Repository navigation
[fix][ap] Tell agent sandboxes what their actual CPU limit is - #394
Open
jamie-retool wants to merge 1 commit into
Open
jamie-retool wants to merge 1 commit into
jamie-retool wants to merge 1 commit into
Conversation
jamie-retool
marked this pull request as ready for review
October 4, 2026 04:30
Contributor
[Medium risk] Agent sandbox configuration passes CPU limit to build tools. The PR appears safe to merge, though fractional sandbox CPU limits will be reported too high. Findings
Reviews (1) · Last reviewed commit: "[fix][ap] Tell agent sandboxes what thei..." |
| ,{"name": "SANDBOX_GLOBAL_LIFETIME_MS", "value": "{{ $as.sandbox.sandboxGlobalLifetimeMs }}"} | ||
| ,{"name": "SANDBOX_READY_TIMEOUT_MS", "value": "{{ $as.sandbox.sandboxReadyTimeoutMs }}"} | ||
| {{- if $as.sandbox.cpuAwareThreads }} | ||
| ,{"name": "SANDBOX_CPU_LIMIT", "valueFrom": {"resourceFieldRef": {"resource": "limits.cpu", "divisor": "1"}}} |
Contributor
There was a problem hiding this comment.
Fractional CPU limits round up
When a user sets rr.agentSandbox.sandbox.resources.limits.cpu to a fractional value, divisor: "1" rounds SANDBOX_CPU_LIMIT up to a whole core. For example, a 1.5-core limit is reported as 2. Build tools using that value may start too many threads for the sandbox's limit. Pass a value that preserves the fraction in a unit the consumer expects.
drewmacneil
approved these changes
Oct 4, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

TL;DR
Adds CPU-aware thread pool sizing for sandbox build tools by exposing the container's CPU limit as an environment variable.
What changed?
A new
cpuAwareThreadsoption (defaulting totrue) has been added to the sandbox configuration. When enabled, theSANDBOX_CPU_LIMITenvironment variable is injected into the sandbox container using aresourceFieldRefpointing tolimits.cpu. This allows build tools such astsc,esbuild,Rolldown, andpnpmto size their thread pools based on the container's actual CPU limit rather than the host node's total CPU count. The chart version has been bumped to6.12.2.How to test?
SANDBOX_CPU_LIMITenvironment variable set to the configured CPU limit (e.g.,2).cpuAwareThreads: falseand verify thatSANDBOX_CPU_LIMITis not injected into the container.Why make this change?
Without this change, build tools inside the sandbox container detect the host node's CPU count when sizing their thread pools, which can far exceed the container's actual CPU limit. This leads to over-provisioned thread pools, resource contention, and degraded performance. By passing the container's CPU limit directly, build tools can right-size their concurrency to match available resources.