AWS Fargate

Managed container execution for ECS workloads with per-task isolation.

Routing Summary

Use when AWS IAM, networking, and ECS lifecycle ownership are requirements. This is a substrate for building a sandbox service, not a ready-made agent workspace API. Route implementation through AWS Ecosystem.

Verified documentation

AWS documents a separate isolation boundary per Fargate task, including kernel, CPU/memory resources, and network interface. Workspace commands, snapshots, tenant policy, and agent lifecycle still require an application control plane. Compare Cloudflare Sandbox SDK or Vercel Sandbox when a packaged execution API is sufficient. Source: official documentation, checked 2026-09-25

Evidence status

Documentation review only; no account setup, workload benchmark, or isolation test was performed. Keep rules, skills, approvals, source history, and proof in Kevin's control plane. Provider execution must remain replaceable. See Agent Sandboxes for the comparison contract.


Timeline

  • 2026-09-25 | Recovered this provider identity from the July 7 test2 snapshot and rewrote it against current primary documentation. Source: test2 snapshot