Infrastructure & Platforms · core
Sandboxes & Execution Environments
Processes, containers, microVMs, V8 isolates, WebAssembly, capabilities, quotas, and untrusted-code execution.
Mental model
A sandbox is a capability boundary plus resource accounting. Isolation strength, startup cost, syscall surface, and density must match the threat model. Scope: this card owns the mechanisms and their trade-offs — process, container, microVM, V8 isolate, WebAssembly — compared on isolation strength, startup cost, syscall surface and density. Deciding what you are defending against is `security-isolation-boundaries`.
How to study Sandboxes & Execution Environments
Begin by restating the mental model in your own words, then connect it to a concrete system you have built or operated. Name the mechanism, the constraint it addresses, and the trade-off it introduces. Use Swivel: Hardening WebAssembly against Spectre (USENIX Security '21), USENIX Enigma 2023 — Navigating the Sandbox Buffet, Bringing the Web up to Speed with WebAssembly (PLDI '17) to check details, but close the source before writing your explanation. Retrieval is the learning step; rereading is only preparation.
Next, compare Sandboxes & Execution Environments with Observability. Ask what changes in correctness, latency, resource use, operability, and failure recovery. Complete Design exercise: Sandboxes & Execution Environments and preserve the command, input, output, and one failed attempt as evidence. Finish by explaining the idea without jargon to someone who has not studied the track.
Proof of understanding
- Explain the mechanism from first principles and identify the state it reads or changes.
- Give one situation where the concept is the right choice and one where it is not.
- Predict a realistic failure mode before running the drill, then compare the prediction with evidence.
- Connect the result to a roadmap or build artifact instead of treating the concept as isolated trivia.
Learn from primary sources
Practice and explain it back
Design exercise: Sandboxes & Execution Environments
Processes, containers, microVMs, V8 isolates, WebAssembly, capabilities, quotas, and untrusted-code execution. Implement designOutline() returning non-empty values for: threatModel, capabilities, resourceLimits. Each value must name a concrete mechanism or decision.
Expected evidence: A design outline with threatModel, capabilities, resourceLimits plus an explicit failure mode or trade-off.
Open the interactive drill →Review prompts
- Rank containers, microVMs, and V8 isolates on isolation strength versus startup cost, and say what drives the difference.
Build evidence
Synthesize: Infrastructure & Platforms
Design and operate a reproducible, observable, fault-tolerant platform for untrusted workloads. Produce one working system, benchmark, or evidence-backed design that integrates the path.
- Implements or precisely models the core mechanisms from all three milestones
- Includes at least one injected failure or adversarial case and demonstrates recovery
- Reports quality, latency, resource, reliability, or usability measurements relevant to the domain
- Ships a concise architecture note explaining decisions, trade-offs, and remaining risks