Skip to content

List or watch sandboxes in every project

GET
/apis/nodus.dev/v1/sandboxes
curl --request GET \
--url https://example.com/apis/nodus.dev/v1/sandboxes
labelSelector
string
fieldSelector
string
limit
string
continue
string
watch
string
resourceVersion
string
allowWatchBookmarks
string
timeoutSeconds
string

OK

Media type application/json
object
apiVersion
string
items
required
Array<object>

Sandbox is an isolated container for agents and untrusted code on Nodus CPU nodes. You run commands in it, read and write its files, stop it to stop paying for compute and start it again with its /workspace kept. It bills per second while it holds compute, and stops by itself when idle.

object
apiVersion
string
kind
string
metadata
object
annotations
object
key
additional properties
string
creationTimestamp
string
deletionGracePeriodSeconds
integer format: int64
deletionTimestamp
string
finalizers
Array<string>
nullable
generateName
string
generation
integer format: int64
labels
object
key
additional properties
string
managedFields
Array<object>
nullable
object
apiVersion
string
fieldsType
string
fieldsV1
object
key
additional properties
manager
string
operation
string
subresource
string
time
string
name
string
namespace
string
ownerReferences
Array<object>
nullable
object
apiVersion
required
string
blockOwnerDeletion
boolean
controller
boolean
kind
required
string
name
required
string
uid
required
string
resourceVersion
string
selfLink
string
uid
string
spec
required

SandboxSpec is the container to run and its lifecycle.

object
args

Args are the arguments of Command.

Array<string>
nullable
command

Command is an optional main process. Without it the Sandbox idles and is driven by exec.

Array<string>
nullable
continuity

SandboxContinuity sets what survives a stop.

object
mode

Mode is Snapshotted (the default: /workspace is saved on stop and restored on start) or Ephemeral (every start begins from the image).

string
env

Env sets environment variables (at most 256; the NODUS_ prefix is reserved). A value read from a Secret key uses valueFrom.secretKeyRef.

Array<object>
nullable

EnvVar is one environment variable: a literal value or a Secret key.

object
name
required

Name matches ^[A-Za-z_][A-Za-z0-9_]*$.

string
value

Value is the literal value.

string
valueFrom

EnvVarSource names where an env value comes from.

object
secretKeyRef

SecretKeySelector selects one key of a Secret.

object
key
required

Key is the key within it.

string
name
required

Name is the Secret.

string
image
required

Image is the container image, such as nodus/agent-tools or ghcr.io/acme/tools:1.2; it is pinned to a digest when the Sandbox is created. The CLI and SDK send nodus/agent-tools when you name none.

string
lifecycle

SandboxLifecycleSpec sets when a Sandbox stops or is deleted without being asked.

object
idleTimeout

IdleTimeout stops (or deletes, with onIdle Delete) the Sandbox after this long with no running command, no file request and no terminal input: 0s never, or 1m–24h (default 5m). A silent open terminal is idle.

string
maxLifetime

MaxLifetime deletes the Sandbox this long after it was created, counting stopped time: 1m–720h (default 24h).

string
onIdle

OnIdle is Stop (the default) or Delete.

string
maxCostUSD

MaxCostUSD caps what the Sandbox may spend across every start, as a decimal USD string such as “5.00”. It can only be raised.

string
network

Network sets egress for the container.

object
egress

Egress is the outbound network policy.

object
allow

Allow lists DNS names or *.suffix patterns (AllowList only; at most 128).

Array<string>
nullable
policy

Policy is Deny, AllowList or Open.

string
presets

Presets add curated host lists such as python-packages or huggingface.

Array<string>
nullable
resources

Resources are capacity floors. For GPU work the offering’s host shape applies if larger.

object
cpu

CPU is the vCPU floor.

string
disk

Disk is the ephemeral disk floor.

string
gpu

GPURequest asks for accelerators. A family (H100) matches any of its variants and never another family.

object
count

Count is the GPUs per node: 1, 2, 4 or 8.

integer format: int32
exact

Exact pins the exact variant instead of matching the family.

boolean
interconnect

Interconnect is Any or NVLink.

string
minMemory

MinMemory is the per-GPU memory floor.

string
type

Type lists 1–8 accelerator ids or families from the catalog.

