Open source

All of OmniRun, under Apache-2.0.

The server, the in-VM agent, the gateway, the CLI and the SDKs are the same code we run in the managed service. Install it on one Linux box, read every line, and change what you need.

Apache-2.0x86_64 Linux with KVMWritten in Go
Source opens soon: Apache-2.0, public shortly. Questions: hello@omnirun.io
root@your-kvm-host · ~
# check the host, then install one node
sudo omnictl doctor
sudo omnictl install --single-node --loop-size 50G
# or put the thin pool on an empty disk:
# sudo omnictl install --single-node --disk /dev/nvme1n1
# load the admin key, create a sandbox
export OMNIRUN_API_KEY="$(sudo cat \ /opt/omnirun/configs/admin.key)"
curl -X POST http://<host>:8080/sandboxes \ -H "X-API-Key: $OMNIRUN_API_KEY" \ -d '{"templateID": "python-3.11"}'
The API serves plain HTTP on :8080. Put your own TLS proxy in front before you expose it.
What is open

Every part you need to run sandboxes.

The managed service runs this same sandbox stack, operated by us on hosts in Finland. Nothing you need to run OmniRun yourself sits behind a paid tier.

ComponentWhat it doesWhere
Sandbox serverThe REST API, sandbox lifecycle manager, Firecracker driver, LVM thin-provisioned disks and per-VM network namespaces.cmd/omnirun
In-VM agentThe static binary inside every sandbox: commands, streaming, PTY, files, interpreter contexts and desktop control.cmd/agent
Accounts and accessMagic-link sign-in, TOTP, API tokens, admin keys and per-user sandbox ownership. A single node starts with the admin key only; sign-in is switched on in the node config (auth_mode = "hybrid" and a Resend key).internal/auth
Quotas and usage eventsPer-user limits and metered usage you can feed into your own billing, with the gateway. Pricing is configuration; metering-only by default.cmd/gateway
Previews, vault and audit logPreview URLs for sandbox ports, a hash-chained audit log and a credential vault. Previews and the durable audit log run on the node but are off on a fresh install: previews need a wildcard domain (preview_domain), the audit log needs audit_log_path. The vault comes with the gateway.cmd/omnirun
Multi-node gateway (beta)Node registry, routing and reconciliation for running more than one box.cmd/gateway
Egress filteromni-sniproxy, the opt-in per-domain egress filter for HTTPS traffic.cmd/omni-sniproxy
omnictlThe install, doctor and operations CLI for the box you run OmniRun on.cmd/omnictl
TemplatesDockerfiles and build scripts for the Python, Node and agent templates.scripts/
SDKs and integrationsThe TypeScript SDK, the Python SDK (public at launch), the CLI, LangChain and LlamaIndex tools, and examples.@omnirun/sdk

What stays private: a14a's own deployment configuration, node inventory and runbooks; integrations built for specific a14a clients; the billing setup of the managed service; this website and the managed dashboard.

Self-host

One box, one command.

The single-node installer sets up LVM thin storage, the network bridge, the OmniRun service and the default template snapshot.

The single-node install is admin-API-key only, with preview URLs, magic-link sign-in and the durable audit log switched off. The node runs all three once configured: auth_mode = "hybrid" with a Resend key for sign-in, preview_domain (and optionally a preview TLS cert) for previews, and audit_log_path for the hash-chained audit log. Per-user quotas, usage metering, the credential vault and more than one node come with the gateway, which you set up on top of the node.

CPUx86_64 with hardware virtualisation
KernelLinux with KVM (/dev/kvm present): bare metal, or a VM with nested virtualisation
Memory and diskAt least 8 GB RAM and 30 GB free disk. The installer refuses to run below that.
StorageA sparse loop file (--loop-size) or an empty block device (--disk) for the LVM thin pool
DistroUbuntu 24.04 is tested. Others get a warning and may need packages installed by hand.
AccessRoot, for networking and storage setup
Cloud VMs. Most need nested virtualisation turned on, and many do not support it. Bare metal is the reliable choice. No Kubernetes, Nomad or external database: state lives in SQLite.
Self-host or managed

Same API. Different operator.

Start on one and move to the other without rewriting code. Only the base URL and token change.

Side by side

Where it runs, who operates it, and what is included.

Self-hostedManaged OmniRun
CodeThe same Apache-2.0 releaseThe same Apache-2.0 release
Where it runsYour hardware, your region, your networkEU infrastructure operated by a14a
Who operates itYou: upgrades, kernels, templates, backupsa14a: upgrades, monitoring and incident response
Accounts, tokens, quotasIncluded; sign-in is switched on in config, per-user quotas need the gatewayIncluded
TemplatesBuild your own from the template scriptsPrebuilt Python, Node and agent templates
Egress allowlistsOpt-in SNI proxy, HTTPS onlyOpt-in SNI proxy, HTTPS only
SupportGitHub issues and discussionsDirect line to the team that builds it
CostYour hardwareAgreed per client or team
Managed OmniRun is arranged per client or team.Talk to us about managed
Roadmap

What ships now, and what is next.

OmniRun is an ephemeral sandbox today. The next release makes sandboxes persistent and forkable. The comparison page shows where that leaves us against the rest of the field.

v0.1 · now

MicroVM sandboxes

A Firecracker VM per sandbox, snapshot restore, copy-on-write disks, commands, code and files.

Available
v0.1

Single-node install

One-command install on a single x86_64 Linux host with KVM. Python and Node templates built in CI.

In the v0.1 release
v0.1 · now

Sign-in, previews and audit log

Magic-link sign-in, preview URLs and the hash-chained audit log run on the node, switched on in config. Per-user quotas and metering come with the gateway.

Available
v0.1 · now

Network controls

Internet on or off for base templates, and HTTPS hostname allowlists through the opt-in SNI proxy.

Available
v0.1

Signed releases

Release binaries with checksums and an SBOM.

In the v0.1 release
v0.2

Hibernate

Pause a sandbox to disk, and sandboxes that survive a restart.

Coming in v0.2
v0.2

Fork and snapshots

Fork a running sandbox, and user snapshots that start new sandboxes.

Coming in v0.2
v0.2

Template builds and metrics

A template build API (Dockerfile to template), and Prometheus and OpenTelemetry metrics.

Coming in v0.2
Later

Driven by what people run

Per-sandbox CPU, memory and disk sizing, secrets that never enter the VM, SSH and IDE access, and persistent volumes.

Planned
License and contributing

Apache-2.0, with a DCO.

Everything public is licensed under Apache-2.0, the same license as Firecracker. You can embed OmniRun in your own product, modify it and run it commercially, and you get the patent grant. Contributions use a Developer Certificate of Origin instead of a CLA, so you keep the copyright to your work.

  • Pick an issue. Look for good first issue, or open one to discuss a bigger change first.
  • Read the guide. CONTRIBUTING.md covers the build, the tests and the review process.
  • Sign off your commits. Use git commit -s and open a pull request.
  • Security issues go private. Report them by email, not in a public issue.

Run it on your own box.

The quickstart above takes you from a fresh Linux machine to your first sandbox. If you would rather not run hardware, we can run it for you.

On your box$sudo omnictl install --single-node --loop-size 50GIn your code$npm i @omnirun/sdk