# GKE Agent Sandbox

Official pricing: https://cloud.google.com/kubernetes-engine/docs/concepts/agent-sandbox  
Category: hyperscaler · Isolation: gvisor

## Pricing regimes (raw)

- **GKE Autopilot sandbox pods** (resource): $0.0445/vCPU-h, $0.0049225/GiB-h [beta]
- **GKE Autopilot Spot sandbox pods** (resource): $0.0133/vCPU-h, $0.0014767/GiB-h [spot, beta]
- **GKE Standard sandbox nodes** (resource) [alt, beta]
- **Autopilot default — Compute Flexible CUD 1 year** (resource): $0.03204/vCPU-h, $0.0035442/GiB-h [commit, beta]
- **Autopilot default — Compute Flexible CUD 3 years** (resource): $0.02403/vCPU-h, $0.00265815/GiB-h [commit, beta]
- **Autopilot default — GKE CUD 1 year** (resource): $0.0356/vCPU-h, $0.003938/GiB-h [commit, beta]
- **Autopilot default — GKE CUD 3 years** (resource): $0.024475/vCPU-h, $0.002707375/GiB-h [commit, beta]

## Features

Yes: snapshots, memory snapshots, fork/clone, pause/resume, persistent disk, volumes, ≥24 h sessions, custom image (Docker or snapshot), start from your own snapshot, your own Docker/OCI image, HTTPS preview URLs, egress allowlist, open internet, static egress IP, self-hosting, BYOC, open source, SOC 2, HIPAA, SSO, GPU, arm64, Python, live resize, live fork (no pause), memory fork, EU data residency, snapshots on demand, gVisor or VM (no shared kernel), inbound access rules, extra volumes, shared volumes

No: idle auto-stop, full VM (own kernel), Docker inside, nested virtualization, root, browser, desktop GUI, computer-use API, browser + desktop control, anti-bot stealth, CAPTCHA solving, residential IPs, preinstalled agents, SSH, public IPv4, Windows, macOS, Node.js, HTTP method/path egress rules, wake on request, MCP server, automatic snapshots, agent harness API, hosted agent API (their own agent), firewall inside (nftables), secret proxy, secret proxy for any API

Unknown: everything else. Evidence (source + quote) per feature: https://battleships.dev/data/providers/gke-agent-sandbox.json → feature_evidence

## Caveats

- Autopilot rates are for the default region on the GKE pricing page (us-central1); other regions cost ~5-30% more. You run and operate your own GKE cluster (Agent Sandbox CRDs, warm pools, templates); regional quotas apply. Minimum Pod sizes / CPU:memory ratios of Autopilot are not modelled.
- Compute is billed on Pod requests (not usage). Egress follows standard Google Cloud network pricing (not captured; null).
- Harbor GKE backend and ADK GKE codeexecutor use customer GKE infrastructure. Agent Sandbox orchestration is not a separate all-inclusive VM rate. Price depends on Autopilot/Standard, location, machine, warm pool and storage.
- Features set to null were not verified. No sandbox was purchased or tested; feature/performance statements are documentation claims. Null maximums are unknown unless a cited note explicitly states unlimited.
- A complete monthly bill requires known snapshot/egress/plan limits; do not silently treat missing ancillary charges as free.
- Warm pools: pre-warmed sandboxes are running Pods that accrue requested CPU, RAM and ephemeral storage before any claim (startup typically under 1 s; replicas user-configured). Platform overhead: the sandbox-router alone requests 100m CPU / 512 MiB, plus controller and networking resources; not modelled.
- Nested virtualization set to no: every sandbox runs under gVisor, which gives the workload its own user-space kernel and no /dev/kvm device (no KVM-based emulators or VMs inside). Docker inside is a separate question.

## How this provider charges


As of 2026-09-28. Prices are USD unless explicitly labelled otherwise. Source type: official published list/promo or unknown, never a fabricated quote.

Harbor GKE backend and ADK GKE codeexecutor use customer GKE infrastructure. Agent Sandbox orchestration is not a separate all-inclusive VM rate. Price depends on Autopilot/Standard, location, machine, warm pool and storage.

| Regime | When it applies | How billed / numbers | Source |
|---|---|---|---|
| Autopilot | Pod-driven compute | GKE pod resource and management charges plus disk/network; region unspecified. | https://cloud.google.com/kubernetes-engine/docs/concepts/agent-sandbox |
| Standard | Provisioned nodes | NodeVM rates plus cluster management; warm pool bills whileidle. | https://cloud.google.com/kubernetes-engine/docs/concepts/agent-sandbox |

## Gotchas

- Harbor GKE backend and ADK GKE codeexecutor use customer GKE infrastructure. Agent Sandbox orchestration is not a separate all-inclusive VM rate. Price depends on Autopilot/Standard, location, machine, warm pool and storage.
- Not fully priceable in ENGINE_CARD: unknown USD resource rates or machine shape. Null is not zero; do not rank as a free provider.
- Features set to null were not verified. No sandbox was purchased or tested; feature/performance statements are documentation claims. Null maximums are unknown unless a cited note explicitly states unlimited.
- A complete monthly bill requires known snapshot/egress/plan limits; do not silently treat missing ancillary charges as free.

## Worked workload

4 vCPU / 8 GiB; 50 simultaneous instances × 8 h/day × 22 days = **8,800 instance-hours**, **35,200 vCPU-hours**, **70,400 GiB-hours**. At 30% observed CPU:10,560 active-vCPU-hours only where the meter actually uses utilization. Assume one start/instance/day:1,100starts. Retain50GiB snapshots for a month;100GiB outbound. Active disk capacity was not specified.

Requires200vCPU/400GiB concurrent capacity before node packing/overhead;8,800 sandbox-hours do not uniquely determine node-hours. Select cluster/node/storage/network region and account discounts; totalnull.

## Sources

- https://cloud.google.com/kubernetes-engine/docs/concepts/agent-sandbox
- https://github.com/laude-institute/harbor/blob/main/src/harbor/environments/gke.py
