Best sandbox for Devin Outposts in 2026
A Devin Outposts worker needs git, outbound HTTPS and passwordless sudo; the best sandbox adds its own kernel and one machine per session.
A Runtime sandbox already meets every requirement Devin lists for a worker
machine, and with devin worker start --session each Devin session can get a
fresh Firecracker microVM that stops when the session ends. Devin's agent
loop stays in Devin's cloud; the commands, file edits and repository access
run in a machine with its own Linux kernel on Runtime. Five hundred
45-minute sessions a month, each busy for five CPU-minutes, cost
$12.29 on Runtime against
$62.10 on E2B and $62.10 on
Daytona, at rates checked 23 September to 2 October 2026.
How do Devin Outposts work?
Devin's Outposts overview, read on 1 October 2026, splits the work in two. The "agent loop (inference and planning) continues to run in Devin's cloud", while "all command execution, file edits, and repository access happen on machines you operate". A machine joins by running the Devin CLI's worker, which makes "an outbound connection to Devin's cloud and watches the outpost's queue". It needs "only outbound HTTPS access. No inbound ports, public IPs, or VPN tunnels".
The same page lists seven partner platforms, Namespace, Modal, NVIDIA OpenShell, NVIDIA Brev, Daytona, E2B and Cloudflare, and an open-source Kubernetes operator, devin-outpost-k8s.
Does a Runtime sandbox meet Devin's worker requirements?
| What Devin's docs ask of a worker | In a Runtime sandbox |
|---|---|
git on PATH (required) |
Installed: git 2.43 on Ubuntu 24.04 |
| Outbound HTTPS only | Allowed by default; narrow it to Devin's hosts and yours |
Passwordless sudo, on dedicated machines |
Yes; with --session, each session gets its own sandbox |
| Chrome or Chromium, for browser features | Installs with npx @puppeteer/browsers (headless Chrome) |
| A graphical display, for computer use | A desktop with screenshots and input (control a desktop) |
ffmpeg, for screen recording |
Installs with apt (FFmpeg) |
What should a Devin worker machine give you?
- One machine per session. The worker's
--sessionflag claims one session, serves it, then exits. Start a sandbox per session and stop it when the worker exits, and no session ever sees another's files. - Its own kernel. Devin runs commands with
sudoon a worker. In a container that is root on a shared kernel; in a microVM it is root on a machine made for the session. - Your network, from the inside. A paid account can join a sandbox to your private network over a WireGuard tunnel, so Devin reaches an internal Git server or package mirror without anything opening inward.
- Your toolchain, prebuilt. Build the worker's image from your Dockerfile once (images), and each session starts with the CLI, your compilers and your caches in place.
- A bill for use. A session's machine mostly waits on Devin's planning; Runtime bills that time at its CPU floor of a twentieth of a vCPU per vCPU.
What do Devin sessions cost on each sandbox?
Five hundred sessions a month, each 45 minutes on a 2 vCPU, 4 GiB machine and busy for 300 CPU-seconds:
| Provider | Isolation | A month of sessions | Runtime costs less by |
|---|---|---|---|
| Runtime | Firecracker microVM | $12.29 | |
| Cloudflare Sandbox | A container in its own VM | $24.38 | 50% |
| E2B | Firecracker microVM | $62.10 | 80% |
| Daytona | Containers by default | $62.10 | 80% |
| Modal | gVisor, a shared kernel | $89.24 | 86% |
A run on Runtime, recorded 1 October 2026
TypeScriptimport { Sandbox } from "withruntime";export async function serve(sessionId: string) { await using sbx = await Sandbox.create({ timeoutSeconds: 4 * 3600 }); await sbx.exec("curl -fsSL https://cli.devin.ai/install.sh | bash", { timeoutMs: 600_000 }); // Devin's worker claims this one session, serves it, and exits. return sbx.exec(["bash", "-lc", `~/.local/bin/devin worker start --session ${sessionId}`], { timeoutMs: 4 * 3600 * 1000, });}On 1 October 2026 the installer ran in a fresh production sandbox and put the
CLI in ~/.local/bin. Serving a session needs your Devin organization's
outpost and sign-in, so the run stopped at the CLI:
textcurl -fsSL https://cli.devin.ai/install.sh | bash Installed devin v3000.11.3devin --version devin 3000.11.3 (9c803229faa4)devin worker start --help Start the Outposts worker and serve queued sessions --session <SESSION_ID> Claim and serve this one session, then exitWhen might another sandbox fit better?
- macOS or GPUs. A Runtime sandbox is Linux on CPUs. Devin's partner list includes Namespace for macOS on Apple silicon and NVIDIA Brev for GPU instances.
Sources
Checked 1 October 2026.
- Devin Outposts overview: the split between Devin's cloud and your machines, the worker's connection and requirements, and the partner list
- Devin CLI: the install command
- Each provider's published rates, checked 23 September to 2 October 2026, as the pricing guide lists them
- The recorded run: the Devin CLI 3000.11.3 from Devin's installer, in a production sandbox on 1 October 2026