Cloudflare Just Made AI Agent Sandboxes 6× FasterAI agents increasingly need their own computers. Cloudflare’s latest Containers architecture makes those computers faster to create, easier to suspend, and much more programmable.The Network Layer Problem Most Privacy Stacks Don’t Address (Sponsor)Your carrier operates at a layer your privacy settings can’t reach. Privacy engineering lives at the application layer — encryption in transit, zero-knowledge design, data minimization. The network layer gets less scrutiny. Your carrier sits below all that. It sees your IMSI — a static identifier tied to your SIM that persists across every tower connection, regardless of VPN, DNS, or OS. It also sees your real number, call and text metadata, and location via tower triangulation. No application-layer config touches it. Cape rotates the IMSI every 24 hours, resetting the trail at the only layer where the problem lives. How fast can a model generate tokens? How much context can it hold? How cheaply can inference run? How many GPUs does it take to serve millions of users? Agentic AI introduces a very different infrastructure problem. Once the model decides what to do, where does the work actually happen? A coding agent cannot modify a repository merely by generating text. It needs a filesystem. It may need Git, Python, Node.js, package managers, compilers, shells, development servers, browsers, credentials, and network access. In other words, an increasingly capable agent needs something resembling its own computer. The obvious solution is a sandboxed container. But traditional container infrastructure was designed primarily around relatively long-lived applications, not thousands of temporary computers created dynamically by AI agents. Cloudflare is now rebuilding that model. Its new Containers architecture introduces a Cloudflare reports that median startup under the new architecture fell from 4.049 seconds to 648 milliseconds — a 6.2× improvement. P95 dropped from 5.839 seconds to 910 ms, while P99 fell from 6.717 seconds to 1.129 seconds. Those numbers are impressive. But the more important story is what Cloudflare changed underneath. The sandbox is evolving from something developers deploy ahead of time into something an agent system can create, configure, pause, restore, and eventually discard as part of the agent’s workflow. That could become a fundamental building block of the emerging agent cloud. The Container Model Was Built for Applications, Not AgentsTraditional container infrastructure assumes that developers generally know what they are deploying beforehand.
The platform places instances somewhere in the infrastructure and routes work toward them. That model makes sense for an API server or background service. An AI agent behaves differently. The task itself may determine what computer the agent needs. One request might require a lightweight Node.js environment. Another could involve compiling a large Rust project and need significantly more CPU and memory. A Python data-analysis task might need another image entirely. And those environments may only exist for a few minutes. Cloudflare describes an agent workspace as something created while the agent is working. Its image, resources, tools, and starting filesystem may all depend on the task, and the workspace might disappear between requests or need to return days later. Previously, different environments could mean different Cloudflare applications, namespaces, and routing logic. With the new That changes the infrastructure flow from: Deploy computer → receive work to: Receive work → decide which computer is needed → create computer And that distinction becomes increasingly important as agents become more autonomous. This separation is one of the most interesting parts of Cloudflare’s architecture. Every Container is attached to a Durable Object — a stateful controller that can exist separately from the Linux environment. Cloudflare describes the Container as effectively becoming a compute extension of the Durable Object. The Container supplies Linux, while the Durable Object retains identity, state, policy, and lifecycle control. That maps remarkably well to agents. An agent does not necessarily need its Linux environment running continuously. It may call a model and wait several seconds. It may wait minutes for a human approval. It could stop overnight and continue tomorrow. Keeping a full Linux environment running throughout those idle periods wastes compute. Instead:
Why 648 Milliseconds Matters |