Skip to content

Add Cloudflare sandboxes with Tailscale SSH - #67

Open
czpython wants to merge 1 commit into
mainfrom
codex/cloudflare-sandbox
Open

czpython wants to merge 1 commit into
mainfrom
codex/cloudflare-sandbox

Conversation

@czpython

@czpython czpython commented Oct 4, 2026

Copy link
Copy Markdown
Owner

Adds provider: "cloudflare" through an authenticated Worker and the native Durable Object Container API. Hosts use Tailscale SSH. The included image runs userspace Tailscale without systemd or a TUN device.

The Worker accepts deployed image aliases and Cloudflare instance sizes, runs bootstrap once per host name, keeps active VMs awake, and deletes by stable name. Failed starts trigger cleanup; deletion during bootstrap cannot activate the deleted host. Provider settings, deployment instructions, and a Worker CI job are included.

Research: Cloudflare Container API and Tailscale userspace networking.

Validation: 780 Python tests and 12 Worker tests passed. Ruff, format check, Pyright, TypeScript, Docker image build, userspace tailscaled startup, and Wrangler deployment dry run passed. npm audit reports no vulnerabilities.

No live Cloudflare VM, tailnet SSH connection, or deployment was tested. The Worker must be deployed in the operator's account. Userspace Tailscale does not route ordinary application traffic: the secrets proxy needs a reachable outbound address. VMs and files can be lost on a provider stop; there is no automatic restore.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant