OpenMetal
Concepts

Routing and capabilities

Understand candidate order, fallback safety, and current provider limits.

Candidate order

Automatic selection tries explicit fallback providers first, then other configured managed or BYOK providers in their configured order.

An explicit provider is primary. Listed fallback providers follow in order. Candidates must be unique.

OpenMetal does not currently calculate cheapest, fastest, reliable, or balanced rankings.

Source support

Portable environments work across all current providers. OCI images work with Blaxel, Daytona, Modal, Northflank, and Vercel. Provider templates work with CodeSandbox, E2B, Freestyle, and Runloop.

Recognized portable environments are metal/base, metal/node, and metal/python.

Runtime support

CodeSandbox and Northflank adapters currently expose lifecycle only, without process execution or file access, so automatic routing never selects them.

Current public process streaming works with Cloudflare, E2B, Modal, and Vercel. Request features.process.ordered_output to route only to them. Process cancellation is not confirmed for those adapters.

Filesystem read and write support is broader. List, delete, append, and parent creation vary by provider; request them under features.filesystem when you depend on them.

Portable leased HTTP endpoints are currently available through Blaxel and Daytona.

Reliable pause and resume are available through CodeSandbox, E2B, Freestyle, Northflank, and Runloop. Daytona pause reporting is inconsistent.

Hard requirements

Source, resources, features, network, and regions are hard requirements. Before calling a candidate, OpenMetal removes it if its declared capabilities cannot satisfy every requirement, records each unmet requirement on the provider attempt, and moves to the next candidate. After provisioning, it checks runtime requirements again against the capabilities discovered on the sandbox and destroys a sandbox that falls short.

When no candidate qualifies, the create operation fails with no_eligible_provider. error.details.attempts lists each provider with its unmet_requirements, for example ["isolation", "network.allow_domains"].

Automatic routing adds a portable baseline: process execution plus file read and write. Set features.process.execute, features.filesystem.read, or features.filesystem.write to false to opt out. Explicit providers only need what you request.

RequirementCurrent support
features.isolationProvider-reported microVM: Blaxel, CodeSandbox, E2B, Runloop, Vercel. VM: Freestyle, Prime Intellect. Container: Cloudflare, Daytona, Modal. Northflank is unknown and never qualifies.
features.processSee runtime support below.
features.filesystemSee runtime support below.
features.public_portsBlaxel only.
features.pause_resumeProviders with reliable pause and resume.
features.ptyNever satisfied. Interactive PTY sessions are not part of the API.
network restrictionsNever satisfied yet. No adapter enforces outbound restrictions, so requests that restrict egress fail closed.
regionsNever satisfied yet. No adapter declares every region it may place a sandbox in.

Provider-reported isolation

Isolation claims come from provider documentation. OpenMetal has not independently verified them.

Fallback safety

Capacity, provider unavailable, known absent timeout, and provider-declined unsupported requests can move to the next candidate. Unknown provider outcomes enter reconciling first so OpenMetal does not create duplicate live capacity.

See route across providers for a complete request.

On this page