Runtime

What is object storage?

Object storage keeps data as whole objects in buckets, each addressed by a key over HTTP, not as files in folders or disk blocks.

A Runtime sandbox mounts your bucket in Amazon S3, Cloudflare R2 or Google Cloud Storage as a folder without ever holding the bucket's key. You store the key once as a secret, and the host signs the sandbox's requests on the way out, so code in the sandbox reads and writes the files and cannot copy the credential (mount your own bucket).

How it is organised

Amazon's S3 guide gives the model in three nouns. An object "is a file and any metadata that describes the file". A bucket "is a container for objects". A key "is the unique identifier for an object within a bucket". There are no real directories: photos/puppy.jpg is one key that happens to contain a slash.

Object, block and file storage

Kind Addressed by Changed by Typical use
Object Bucket and key, HTTP Replacing the whole object Datasets, backups, media, build outputs
Block A disk's block numbers Writing any block A machine's root disk, databases
File A path in a tree Writing part of a file Shared folders, home directories

Object stores trade in-place edits for scale and price: S3 promises strong read-after-write consistency, and Cloudflare R2 stores data for $0.015 per GB-month with no charge for egress.

Object storage and sandboxes

An agent's input data usually already lives in a bucket. Mounting it saves the download on every run, and keeping the key on the host means a prompt injection in that data cannot send the credential anywhere. Runtime keeps its own state on disks instead: a sandbox's files, a volume that outlives sandboxes, and snapshots copied off their server (snapshots survive their server). Runtime does not sell an object store of its own today; it mounts yours.

Sources

Checked 27 September 2026.