- The aggregated apiserver authenticates callers through standard Kubernetes
authn/authz; access to
agents.x-k8s.ioresources is governed by RBAC. The e2b surface authenticates with the API keys it is given (apiserver.e2b.apiKeySecret). - Node-local warm-pool claims are authorized by the sandboxd bearer token. A
claimed sandbox is driven with the per-claim token handed back on create:
the
sandbox.cocoonstack.io/tokenannotation on the Kubernetes surface. The e2b surface hands outenvdAccessTokeninstead, an HMAC of that claim token under the envd secret (apiserver.e2b.envdSecret), which the sandbox's ownenvdenforces. Both are secrets: leaking one grants control over that sandbox, never over the host, and the e2b token reaches only its data plane. sandbox-envd-proxyholds the fleet sandboxd token and the envd secret. It reads a sandbox's claim token from the owning node, admits a request only when the presented token derives from it, and opens the relay with the claim token, which no client ever sees. A signed file URL on 49983 is the one request it admits without a token; it relays that with the fleet token, which sandboxd keeps passive, so it never wakes a paused sandbox, andenvdchecks the signature. A caller never learns a node address.- Sandboxes are hardware-isolated microVMs. A guest escape is a vulnerability in the hypervisor stack underneath, coordinated with the relevant upstream.
Do not open a public issue. Report privately through GitHub Security
Advisories — "Report a vulnerability" on the repository's Security tab. Fixes
land on master and the most recent tagged release.