658).
Networking & Security
- Fixed sandboxes having a guest MTU larger than the node uplink NIC under overlay CNI, which left the network broken out of the box: guest MTU now follows the node NIC automatically (it only decreases), and can be pinned with
cubeNode.network.mtu(#1674).
Deployment & Upgrade
- Fixed the
CUBE_SANDBOX_CUBE_EGRESS_IMAGEenvironment variable not being updated in.one-click.envfor one-click deployments (#1788). - Fixed CubeOps failing to connect when the MySQL password contains special characters; invalid configuration now fails at startup (#1617).
- Fixed one-click install failing silently on snap-packaged Docker; it now tells users to switch to
docker-ce(#1789). - Fixed inconsistent Redis logical-DB configuration across components in one-click deployments, which made CubeOps write metrics to the wrong database (#1705).
- Fixed PVM installation failing on Ubuntu (#1770).
- Fixed the template artifact cache not being movable to the data disk on its own (#1675).
- Fixed CubeS3lvol being pinned to CPU0/CPU1 by default; another CPU is now picked automatically when unconfigured (#1713).
Other
- Fixed PostgreSQL template-alias duplicate errors being misclassified by error text and occasional template status publish failures; classification now uses SQLSTATE (#1724).
- Fixed compatibility issues in the cubebench CPU topology report (#1757).
- Added an Ubuntu desktop sandbox example and integration guide (#1746).
- Added an OpenCode integration: a plugin hook redirects bash into the sandbox so commands no longer run directly on the developer's machine (#1238).
- Added a CI status page (#1737).
- Corrected the PVM expansion: Pagetable-based, not Parallel (#1772).
- Added a documentation security warning: injecting credentials over HTTP is unsafe, limited to controlled internal networks; prefer HTTPS (#1818).
v0.7.2-rc3
v0.7.2-rc3
v0.7.2-rc2
v0.7.2-rc2
v0.7.2-rc1
v0.7.2-rc1
kernel-release-260921-1
Dedicated kernel assets release (BM + PVM guest + PVM host).
v0.7.1
2026.09.11 Release v0.7.1
CubeSandbox 0.7.1 introduces 1 major feature along with multiple enhancements and bug fixes. 70 commits from 24 contributors.
🎯 Major Features
End-to-end high availability for Cube control-plane services
- A standalone template-center service enables multi-replica CubeMaster deployment.
- The lifecycle management service now supports active/standby deployment.
✨ Enhancements
Templates & Storage
- Snapshot support for Host Mount and Volume Plugin: snapshot, restore, rollback, and clone now work for sandboxes with external mounts (#1654, #1656).
- Standalone CubeTemplateCenter: template build / delete / reclaim is split out of CubeMaster into an independently scalable multi-replica service. Build artifacts are persisted to S3/MinIO (AWS S3 compatible). Also fixes long-standing issues around concurrent build races, inconsistent artifact table names, and ephemeral local-disk storage (#1659).
- Faster same-bucket cross-node snapshot restore (#1663): restoring a snapshot from the same bucket now uses object-storage server-side copy, which is significantly faster. Also improves delayed-delete reclamation and adds snapshot cancellation.
Lifecycle & Control Plane
- CLM now supports active/standby disaster recovery.
- Running sandboxes no longer block snapshot deletion (#1620): deleting a still-referenced snapshot takes effect immediately; underlying storage is reclaimed after the last reference is released.
Security
- virtiofsd hardening (#1612): after a directory whitelist is set, root-directory mutation operations are rejected, as are forged readdirplus requests.
Deployment & Runtime
- CubeS3lvol on Kubernetes (#1637): use the S3 backend for cross-node pause/resume and snapshots in K8s deployments.
- One-click deployment supports external PostgreSQL (#1644): choose MySQL / PostgreSQL via
CUBE_DATABASE_DRIVERand connect to a self-managed database instance. - CubeS3lvol is now opt-in (#1622, #1633): set
[cow.s3] enable = true(orONE_CLICK_ENABLE_S3LVOL=1for one-click deploy); it is disabled by default. Also fixes the switch not taking effect during one-click upgrades. Upgrade note: nodes that were using S3 without an explicit setting must enable it after upgrade. - Unified Helm Redis logical-DB config (#1638): new top-level
redis.dbapplies to CubeMaster / CubeProxy / CLM, so multiple clusters sharing one Redis instance can isolate logical databases per cluster.
