Skip to main content
Model-authored code never runs in the Fleet process. Fleet submits generated Python to a Daytona Sandbox and serves host tools through an authenticated broker.

Sandbox kinds

Even when Fleet reuses a root Sandbox, each invocation starts with fresh bindings, tools, budget, and DSPy history. Don’t rely on Python variables between Turns.

The tool broker

daytona/broker.py runs a JSON-only, authenticated broker inside the Sandbox. It dispatches authorized host tools and DSPy semantic calls back to Fleet.
  • Only the /pending endpoint issues tool leases. A dropped notification leaves unclaimed work available to polling.
  • Fleet doesn’t re-execute claimed tools automatically.
  • The /result endpoint fences late or duplicate results against the issued lease.
See Sandbox tools for the tools available to model code.

Leases and admission

runtime.max_active_daytona_leases caps concurrent Sandboxes. The value must be between 2 and 8. Fleet reserves one slot for short-lived host I/O. Fleet serializes Workspace I/O. Queueing and preparation must finish within runtime.workspace_io_acquisition_timeout_seconds. Shutdown drains active file operations before deleting their Sandbox. Unconfirmed cleanup blocks replacement and stays owned by the runtime for retry.

Snapshots

Fleet can start Sandboxes from prebuilt Daytona snapshots. Build and verify snapshots with the Makefile targets:
The default snapshot names are fleet-rlm-python313-v7 and fleet-rlm-python313-child-v2. Override them with DAYTONA_SNAPSHOT_NAME and DAYTONA_CHILD_SNAPSHOT_NAME.

Network work

Public search, page retrieval, Git inspection, and package installation run as ordinary Sandbox Python or subprocesses. Fleet has no host-side URL fetcher.
Last modified on October 9, 2026