Array<string>
nullable
memory

Memory is the host memory floor.

string
nodes

Nodes above 1 is shorthand for spec.distributed.nodes and is stored in that form.

integer format: int32
secrets

Secrets mount Secrets as env vars and 0400 files under /run/secrets// (at most 32). Each start pins the newest version of each Secret (or the version a mount names) and keeps it until it stops, so a new value reaches the Sandbox on its next start.

Array<object>
nullable

SecretMount mounts one Secret, optionally pinned to a version. The bare name is accepted on write.

object
name
required

Name is the Secret.

string
version

Version pins a version; unset pins the latest at admission.

integer format: int32
state

State is Running (the default) or Stopped. Stopping releases the compute and keeps /workspace.

string
workingDir

WorkingDir is the absolute directory commands start in (default /workspace).

string
status

SandboxStatus is what Nodus observed about a Sandbox.

object
activity

Activity is Busy while a command runs, else Idle.

string
attempt

SandboxAttempt names one run of a Sandbox’s container.

object
epoch
required

Epoch counts the runs: it grows on every start and every recovery.

integer format: int64
name
required

Name is the attempt’s id.

string
conditions

Conditions are Scheduled, Funded, Ready and StateSaved.

Array<object>
nullable
object
lastTransitionTime
required
string
message
required
string
observedGeneration
integer format: int64
reason
required
string
status
required
string
type
required
string
cost

Cost is status.cost on every kind that spends money. It is a display copy of the ledger: amounts are decimal USD strings, and nothing is charged from these fields.

object
bySegment

CostSegments splits a charge by billing segment.

object
bootUSD

BootUSD is the charge from the start of billing until the program started.

string
coveredByNodus

CoveredByNodus lists the segments (Boot, Running, Restore, Teardown) with time Nodus paid for instead of charging it, such as the start and teardown of a run that failed because of Nodus.

Array<string>
nullable
restoreUSD

RestoreUSD is the charge for bringing a replacement up after capacity was lost.

string
runningUSD

RunningUSD is the charge while the program ran.

string
teardownUSD

TeardownUSD is the charge from stop until deletion was confirmed, with the billing increment.

string
final

Final is true once the final charge has posted.

boolean
fundedUntilTime

FundedUntilTime is when the current holds stop paying for the object.

string
heldUSD

HeldUSD is what is currently held for it.

string
limitUSD

LimitUSD is the object’s maxCostUSD, if it has one.

string
rateUSDPerHour

RateUSDPerHour is the sum of the hourly rates of its capacity that is still billing.

string
totalUSD

TotalUSD is what has been charged for this object so far.

string
expirationTime

ExpirationTime is when maxLifetime deletes the Sandbox.

string
handledRequests

HandledRequests records the nodus.dev/start-requested-at value last acted on.

object
key
additional properties
string
image

ImageStatus is the pinned image.

object
digest

Digest is the pinned digest.

string
reference

Reference is the image as written.

string
user

User is the user the image’s config runs its process as (root when it names none). Only an image that runs as root is placed on offerings that start the Nodus node agent inside the image itself.

string
lastActivityTime

LastActivityTime is the last command, file request or terminal input seen; idleTimeout counts from it.

string
message

Message is a human-readable account of Reason.

string
phase

Phase is Pending, Starting, Running, Recovering, Stopping, Stopped, Terminating or Failed.

string
reason

Reason says why the Sandbox Failed, such as StartupFailed or NodeLost.

string
secretVersionIDs

SecretVersionIDs identify the versions resolved when the Sandbox was created.

object
key
additional properties
string
secretVersions

SecretVersions are the versions resolved when the Sandbox was created, which proves its Secrets exist; each start pins the newest version again.

object
key
additional properties
integer format: int32
snapshot

SandboxSnapshot describes the last saved copy of /workspace.

object
reason
required

Reason is Stop.

string
time
required

Time is when it was saved.

string
stopReason

StopReason says why the Sandbox is stopped; empty while it runs.