Web UI / CubeOps / Other
- cubemastercli batch template deletion (#1549):
tpl deleteaccepts multiple template IDs in one call.
🐛 Bug Fixes
Lifecycle & Sandbox
- Fixed sandboxes set to never expire (
NEVER_TIMEOUT) being immediately treated as expired (#1401). - Fixed invalid CPU / memory specs in create requests being treated as 0, allowing sandboxes to bypass node resource filters and be scheduled onto any node (#1463).
- Fixed a new timeout passed on Resume being discarded, so the sandbox kept its pre-pause timeout (#862).
- Fixed snapshots after an S3-backend restore falling back to a full memory dump; snapshots stay incremental (#1688).
- Fixed no log output from
cubecli logsfor sandboxes created from a template (#1616). - Fixed template creation hanging indefinitely when a compute node is unresponsive; added a configurable timeout (default 300 seconds) (#994).
- Fixed gRPC connections not being closed promptly after a node is taken offline or deleted (#1585).
- Fixed S3 volume mount failures with newer s3fs (1.97+ / FUSE3) (#1647).
Networking & Security
- Fixed the transparent proxy returning 504 after 60 seconds when talking to slow-TTFB upstreams such as LLMs; proxy send/receive timeout is now 2 hours (#1655).
- Fixed CubeEgress failures caused by oversized credential values injected via network rules; the per-entry injection limit is aligned with E2B at 2048 bytes (#1606).
- Fixed TAP device names silently truncated past the kernel length limit, causing network device lookup failures (#1552).
- Fixed intermittent Cubelet network-plugin init failures on K8s when the gateway ARP cache is not ready early in node startup (#1609).
- Image-registry credentials no longer appear in component logs (#1600).
Deployment & Upgrade
- Fixed Helm upgrades failing because Redis StatefulSet PVC labels changed (#1604).
- Fixed
global.imageRegistryoverwriting explicitly configured private / third-party registry addresses (#1605). - Fixed helm test pods remaining Pending on tainted nodes (#1388).
- Fixed Terraform deployments skipping validation and template creation when node queries returned 0 healthy nodes (#1602).
- Fixed CubeOps ignoring the logical-DB number when using a standalone Redis config, which hid node metrics and caused scheduling-metric update timeouts (#1607).
- Fixed lowercase log-level values (e.g.
info) not taking effect and falling back to DEBUG (#1597). - Fixed builder image builds failing on Ubuntu 20.04 (#1588).
Other
- Node / Python SDK: fixed command execution never returning when timeout is
0orNEVER_TIMEOUT(#1485). - Fixed cubeopscli reporting a hardcoded 0.1.0 version and the
versionsubcommand being unavailable (#1596). - Fixed cubemastercli
versionproducing no output by default (#1657). - Fixed the Web UI runtime config page showing deprecated settings (#1573).
v0.7.1-rc2
v0.7.1-rc2
v0.7.1-rc1
v0.7.1-rc1
v0.7.0
2026.08.28 Release v0.7.0
CubeSandbox 0.7.0 introduces 4 major features along with multiple enhancements and bug fixes. 239 commits from 57 contributors.
🎯 Major Features
Cross-Node Pause & Resume
With an S3 backend, sandboxes support pause/resume across nodes as well as creating sandboxes from snapshots. This feature is currently in preview.
Component Multi-Versioning
- Newly created templates and snapshots now record the versions of the components they depend on. After components on compute nodes are upgraded, historical templates and snapshots remain usable, and upgrades no longer affect pause/resume of existing instances — improving stability for running workloads.
Network Subsystem Refactor: Faster Sandbox Network Provisioning
- Architecture: fewer components to deploy — the network-agent component is merged into Cubelet, reducing inter-process RPC calls during sandbox creation; TAP device lifecycle management is redesigned to prevent network rules from leaking across sandboxes, reducing attack surface.
