ACA Sandboxes - Isolated, secure hosting for agents
John Savill explains Azure Container Apps (ACA) Sandboxes, focusing on how they provide isolated, secure hosting for agent workloads. He covers the MicroVM-based model, egress controls via proxy and rules, lifecycle and pricing considerations, how sandbox groups work, and operational topics like managing instances and logging.
Overview
The video introduces ACA Sandboxes as an Azure-hosted option for running agent workloads in an isolated environment using a MicroVM approach.
Key areas covered:
MicroVM for container agents
- How the sandbox model uses MicroVM-style isolation for container-based agent workloads.
Egress proxy
- Using an egress proxy to control outbound connectivity from sandboxed workloads.
Lifecycle
- How sandbox instances are created/used and how lifecycle considerations affect operations.
Pricing
- What to consider when evaluating cost for sandbox usage.
ACA Sandbox Group
- How sandbox groups are used to organize and work with sandbox instances.
Managing sandbox instances
- Operational management of sandbox instances.
Egress rules
- Defining and applying egress rules to restrict/allow outbound traffic.
Logging
- Logging considerations for sandboxed workloads.
When to use
- Scenarios where ACA Sandboxes are a good fit for isolated hosting of agent workloads.