string
kind
string
metadata
object
continue
string
remainingItemCount
integer format: int64
resourceVersion
string
selfLink
string
shardInfo
object
selector
required
string
Example generated
{
"apiVersion": "example",
"items": [
{
"apiVersion": "example",
"kind": "example",
"metadata": {
"annotations": {
"additionalProperty": "example"
},
"creationTimestamp": "example",
"deletionGracePeriodSeconds": 1,
"deletionTimestamp": "example",
"finalizers": [
"example"
],
"generateName": "example",
"generation": 1,
"labels": {
"additionalProperty": "example"
},
"managedFields": [
{
"apiVersion": "example",
"fieldsType": "example",
"fieldsV1": {
"additionalProperty": "example"
},
"manager": "example",
"operation": "example",
"subresource": "example",
"time": "example"
}
],
"name": "example",
"namespace": "example",
"ownerReferences": [
{
"apiVersion": "example",
"blockOwnerDeletion": true,
"controller": true,
"kind": "example",
"name": "example",
"uid": "example"
}
],
"resourceVersion": "example",
"selfLink": "example",
"uid": "example"
},
"spec": {
"args": [
"example"
],
"command": [
"example"
],
"continuity": {
"mode": "example"
},
"env": [
{
"name": "example",
"value": "example",
"valueFrom": {
"secretKeyRef": {
"key": "example",
"name": "example"
}
}
}
],
"image": "example",
"lifecycle": {
"idleTimeout": "example",
"maxLifetime": "example",
"onIdle": "example"
},
"maxCostUSD": "example",
"network": {
"egress": {
"allow": [
"example"
],
"policy": "example",
"presets": [
"example"
]
}
},
"resources": {
"cpu": "example",
"disk": "example",
"gpu": {
"count": 1,
"exact": true,
"interconnect": "example",
"minMemory": "example",
"type": [
"example"
]
},
"memory": "example",
"nodes": 1
},
"secrets": [
{
"name": "example",
"version": 1
}
],
"state": "example",
"workingDir": "example"
},
"status": {
"activity": "example",
"attempt": {
"epoch": 1,
"name": "example"
},
"conditions": [
{
"lastTransitionTime": "example",
"message": "example",
"observedGeneration": 1,
"reason": "example",
"status": "example",
"type": "example"
}
],
"cost": {
"bySegment": {
"bootUSD": "example",
"coveredByNodus": [
"example"
],
"restoreUSD": "example",
"runningUSD": "example",
"teardownUSD": "example"
},
"final": true,
"fundedUntilTime": "example",
"heldUSD": "example",
"limitUSD": "example",
"rateUSDPerHour": "example",
"totalUSD": "example"
},
"expirationTime": "example",
"handledRequests": {
"additionalProperty": "example"
},
"image": {
"digest": "example",
"reference": "example",
"user": "example"
},
"lastActivityTime": "example",
"message": "example",
"phase": "example",
"reason": "example",
"secretVersionIDs": {
"additionalProperty": "example"
},
"secretVersions": {
"additionalProperty": 1
},
"snapshot": {
"reason": "example",
"time": "example"
},
"stopReason": "example"
}
}
],
"kind": "example",
"metadata": {
"continue": "example",
"remainingItemCount": 1,
"resourceVersion": "example",
"selfLink": "example",
"shardInfo": {
"selector": "example"
}
}
}

An error: a metav1.Status whose reason is a registered code.

Media type application/json

Status is the error body of every API response: a Kubernetes metav1.Status (so kubectl and client-go understand it) plus three top-level extensions that those clients ignore (ADR-028).

object
apiVersion
string
code
integer format: int32
details
object
causes
Array<object>
nullable
object
field
string
message
string
reason
string
group
string
kind
string
name
string
retryAfterSeconds
integer format: int32
uid
string
docs

Docs is the URL of the code’s docs page.

string
fix

Fix says what to do next, for example a CLI command or the field to change.

string
kind
string
message
string
metadata
object
continue
string
remainingItemCount
integer format: int64
resourceVersion
string
selfLink
string
shardInfo
object
selector
required
string
reason
string
requestId

RequestID identifies the request in logs and support tickets.

string
status
string
Example generated
{
"apiVersion": "example",
"code": 1,
"details": {
"causes": [
{
"field": "example",
"message": "example",
"reason": "example"
}
],
"group": "example",
"kind": "example",
"name": "example",
"retryAfterSeconds": 1,
"uid": "example"
},
"docs": "example",
"fix": "example",
"kind": "example",
"message": "example",
"metadata": {
"continue": "example",
"remainingItemCount": 1,
"resourceVersion": "example",
"selfLink": "example",
"shardInfo": {
"selector": "example"
}
},
"reason": "example",
"requestId": "example",
"status": "example"
}