> ## Documentation Index
> Fetch the complete documentation index at: https://docs.qredence.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Sandbox execution

> How Fleet RLM runs model-authored Python in Daytona Sandboxes, brokers host tools, and manages snapshots, leases, and cleanup.

Model-authored code never runs in the Fleet process. Fleet submits generated Python to a Daytona Sandbox and serves host tools through an authenticated broker.

## Sandbox kinds

| Sandbox | Lifetime | Mount |
| - | - | - |
| Root Session Sandbox | Retained for the Session. Reused across clean sequential Turns. | Session Workspace at `/workspace`. |
| Host I/O Sandbox | Short-lived. One may stay warm for `runtime.workspace_io_idle_seconds`. | Whole Workspace at `daytona.volume_mount_path`. |
| Child Sandbox | Disposable, one per recursive child. | No Volume. |

Even when Fleet reuses a root Sandbox, each invocation starts with fresh bindings, tools, budget, and DSPy history. Don't rely on Python variables between Turns.

## The tool broker

`daytona/broker.py` runs a JSON-only, authenticated broker inside the Sandbox. It dispatches authorized host tools and DSPy semantic calls back to Fleet.

* Only the `/pending` endpoint issues tool leases. A dropped notification leaves unclaimed work available to polling.
* Fleet doesn't re-execute claimed tools automatically.
* The `/result` endpoint fences late or duplicate results against the issued lease.

See [Sandbox tools](/fleet-rlm/reference/sandbox-tools) for the tools available to model code.

## Leases and admission

`runtime.max_active_daytona_leases` caps concurrent Sandboxes. The value must be between 2 and 8. Fleet reserves one slot for short-lived host I/O.

Fleet serializes Workspace I/O. Queueing and preparation must finish within `runtime.workspace_io_acquisition_timeout_seconds`. Shutdown drains active file operations before deleting their Sandbox. Unconfirmed cleanup blocks replacement and stays owned by the runtime for retry.

## Snapshots

Fleet can start Sandboxes from prebuilt Daytona snapshots.

| Variable | Profile | Used for |
| - | - | - |
| `FLEET_DAYTONA_SNAPSHOT` | `session` | Root Session Sandboxes. |
| `FLEET_DAYTONA_CHILD_SNAPSHOT` | `semantic-child` | Lean child Sandboxes. |

Build and verify snapshots with the Makefile targets:

```bash theme={null}
make daytona-snapshot-create
make daytona-snapshot-check
make daytona-child-snapshot-create
make daytona-child-snapshot-check
```

The default snapshot names are `fleet-rlm-python313-v7` and `fleet-rlm-python313-child-v2`. Override them with `DAYTONA_SNAPSHOT_NAME` and `DAYTONA_CHILD_SNAPSHOT_NAME`.

## Network work

Public search, page retrieval, Git inspection, and package installation run as ordinary Sandbox Python or subprocesses. Fleet has no host-side URL fetcher.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.