Session

Give Your Agent a Computer: Azure Container Apps Sandboxes

AI agents write code, and someone has to run it. Not in your production cluster, not on your laptop, and preferably not anywhere it can reach your database. Azure Container Apps Sandboxes give agents what they actually need: a disposable computer with strong isolation, snapshot-based suspend and resume, and an egress policy that says exactly what it may talk to.

This session comes from running agentic workloads on Azure Container Apps in production and repeatedly discovering that the app model fights you: always-on services for bursty work, stateless containers for stateful tasks, and scale-to-zero settings that quietly pause the wrong workers. Sandboxes are a different compute primitive, the same one underneath GitHub Copilot's cloud sandboxes and Foundry hosted agents, and now you can use it directly.

We build a sandbox group live, let an agent generate and execute code inside it, suspend it mid-task, resume it with memory intact, and try to sneak data past an egress policy. You leave knowing when to reach for sandboxes, dynamic sessions, jobs, or plain container apps, and what the preview does not do yet.

For engineers and architects running or planning agentic workloads on Azure.


AI agents generate code someone has to run. Azure Container Apps Sandboxes give them a disposable, isolated computer with suspend/resume and egress control. Live build, live suspend, live exfiltration attempt, and a clear map of sandboxes vs sessions vs jobs vs apps.

Nikos Delis

Senior Cloud & Software Engineer | Microsoft MVP for Azure & IoT

Malmö, Sweden

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top