给 Agent 一台完整的 Linux 虚拟机
Key Highlights
Modal announced VM Sandboxes is generally available: set runtime="vm" and you get a full Linux virtual machine with Docker, FUSE, and kernel features. It reuses the original Sandbox calling interface, modal.Image, sub-second cold starts, and memory bursting, and early customers have already launched over 20 million VMs, which signals production maturity rather than a demo.
What Happened
Previously a Sandbox was a restricted container that could not run workloads needing kernel features. VM Sandboxes hand the agent a whole Linux machine: it can mount filesystems, use FUSE, and touch the kernel without working around limits. For agents that write code, drive browsers, or process data, this is a qualitative change in what they can actually do.
Technical Details
The interface barely changes: switch the original Sandbox call from container to VM and upper code needs little rewrite. Sub-second cold start and memory bursting stay, so elasticity remains, and modal.Image still packs the environment. The 20 million VM figure shows a scheduler that can carry production load, not a toy that falls over at scale.
Comparison with Competitors
E2B also builds agent execution environments, but Modal's difference is fused cloud-native scheduling, images, and billing with seamless continuity into existing Modal workflows. For teams already on Modal the migration cost is near zero, and for new users it is a one-stop "give the agent a real machine" option rather than glue code.
Industry Impact and Use Cases
Agents that need full system calls, compiling kernel modules, running a database, or browser automation, finally get a compliant yet isolated runtime that security and finance teams can actually approve because it is observable, billable, and reclaimable instead of a mystery box.
Data and Methodology
The "sub-second cold start" is steadiest under a resident Cluster; spinning a VM on demand can still carry start-up cost, so citations should distinguish the two. The 20 million VMs are cumulative, not concurrent, but they still prove scheduler maturity well beyond a prototype anyone would fear to ship.
Risks and Limitations
A full VM expands the attack surface: malicious code can touch the kernel. Isolation depends on sandbox policy and Sidecars, and a wrong config leaks. On cost, use on-demand for sporadic tasks and a Cluster for steady load, or machines sit idle and burn money while nothing runs on them at all.
Further Analysis
Put simply, for an agent to do real work it lacks a reliable machine. VM Sandboxes fill the gap between containers and bare cloud: full system calls with Serverless elasticity. This execution layer will gradually replace self-managed Kubernetes as the default substrate for agent products, so you write the logic and let the platform handle the machine, the patching, and the scaling.
How to Deploy
First inventory which agents truly need kernel features or full system calls before choosing VM versus container. Use Modal Clusters for steady load to keep cold starts stable, and on-demand for sporadic tasks. Wire sandbox lifecycles into your orchestration so machines reclaim the moment a task ends, avoiding the idle burn that quietly inflates the bill when nothing runs.
Common Pitfalls
Pitfall one is putting everything on VM blindly, raising both cost and attack surface. Pitfall two is ignoring the Sidecar trust boundary and stuffing keys into untrusted code. Pitfall three is assuming a VM is absolutely safe and skipping least privilege and audit. The right move is select by need, isolate by boundary, and reclaim by lifecycle rather than treating the VM as a magic wall.
One-Line Conclusion
Put simply, VM Sandboxes give the agent a reliable machine with both full system calls and elasticity. It is the pragmatic substrate for the agent-era execution layer, and paired with Sidecars it completes the trusted and isolated halves that a production platform actually needs to pass review.
Extended Observation
The maturity of the execution layer directly decides how many real jobs agents can take. The more mature platforms like VM Sandboxes get, the wider the boundary agents can touch, moving from toy conversations to actually doing work. Together with Sidecars and routing, it forms the production-grade substrate of the agent era, and architects should put it on the shortlist rather than reinventing fragile VMs nobody owns when something breaks at 3 a.m.