Skip to content

Bunny.net Launches Bunny Sandbox for AI Agent Code Execution

Bunny.net launched Bunny Sandbox, disposable cloud environments where AI coding agents like Claude Code can work without putting the developer's own machine at risk.

Bunny.Net Bunny Sandbox
Bunny Sandbox · Credit: Bunny.Net

Bunny.net launched Bunny Sandbox on Wednesday, giving AI coding agents a contained cloud environment to work in without putting the developer's own machine at risk of the commands agents run autonomously.

Bunny Sandbox sits on top of Bunny.net's existing Magic Containers infrastructure. Each environment is a fresh Ubuntu container with Node.js, Bun, Python, and Claude Code pre-installed, plus a 10 GB persistent workspace. Developers create one with a single CLI command, SSH into the box, let the agent work, and delete the environment when done. Deleting stops the billing immediately.

The isolation model is Bunny Sandbox's core claim. Every container runs on gVisor, a user-space kernel that sits between the container and the real host. Code running inside talks to gVisor instead of the underlying kernel, meaning an agent that deletes files or pulls a malicious package cannot reach anything outside its own box. Bunny.net says each environment is also walled off from every other.

According to Bunny.net's announcement, pricing runs at $0.02 per CPU core per hour and $0.005 per GB of memory per hour, both billed to the second, with workspace storage at $0.10 per GB per month on the included 10 GB allocation. A few active hours of coding work runs to roughly cents of compute. A JavaScript SDK is also available, letting teams spin up Bunny Sandbox fleets programmatically for test pipelines or per-user environments.

Claude Code is the only supported agent Bunny Sandbox ships with at launch. Bunny.net says more coding agents are coming alongside Python and Rust SDKs, deeper integration with its other services, and a built-in gateway that would replace the per-environment Anycast IP charge.

For developers who regularly hand AI agents unrestricted shell access, the risk calculus is direct: each run has a low chance of going wrong, but over thousands of runs the expected cost of one bad command is not small. A throwaway cloud environment limits the damage to the box.

Share this story

Julian Beaumont

Julian Beaumont covers artificial intelligence and large language models for techshooked, following the path from research paper to deployed feature. His standard is anti-hype: ask what a model actually does, what trained it, how it fails, and whether a benchmark measures what the announcement claims.