opensourceprojects.dev

A broadsheet for software that doesn't ask for your email

Micro-VMs that run any OCI image and actually persist
GitHub RepoImpressions3

Project Description

View on GitHub

Micro-VMs That Run Any OCI Image and Actually Persist

If you've ever tried to give an AI agent a place to run code, you know the pain. Containers feel too leaky, full VMs feel too heavy, and every time your agent comes back for another turn, it's starting from scratch. BoxLite is a project that tries to solve that with hardware-isolated micro-VMs that run any OCI image and, crucially, persist across turns.

What It Does

BoxLite is a compute substrate for AI agents. At its core, a "Box" is a hardware-isolated micro-VM that runs any OCI image — the same Docker images you already use, like python:slim or node:alpine. Each Box gets its own kernel, which puts it somewhere between a container and a full virtual machine in terms of isolation and weight.

The project is daemonless. You can embed it directly as a library in your application — no root access required, no background service to manage. There's an optional server mode if you want it, but the default path is embedding. It ships with SDKs for Python (3.10+), Node.js (18+), Go (1.24+ with CGO), Rust, and a C SDK. It also supports a cloud control plane, so the same engine can run locally on your laptop or scale out to a multi-tenant cloud.

Why It's Cool

Persistence is the headline. Most sandboxed execution environments treat each run as disposable. BoxLite doesn't. Agents can install packages, write files, and resume across turns without going cold. If you're building an agent that needs to maintain state — a working directory, a set of installed dependencies, a half-finished task — this is the feature that matters.

Real isolation without the weight. Running its own kernel means it's stronger than a container, but the README is explicit that it stays lighter than a full VM. That's the sweet spot for agent workloads, where you want genuine separation between the agent's code and your host, but you don't want to pay the cost of spinning up a traditional VM for every task.

No daemon, no root. Being able to pip install boxlite and embed it as a library is a big deal for local development and for shipping products that include sandboxing. You don't need to ask users to run a privileged service, and you don't need to worry about a background process falling over.

Networking you can actually control. You can restrict egress with allow_net, and inject real secrets via placeholders. That last part is subtle but useful — your agent's code can reference a placeholder, and BoxLite swaps in the real credential at the boundary, so secrets don't end up baked into the sandbox.

One engine, two deployment targets. The same thing that runs on your laptop is meant to power a multi-tenant cloud. That's a nice property if you're prototyping locally and later want to move the same workload to a hosted environment without rewriting your integration.

Async-first design. The README calls out that it's async-first for fleets, which suggests it was built with the expectation that you'll be running many of these at once, not just one.

How to Try It

The fastest path is Python. Install it:

pip install boxlite

Then give your agent a Box and run something in it:

import asyncio
import boxlite

async def main():
    async with boxlite.SimpleBox(image="python:slim") as box:
        result = await box.exec("python", "-c", "print('Hello from BoxLite!')")
        print(result.stdout)

asyncio.run(main())

If you're working in Node.js, install the package with npm install @boxlite-ai/boxlite (Node 18+):

import { SimpleBox } from '@boxlite-ai/boxlite';

const box = new SimpleBox({ image: 'python:slim' });
try {
  const result = await box.exec('python', '-c', "print('Hello from BoxLite!')");
  console.log(result.stdout);
} finally {
  await box.stop();
}

Go and Rust are supported too. For Go, you'll need go get github.com/boxlite-ai/boxlite/sdks/go and Go 1.24+ with CGO. For Rust, it's cargo add boxlite tokio futures --features tokio/macros,tokio/rt-multi-thread. There's also a C SDK if you're working in a language that isn't covered directly.

The repository is at github.com/boxlite-ai/boxlite. It's Apache 2.0 licensed, and there's a Discord if you want to ask questions.

Final Thoughts

BoxLite is aimed squarely at people building AI agents that need to execute code — and it's making a specific bet that persistence plus real isolation is the combination that matters. If you've been stitching together containers and ephemeral sandboxes to get something that works, this is worth a look. It's also a reasonable choice if you want sandboxing in a product without asking your users to run a privileged daemon.

The project is early, and the README is honest about the scope — no claims of solving everything. But the design choices are coherent, and the multi-language SDK coverage suggests the maintainers are thinking about real adoption rather than a single-language demo. Worth watching, and worth trying if agent isolation is on your roadmap.


Follow @githubprojects for more developer tools and open source projects.

Back to Projects
Project ID: 96f28cef-7729-4ed4-9125-f610f65011f8Last updated: September 30, 2026 at 05:28 AM