Build1 publisher2 min readPublished
Microsoft puts Container Apps Express on prewarmed microVM sandboxes built for agents
Microsoft made Azure Container Apps Express generally available on a sandbox layer that starts isolated microVMs from prewarmed pools in under a second. The agent-oriented engineering sits in that layer, while Express on top keeps a narrow slice of Container Apps features.
The Engineer · Build desk

What happened
- Express takes a container image, a region and app configuration, then provisions compute, ingress and scaling itself.
- Sandboxes can suspend and resume, snapshotting full state including memory and disk and restoring it in under a second.
- Microsoft positions direct use of Sandboxes for agent platforms and secure code execution, managed through a Microsoft.App/SandboxGroups resource.
- Express excludes custom domains, zone redundancy, GPU workloads, Dapr, OpenTelemetry and jobs, among other Container Apps features.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- constraint An agent updating an Express app cannot run the new version beside the old one behind a traffic split, because multiple revisions are excluded.
- decision Outbound subnets are fixed once set, so whoever creates the app, a person or an agent, has to choose network placement correctly at creation time.
- exposure Express apps that call each other go over public URLs because service discovery is absent, leaving IP restrictions as the listed control on who can reach them.
- cost With Key Vault references and system-assigned managed identities excluded, secrets are set manually per app, and rotating them is work for whatever created the app.
The subsecond startup figure is a property of the pool. Microsoft's documentation says Sandboxes provision from prewarmed pools and burst to thousands of concurrent sandboxes [6]. For the number to hold on a given workload, a warm slot has to be waiting in that region when the request arrives. The burst also has to fit inside what the pool holds. The InfoQ report does not give a startup time for a request that misses the pool.
The agent framing is Microsoft's own. Its material calls Express developer-first and agent-first, and says: "AI-assisted workflows can create and update apps far faster than anyone can configure infrastructure by hand." [5] In my view that sentence describes the sandbox layer better than it describes Express. Snapshotting memory along with disk is the hard engineering in this release, and it sits underneath [7]. On Reddit, commenter brianveldman separated Sandboxes from Container Apps jobs by lifecycle: "ACA Jobs are designed for run to completion tasks and batch processing (start to run to complete), while Sandboxes provide programmable, isolated compute environments with lifecycle control." [12]
Reddit users describe the primitive in use before GA. "ACA Sandboxes actually underpin a lot of core Azure services including Foundry Hosted Agents," commenter MuhBlockchain wrote [9]. That claim rests on one commenter. Another, tankerkiller125real, wrote that his team runs them as Python sandboxes for a customer-facing agent harness [10]. Minute_Passion_8077, who deploys them for clients through Bicep, wrote: "Just point it to an image and off you go. Dont need it? Scale to 0." [11]
Google shipped the same pairing in Kubernetes Engine this year [15]. GKE combines Pod snapshots, which checkpoint CPU and GPU memory through gVisor, with GKE Agent Sandbox for untrusted agent code [15]. Microsoft instead puts each workload in its own hardware-isolated microVM [6]. InfoQ describes both as answers to one question: how to give an agent an isolated environment that costs nothing while idle and returns in under a second [21]. On the Microsoft side, scale to zero and per-second billing cover the idle half [4]. One commenter, RustOnTheEdge, met the microVM description with open skepticism and did not elaborate [13].
Two vendors have now added an isolation and snapshot layer for agent code beside their existing container platforms [2][15]. The platforms underneath stay in place. Microsoft advises a standard Container Apps environment for teams that need more control over networking, GPU compute, advanced configuration or Dapr [20]. Express, the app layer on top, keeps eight Container Apps capabilities and drops eleven, going by the lists in InfoQ's report [1]. The same documentation lists rapid prototyping as a use case [20].
What to watch
- Whether Microsoft brings Sandboxes to AKS: a Reddit user whose team runs AKS for requirements Container Apps does not meet asked, and the question went unanswered.
- Whether Microsoft confirms a Reddit commenter's claim that Sandboxes already underpin Foundry Hosted Agents.
- Published startup times for bursts that exceed the prewarmed pool, which would show how far the subsecond figure transfers.