- Performance: optimized the eBPF network policy provisioning path, significantly reducing sandbox creation latency for sandboxes with network rules; removed unnecessary netlink dump operations so that creating new TAP devices under high concurrency remains stable when idle TAP devices are exhausted.
Separation of Control Plane and Operations
Architecturally, operations capabilities are split out of CubeMaster. Node management logic now lives in CubeOps, which supports multi-replica deployment and ships the cubeopscli tool.
✨ Enhancements
Templates & Storage
- CubeS3lvol COW (#1490): besides the local XFS COW engine, cubecow now supports remote snapshot storage on S3 object storage, enabling cross-node pause/resume and snapshot cloning.
- Private HTTP image registry support (#1369): pull images from HTTP image registries to build templates.
- Built-in MinIO as the default S3 volume backend (#1408): MinIO is deployed by default as the S3 backend for the volume feature and cross-node pause/resume. Users can also specify their own S3 backend.
Lifecycle & Control Plane
- Node deletion (#1202): support removing a node from the cluster so it no longer participates in scheduling.
Networking & Security Proxy
- Network subsystem refactor: NetworkAgent is fully embedded into Cubelet, streamlining the network provisioning flow.
- Support dynamically updating network policies for running sandboxes.
- CubeEgress L7 forwarding rules now support custom ports.
- CubeVS learns MAC addresses within the same subnet, avoiding black-holed traffic in non-hairpin networks.
- CubeProxy supports a custom management port and the gRPC protocol.
SDK
- Volume support: the Go (#1269) and Node (#1277) SDKs add Volume CRUD and
volumeMounts, bringing all three languages to parity. - Full template alias support: build-time aliases (#1119) and alias management for existing templates (#1120), covering Go / Node / Python.
- Go SDK user-level file view (#1348):
Files.ForUserisolates file access by user identity. - Node SDK runtime timeout (#1251):
Sandbox.setTimeout(timeout)supportsNEVER_TIMEOUT. - Python SDK sandbox scheduling scope (#1144):
Sandbox.create(distribution_scope=...)explicitly specifies the nodes/zones a sandbox can be placed on. - Go SDK private sandbox dataplane fix (#1185): RunCode / Commands / Files / PTY now correctly pass through the TrafficAccessToken.
- Node SDK auth header fix (#1360): an
Authorizationheader explicitly set by the caller (including lowercase variants) is no longer overridden by the SDK's defaultapiKey. - Clone snapshot deferred cleanup across all three SDKs (#1095): reference counting ensures the temporary snapshot is deleted only after all clones are destroyed.
Deployment & Runtime
- Configurable log rotation policy (#1339): users can adjust cubelet's log rotation policy via the configuration file.
- Kernel / guest images published as separate artifacts (#1324): releases no longer rebuild the kernel and guest images; fixed versions are pulled from dedicated
kernel-release-*/guest-image-*releases.
Web UI / CubeOps / Other
- CubeOps: node management moved into this module; new cubeopscli tool for node management, replacing the cubemastercli node subcommands; two-replica deployment supported by default (#1384, #1494).
- Web UI: node isolation/unisolation and node operation history viewing (#1384).
🐛 Bug Fixes
Lifecycle & Sandbox
- Fixed sandbox state inconsistency, zombie processes, and deletion failures caused by failed pause/resume (#978, #985, #1137, #1274).
- Fixed snapshot performance issues (#1300, #1504).
- Fixed a template cache data race during concurrent sandbox creation (#1366).
Networking & Security
- Fixed sandbox state anomalies caused by TAP device recovery failures during pause/resume and node restarts (#930, #987, #1207).
Other
- Fixed log rotation configuration not taking effect (#1289).
- Expanded the Python SDK compatibility end-to-end tests with coverage for the filesystem, rollback & cloning, online timeout updates, abnormal lifecycles, and advanced template parameters (#1226).
📚 Documentation
v0.7.0-rc2
v0.7.0-rc2