Skip to content

Build1 publisher2 min readPublished

Microsoft puts Container Apps Express on prewarmed microVM sandboxes built for agents

Microsoft made Azure Container Apps Express generally available on a sandbox layer that starts isolated microVMs from prewarmed pools in under a second. The agent-oriented engineering sits in that layer, while Express on top keeps a narrow slice of Container Apps features.

The Engineer · Build desk

Illustration accompanying Microsoft puts Container Apps Express on prewarmed microVM sandboxes built for agents

What happened

  • Express takes a container image, a region and app configuration, then provisions compute, ingress and scaling itself.
  • Sandboxes can suspend and resume, snapshotting full state including memory and disk and restoring it in under a second.
  • Microsoft positions direct use of Sandboxes for agent platforms and secure code execution, managed through a Microsoft.App/SandboxGroups resource.
  • Express excludes custom domains, zone redundancy, GPU workloads, Dapr, OpenTelemetry and jobs, among other Container Apps features.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • constraint An agent updating an Express app cannot run the new version beside the old one behind a traffic split, because multiple revisions are excluded.
  • decision Outbound subnets are fixed once set, so whoever creates the app, a person or an agent, has to choose network placement correctly at creation time.
  • exposure Express apps that call each other go over public URLs because service discovery is absent, leaving IP restrictions as the listed control on who can reach them.
  • cost With Key Vault references and system-assigned managed identities excluded, secrets are set manually per app, and rotating them is work for whatever created the app.

The subsecond startup figure is a property of the pool. Microsoft's documentation says Sandboxes provision from prewarmed pools and burst to thousands of concurrent sandboxes [6]. For the number to hold on a given workload, a warm slot has to be waiting in that region when the request arrives. The burst also has to fit inside what the pool holds. The InfoQ report does not give a startup time for a request that misses the pool.

The agent framing is Microsoft's own. Its material calls Express developer-first and agent-first, and says: "AI-assisted workflows can create and update apps far faster than anyone can configure infrastructure by hand." [5] In my view that sentence describes the sandbox layer better than it describes Express. Snapshotting memory along with disk is the hard engineering in this release, and it sits underneath [7]. On Reddit, commenter brianveldman separated Sandboxes from Container Apps jobs by lifecycle: "ACA Jobs are designed for run to completion tasks and batch processing (start to run to complete), while Sandboxes provide programmable, isolated compute environments with lifecycle control." [12]

Reddit users describe the primitive in use before GA. "ACA Sandboxes actually underpin a lot of core Azure services including Foundry Hosted Agents," commenter MuhBlockchain wrote [9]. That claim rests on one commenter. Another, tankerkiller125real, wrote that his team runs them as Python sandboxes for a customer-facing agent harness [10]. Minute_Passion_8077, who deploys them for clients through Bicep, wrote: "Just point it to an image and off you go. Dont need it? Scale to 0." [11]

Google shipped the same pairing in Kubernetes Engine this year [15]. GKE combines Pod snapshots, which checkpoint CPU and GPU memory through gVisor, with GKE Agent Sandbox for untrusted agent code [15]. Microsoft instead puts each workload in its own hardware-isolated microVM [6]. InfoQ describes both as answers to one question: how to give an agent an isolated environment that costs nothing while idle and returns in under a second [21]. On the Microsoft side, scale to zero and per-second billing cover the idle half [4]. One commenter, RustOnTheEdge, met the microVM description with open skepticism and did not elaborate [13].

Two vendors have now added an isolation and snapshot layer for agent code beside their existing container platforms [2][15]. The platforms underneath stay in place. Microsoft advises a standard Container Apps environment for teams that need more control over networking, GPU compute, advanced configuration or Dapr [20]. Express, the app layer on top, keeps eight Container Apps capabilities and drops eleven, going by the lists in InfoQ's report [1]. The same documentation lists rapid prototyping as a use case [20].

What to watch

  • Whether Microsoft brings Sandboxes to AKS: a Reddit user whose team runs AKS for requirements Container Apps does not meet asked, and the question went unanswered.
  • Whether Microsoft confirms a Reddit commenter's claim that Sandboxes already underpin Foundry Hosted Agents.
  • Published startup times for bursts that exceed the prewarmed pool, which would show how far the subsecond figure transfers.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories