Daytona
Agent sandboxes with independent kernel per sandbox and sub-90ms snapshot resume.
Daytona is an AGPL-3.0 sandbox platform where each sandbox gets its own kernel, filesystem and network stack, with snapshot-based resume in under 90ms; it is OCI/Docker-compatible with SDKs for Python, TypeScript, Ruby, Go and Java, and the project has disclosed CVEs including a path-traversal issue (GO-2026-5367) and a cross-tenant data exposure.
Caveat: AGPL-3.0 has strong copyleft implications for hosted derivatives; the project has publicly disclosed several security CVEs.
Key facts
| Category | Execution Sandbox |
|---|---|
| License | AGPL-3.0 |
| Language | — |
| Self-hosted | Yes |
| GitHub stars | 71,667 (2026-10-04) |
| Last push | 2026-07-24 |
| Last verified | 2026-10-04 |
| Repository | https://github.com/daytonaio/daytona |
Tools in this category
Firecracker
AWS's open-source microVM monitor powering Lambda and Fargate.
gVisor
Google's user-space application kernel for workload isolation, delivered as the runsc OCI runtime.
NVIDIA OpenShell
Policy-governed agent runtime that blocks all outbound network traffic by default.