Class ContainerCodeExecutor
- All Implemented Interfaces:
AutoCloseable
Code is run via docker exec (as in ADK Python), so the image only needs
python3 on its PATH; any image ENTRYPOINT is bypassed. By default a single container is
created on first use and reused for every executeCode(InvocationContext, CodeExecutionUtils.CodeExecutionInput) call, as in ADK Python. With the
strict sandbox enabled, each execution instead runs in a fresh container that is force-removed
afterwards, so one execution cannot observe or affect another's environment.
Sandboxing is opt-in. By default the execution container is unrestricted (network
enabled, writable filesystem, no resource or time limits), matching the previous behavior so
existing callers are not broken; a warning is logged when it is used this way. Call setStrictSandbox(true) to harden each container: no network (unless
re-enabled via setNetworkEnabled(boolean)), all Linux capabilities dropped, no privilege
escalation, a read-only root filesystem with a small writable /tmp tmpfs, memory/PID
limits, and a wall-clock execution timeout. Strict sandboxing becomes the default in ADK 2.0.
The execution timeout and memory limit used by the strict sandbox are configurable via setExecutionTimeoutSeconds(long) and setMemoryLimitBytes(long).
This executor holds a DockerClient; call close() (or rely on the registered
JVM shutdown hook) to release its connections and threads. As with ADK Python, an abrupt JVM
termination (e.g. SIGKILL) during an execution may leave a container behind.
-
Constructor Summary
ConstructorsConstructorDescriptionContainerCodeExecutor(String baseUrl, String image, String dockerPath) Deprecated.Use one of the static factory methods instead. -
Method Summary
Modifier and TypeMethodDescriptionvoidclose()Removes the shared container, if one was created, and closes the underlying Docker client, releasing its connections and threads.executeCode(InvocationContext invocationContext, CodeExecutionUtils.CodeExecutionInput codeExecutionInput) Executes code and return the code execution result.static ContainerCodeExecutorfromDockerPath(String dockerPath) Creates a ContainerCodeExecutor from a Dockerfile path.static ContainerCodeExecutorfromDockerPath(String baseUrl, String dockerPath) Creates a ContainerCodeExecutor from a Dockerfile path.static ContainerCodeExecutorCreates a ContainerCodeExecutor from an image.static ContainerCodeExecutorCreates a ContainerCodeExecutor from an image.booleanIf true, extract and process data files from the model request and attach them to the code executor.setExecutionTimeoutSeconds(long executionTimeoutSeconds) Sets the maximum wall-clock time (in seconds) a single execution may run, in the strict sandbox, before its container is force-removed (killed).setMemoryLimitBytes(long memoryLimitBytes) Sets the per-execution container memory limit, in bytes, used by the strict sandbox.setNetworkEnabled(boolean networkEnabled) Enables or disables container networking when the strict sandbox is on.setStrictSandbox(boolean strictSandbox) Enables the strict sandbox.booleanstateful()Whether the code executor is stateful.Methods inherited from class BaseCodeExecutor
codeBlockDelimiters, errorRetryAttempts, executionResultDelimitersModifier and TypeMethodDescriptioncom.google.common.collect.ImmutableList<com.google.common.collect.ImmutableList<String>> The list of the enclosing delimiters to identify the code blocks.intThe number of attempts to retry on consecutive code execution errors.com.google.common.collect.ImmutableList<String> The delimiters to format the code execution result.Methods inherited from class JsonBaseModel
fromJsonNode, fromJsonString, getMapper, toJson, toJsonNode, toJsonStringModifier and TypeMethodDescriptionstatic <T extends JsonBaseModel>
TfromJsonNode(com.fasterxml.jackson.databind.JsonNode jsonNode, Class<T> clazz) Deserializes a JsonNode to an object of the given type.static <T extends JsonBaseModel>
TfromJsonString(String jsonString, Class<T> clazz) Deserializes a Json string to an object of the given type.static com.fasterxml.jackson.databind.ObjectMapperReturns the mutable ObjectMapper instance used by ADK.toJson()Serializes this object (i.e., the ObjectMappper instance used by ADK) to a Json string.protected static com.fasterxml.jackson.databind.JsonNodetoJsonNode(Object object) Serializes an object to a JsonNode.static StringtoJsonString(Object object) Serializes an object to a Json string.
-
Constructor Details
-
ContainerCodeExecutor
Deprecated.Use one of the static factory methods instead.Initializes the ContainerCodeExecutor. Either dockerPath or image must be set.
-
-
Method Details
-
fromImage
Creates a ContainerCodeExecutor from an image.- Parameters:
baseUrl- The base url of the user hosted Docker client.image- The tag of the predefined image or custom image to run on the container.
-
fromImage
Creates a ContainerCodeExecutor from an image.- Parameters:
image- The tag of the predefined image or custom image to run on the container.
-
fromDockerPath
Creates a ContainerCodeExecutor from a Dockerfile path.- Parameters:
baseUrl- The base url of the user hosted Docker client.dockerPath- The path to the directory containing the Dockerfile.
-
fromDockerPath
Creates a ContainerCodeExecutor from a Dockerfile path.- Parameters:
dockerPath- The path to the directory containing the Dockerfile.
-
setNetworkEnabled
Enables or disables container networking when the strict sandbox is on. In strict mode networking is disabled by default so executed code cannot reach the network (including the cloud metadata endpoint); passtrueto allow it. Has no effect unlesssetStrictSandbox(boolean)is enabled — without the sandbox the container always has network access. -
setExecutionTimeoutSeconds
Sets the maximum wall-clock time (in seconds) a single execution may run, in the strict sandbox, before its container is force-removed (killed). Defaults to 60 seconds. Has no effect unlesssetStrictSandbox(boolean)is enabled. -
setMemoryLimitBytes
Sets the per-execution container memory limit, in bytes, used by the strict sandbox. Defaults to 512 MiB. Has no effect unlesssetStrictSandbox(boolean)is enabled. -
setStrictSandbox
Enables the strict sandbox. When enabled, each execution runs in its own fresh container (force-removed afterwards) that is hardened: no network (unless re-enabled viasetNetworkEnabled(boolean)), all Linux capabilities dropped, no privilege escalation, a read-only root filesystem (writable/tmponly), memory/PID limits, and a wall-clock timeout. While disabled, a single unrestricted container is reused across executions, as before.Disabled by default so enabling the sandbox is not a breaking change for existing callers. While it is disabled a warning is logged, because running untrusted, model-generated code without the sandbox is dangerous. Strict sandboxing becomes the default in ADK 2.0.
-
stateful
public boolean stateful()Description copied from class:BaseCodeExecutorWhether the code executor is stateful. Default to False.- Overrides:
statefulin classBaseCodeExecutor
-
optimizeDataFile
public boolean optimizeDataFile()Description copied from class:BaseCodeExecutorIf true, extract and process data files from the model request and attach them to the code executor.Supported data file MimeTypes are [text/csv]. Default to False.
- Overrides:
optimizeDataFilein classBaseCodeExecutor
-
executeCode
public CodeExecutionUtils.CodeExecutionResult executeCode(InvocationContext invocationContext, CodeExecutionUtils.CodeExecutionInput codeExecutionInput) Description copied from class:BaseCodeExecutorExecutes code and return the code execution result.This method may perform blocking operations.
- Specified by:
executeCodein classBaseCodeExecutor- Parameters:
invocationContext- The invocation context of the code execution.codeExecutionInput- The code execution input.- Returns:
- The code execution result.
-
close
public void close()Removes the shared container, if one was created, and closes the underlying Docker client, releasing its connections and threads.- Specified by:
closein interfaceAutoCloseable
-