← All atoms

Ephemeral VM

isolation-constraint · v1.0.0

Single-use VM destroyed on task completion. Strongest practical isolation for untrusted execution.

Isolation

Process
vm
Network
allowlist
Filesystem
tmpfs
Scoped paths
/workspace

Raw atom

/atoms/isolation-constraint/ephemeral-vm.json · schema