Secure, Sandboxed Runtimes for Every Agent You Build.

Spin up pre-configured or fully custom code execution environments in seconds, then reuse the same governed sandbox across Chat and agent harnesses.

Hundreds of packages ready to install in any custom environment
Data Analysis and Visualizationpandasnumpymatplotlibplotlyseabornpolarsscipybokeh Automation and IntegrationsrequestshttpxaiohttppydanticPyYAMLclickrichloguru Web and API Developmentfastapiflaskdjangosqlalchemyuvicornstarlettejinja2gunicorn Cloud and Databaseboto3duckdbpymongoredispsycopg2-binary Document and File Processingopenpyxlpdfplumberpython-docxpython-pptxreportlabpypdf Image and Mediapillowopencv-pythonmoviepyimageiopydubtifffile Development Toolsipythontqdmtyperpytestblackruffmypy Math and Optimizationcvxpynetworkxsympyortoolspulpz3-solver

Your code and its pinned packages run inside the isolation boundary; the host filesystem and the rest of the network stay outside, and CPU and memory are capped for every run. Credentials arrive by name from Secrets Manager as environment variables, never baked into the image or written to logs.

Demo

From Empty Workspace to a Running Job

A 60-second walkthrough in ThinkStack: describe a runtime, approve the assistant’s plan, watch it build, then run code in the sandbox from chat. Pause whenever you want a closer look.

Why Teams Choose It

Everything a Runtime Should Be

Six things a team stops having to build, operate, and argue about.

Hard Sandbox Isolation

Every runtime executes in an isolated AgentCore sandbox — no host filesystem, no lateral network, CPU and memory capped per run.

AI-Assisted, Fully Governed

Describe the environment you want; the assistant proposes a config, resolves every package against your indexes, and applies it once you approve.

Governed Dependencies

Pin Python, npm, and system packages. Only real, resolvable packages get installed — no guessing, no supply-chain surprises.

Instant Provisioning

Watch environments move from Building to Active in seconds, then track live status, created time, and health at a glance.

Reusable Across ThinkStack

Attach any active runtime to a Chat’s Code tool or an agent harness.

Full Observability

Every execution reports tool calls, success/failure, duration, and token usage — so you can audit exactly what ran where.

The Work It Takes Off Your Team

Do It Yourself vs. ThinkStack Runtimes

Everything a platform team would otherwise build and maintain, already in place.

Task
Do It Yourself
ThinkStack Runtimes
Defining the environment
Write and maintain Dockerfiles and YAML
Describe it in plain words; the assistant drafts the configuration
Pinning dependencies
Resolve versions and conflicts by hand
Python, npm and system packages resolved and pinned for you
Building the image
Run your own build pipeline and registry
Built in the background, Active when it is ready
Isolating each run
Configure containers, network rules and limits yourself
Every run in its own sandbox, with CPU and memory caps
Reusing it everywhere
Recreate the setup for each workspace and agent
One runtime for Chat and agent harnesses
Auditing what ran
Stitch logs together after the fact
Tool calls, duration and token usage recorded for every execution
Keeping images current
Patch base images on your own schedule
Curated base images, regularly patched
Available Templates

Start From a Template or a Curated Base Image

Don’t want to build from scratch? Attach the ready-made Pre-Configured Environment, or start from a regularly patched base image and layer exactly what you need with pip, npm and apt.

The Pre-Configured Environment in ThinkStack, with Python 3.11 and Node.js 20. Its capability areas list data analysis, web and API development, document processing, media, and development tools.

Python 3.11

DebianARM64

Data analysis and geospatial work — pandas, numpy, xarray, rasterio, geopandas and friends.

Node.js 20

LTSARM64

Service and integration testing with the npm ecosystem, jest, and supertest.

Ubuntu 22.04

LTSARM64

A general-purpose base for system tooling and mixed-language workloads.

Frequently Asked Questions

Common questions about Agent Runtime Environments.

What is a runtime environment for?+
Running code an agent writes, somewhere you can audit. Each runtime is a pre-configured or custom code execution environment that provisions in seconds, and the same governed sandbox can then be reused across chat, agent harnesses and pipeline steps rather than configured separately for each.
How do we control what gets installed?+
Python, npm and system packages are pinned, and only real, resolvable packages are installed — the assistant resolves every package against your own indexes rather than guessing, and anything it can't resolve is flagged rather than invented. Proposed changes are listed individually for you to approve before anything is applied.
Do we have to write Dockerfiles?+
No. Choose a curated base image or describe what the environment is for, and the assistant stages a proposed config for you to approve. Base images cover Python 3.11 for data science, ML and geospatial work, Node.js 20 for service and integration testing, and Ubuntu 22.04 for general tooling — curated and regularly patched.
Where can a runtime be used once it exists?+
Attach an active runtime to a workspace's Code tool so a whole team runs analysis in the same sandbox with the same packages and limits every session, or give it to an agent so its code steps execute against pinned dependencies and capped resources with a trace for every call.