█

AI/TLDR

AX (Agent Executor)

Google's declarative orchestrator for running untrusted agent tasks in sandboxes on a Kubernetes cluster

Code Sandboxes & IsolationOpen source
Latest
v0.3.0
Updated
20 Sep 2026
Language
Go
License
Apache-2.0
$go install github.com/google/ax/cmd/ax@latest

What's new

v0.3.020 Sep 2026

AX was restructured into a general-purpose orchestration layer built from three binaries — ax-server, ax-controller and ax-task-runner — and task state moved from Kubernetes custom resources to Redis Streams. The legacy Python harness, ATE client, SQL event log and skill examples were removed.

Overview

AX, short for Agent Executor, is Google's open-source orchestration platform for running autonomous agent workloads at scale. Its README frames agents as their own kind of workload — neither stateless services nor batch jobs — and gives them isolation, state management and cost controls to match. You describe an agentic task in a manifest, and AX sandboxes it, wires up its workspace, fences its network, and keeps it running. The CLI deliberately mirrors kubectl: `ax apply`, `ax get`, `ax describe` and `ax delete` all behave the way a Kubernetes user expects.

Four declarative primitives carry the whole model. A Task runs untrusted agent code in an isolated sandbox with CPU and memory limits, and can be suspended and resumed to checkpoint its state. A Workspace declares the environment once — Git repositories, MCP servers and skill packages — so tasks start warm instead of each agent rebuilding the same setup. A Gateway defines which listeners a task exposes and restricts outbound traffic to an explicit allowlist of hosts and ports. A Model is a named LLM configuration: provider, model identifier, generation parameters, and credentials held in a Kubernetes secret, so keys can be rotated in one place rather than per agent.

Version 0.3.0, released on 2026-09-20, reorganized the project around three binaries. `ax-server` exposes a gRPC API that accepts Task manifests, `ax-controller` runs as a horizontally scaled reconciler that consumes work from Redis Streams, and `ax-task-runner` executes tasks inside sandboxed workers. Task state moved out of Kubernetes custom resources and into Redis so the system can handle millions of short-lived tasks without straining etcd. That release also removed the legacy Python harness, the ATE client, the SQL event log and the bundled skill examples, and added design, concepts, manifest, networking, runner and sandbox docs plus Kubernetes deploy manifests. Running AX needs a Kubernetes cluster, the `ko` build tool, a container registry and access to the Agent Substrate Control API; the `ax` CLI itself is a single `go install`.

What it does

  • Declarative Task manifests that run untrusted agent code in isolated sandboxes with CPU and memory limits
  • Workspace resources that pre-wire Git repos, MCP servers and skill packages so tasks start warm
  • Gateway resources that fence outbound traffic to an explicit allowlist of hosts and ports
  • Model resources that centralize provider, model id, generation parameters and Kubernetes-secret credentials
  • Suspend and resume on a running task to checkpoint its state
  • Interactive shell access into a live task with ax ssh, plus ax watch for streaming status
  • kubectl-style CLI (apply, get, describe, delete) with multi-cluster support through kubectx
  • Three-binary control plane — ax-server (gRPC), ax-controller (Redis Streams reconciler), ax-task-runner (sandboxed workers)

Getting started

Install the ax CLI with Go, deploy the control plane to a Kubernetes cluster with ko, then apply a task manifest. The repository's examples directory holds ready-to-run manifests.

Install the CLI

The ax CLI is a Go binary and installs straight from the repository.

bashbash
go install github.com/google/ax/cmd/ax@latest

Deploy the control plane

Deployment needs a Kubernetes cluster, the ko build tool and a container registry to push images to.

bashbash
make deploy AX_IMAGE_REPO=<your-registry>

Apply a task manifest

Tasks are declared in YAML and applied the same way you apply a Kubernetes object. The examples directory ships a starter manifest.

bashbash
ax apply -f examples/task.yaml
ax get tasks

Watch, inspect and control a running task

ax watch streams a task's status, ax ssh drops you into its sandbox, and suspend/resume checkpoint it.

bashbash
ax watch task task123
ax ssh task123 -- ls -la /workspace
ax suspend task task123
ax resume task task123

Commands and code are distilled from the project's own documentation — always check the official repo for the latest.

When to use it

  • Run large fleets of short-lived coding-agent jobs on a cluster without overloading etcd with per-task custom resources
  • Give an untrusted agent a sandbox whose outbound network is limited to a named allowlist of hosts and ports
  • Define a repository checkout, its MCP servers and its skill packages once as a Workspace, then reuse it across many tasks
  • Keep LLM provider credentials in one Kubernetes secret behind a Model resource instead of copying keys into every agent
  • Suspend a long-running agent task, inspect its sandbox over ax ssh, and resume it from the checkpoint

How AX (Agent Executor) compares

AX (Agent Executor) alongside other open-source code sandboxes & isolation tools AI/TLDR tracks, ranked by GitHub stars.

ToolStarsWhat it does
Daytona★ 71.7kDaytona is an open-source runtime that spins up isolated sandboxes in under 90ms so agents can safely run and persist AI-generated code.
NVIDIA NemoClaw★ 22.6kNVIDIA's reference stack for running OpenClaw, Hermes and LangChain Deep Agents Code inside OpenShell sandboxes, adding managed inference, network policy, snapshots and CLI lifecycle control.
OpenSandbox★ 15.6kOpenSandbox gives AI agents a safe place to run code and commands, with one unified API across Docker and Kubernetes runtimes and SDKs in five languages.
E2B★ 14kE2B is open-source infrastructure that runs AI-generated code inside secure, isolated cloud sandboxes, controlled from JavaScript or Python SDKs.
AX (Agent Executor)★ 12.4kGoogle's declarative orchestrator for running untrusted agent tasks in sandboxes on a Kubernetes cluster
Astrid★ 10.3kA portable Rust runtime that executes software as sandboxed WebAssembly capsules, where every file, network, process and tool call is gated by a signed, revocable, per-principal capability instead of ambient authority.
Cloudflare Computer★ 9.3kA virtual filesystem inside a Durable Object that gives an agent one execution surface across Workers isolates and full Linux containers.
smolvm★ 6.4kA cross-platform CLI that boots sub-second Linux microVMs from a declarative Smolfile, so untrusted or agent-generated code runs behind a hypervisor boundary.