OptionalbaseOptional base url of a user-hosted Docker daemon (e.g. tcp://host:2375).
OptionaldockerInjected Docker client, primarily for testing so unit tests never touch a
real Docker daemon. Defaults to a new client built from baseUrl.
OptionaldockerPath to a directory containing a Dockerfile. If set, the image is built
from it instead of using a prebuilt tag. Either image or dockerPath
must be set.
OptionalimageTag of the predefined or custom image to run on the container. Either
image or dockerPath must be set. Defaults to adk-code-executor:latest
when only dockerPath is given.
OptionalnetworkStart the container with networking enabled. Defaults to false so untrusted, model-generated code cannot reach the network (the cloud metadata endpoint, internal services, or exfiltration destinations).
OptionaltimeoutWall-clock timeout in seconds for a single execution. Must be greater than 0; defaults to 300. Every execution shares one long-lived container, so an unbounded run (e.g. a loop emitted by the model) would burn that container's CPU for every later caller. Raise it rather than remove it for a computation that legitimately runs longer.
Options for ContainerCodeExecutor.