All of OmniRun, under Apache-2.0.
The server, the in-VM agent, the gateway, the CLI and the SDKs are the same code we run in the managed service. Install it on one Linux box, read every line, and change what you need.
Every part you need to run sandboxes.
The managed service runs this same sandbox stack, operated by us on hosts in Finland. Nothing you need to run OmniRun yourself sits behind a paid tier.
| Component | What it does |
|---|---|
| Sandbox server | The REST API, sandbox lifecycle manager, Firecracker driver, LVM thin-provisioned disks and per-VM network namespaces. |
| In-VM agent | The static binary inside every sandbox: commands, streaming, PTY, files, interpreter contexts and desktop control. |
| Accounts and access | Magic-link sign-in, TOTP, API tokens, admin keys and per-user sandbox ownership. A single node starts with the admin key only; sign-in is switched on in the node config (auth_mode = "hybrid" and a Resend key). |
| Quotas and usage events | Per-user limits and metered usage you can feed into your own billing, with the gateway. Pricing is configuration; metering-only by default. |
| Previews, vault and audit log | Preview URLs for sandbox ports, a hash-chained audit log and a credential vault. Previews and the durable audit log run on the node but are off on a fresh install: previews need a wildcard domain (preview_domain), the audit log needs audit_log_path. The vault comes with the gateway. |
| Multi-node gateway (beta) | Node registry, routing and reconciliation for running more than one box. |
| Egress filter | omni-sniproxy, the opt-in per-domain egress filter for HTTPS traffic. |
| omnictl | The install, doctor and operations CLI for the box you run OmniRun on. |
| Templates | Dockerfiles and build scripts for the Python, Node and agent templates. |
| SDKs and integrations | The TypeScript SDK, the Python SDK (public at launch), the CLI, LangChain and LlamaIndex tools, and examples. |
What stays private: a14a's own deployment configuration, node inventory and runbooks; integrations built for specific a14a clients; the billing setup of the managed service; this website and the managed dashboard.
One box, one command.
The single-node installer sets up LVM thin storage, the network bridge, the OmniRun service and the default template snapshot.
The single-node install is admin-API-key only, with preview URLs, magic-link sign-in and the durable audit log switched off. The node runs all three once configured: auth_mode = "hybrid" with a Resend key for sign-in, preview_domain (and optionally a preview TLS cert) for previews, and audit_log_path for the hash-chained audit log. Per-user quotas, usage metering, the credential vault and more than one node come with the gateway, which you set up on top of the node.
| CPU | x86_64 with hardware virtualisation |
|---|---|
| Kernel | Linux with KVM (/dev/kvm present): bare metal, or a VM with nested virtualisation |
| Memory and disk | At least 8 GB RAM and 30 GB free disk. The installer refuses to run below that. |
| Storage | A sparse loop file (--loop-size) or an empty block device (--disk) for the LVM thin pool |
| Distro | Ubuntu 24.04 is tested. Others get a warning and may need packages installed by hand. |
| Access | Root, for networking and storage setup |
Same API. Different operator.
Start on one and move to the other without rewriting code. Only the base URL and token change.
Side by side
Where it runs, who operates it, and what is included.
| Self-hosted | Managed OmniRun | |
|---|---|---|
| Code | The same Apache-2.0 release | The same Apache-2.0 release |
| Where it runs | Your hardware, your region, your network | EU infrastructure operated by a14a |
| Who operates it | You: upgrades, kernels, templates, backups | a14a: upgrades, monitoring and incident response |
| Accounts, tokens, quotas | Included; sign-in is switched on in config, per-user quotas need the gateway | Included |
| Templates | Build your own from the template scripts | Prebuilt Python, Node and agent templates |
| Egress allowlists | Opt-in SNI proxy, HTTPS only | Opt-in SNI proxy, HTTPS only |
| Support | GitHub issues and discussions | Direct line to the team that builds it |
| Cost | Your hardware | Agreed per client or team |
What ships now, and what is next.
OmniRun is an ephemeral sandbox today. The next release makes sandboxes persistent and forkable. The comparison page shows where that leaves us against the rest of the field.
MicroVM sandboxes
A Firecracker VM per sandbox, snapshot restore, copy-on-write disks, commands, code and files.
Single-node install
One-command install on a single x86_64 Linux host with KVM. Python and Node templates built in CI.
Sign-in, previews and audit log
Magic-link sign-in, preview URLs and the hash-chained audit log run on the node, switched on in config. Per-user quotas and metering come with the gateway.
Network controls
Internet on or off for base templates, and HTTPS hostname allowlists through the opt-in SNI proxy.
Signed releases
Release binaries with checksums and an SBOM.
Hibernate
Pause a sandbox to disk, and sandboxes that survive a restart.
Fork and snapshots
Fork a running sandbox, and user snapshots that start new sandboxes.
Template builds and metrics
A template build API (Dockerfile to template), and Prometheus and OpenTelemetry metrics.
Driven by what people run
Per-sandbox CPU, memory and disk sizing, secrets that never enter the VM, SSH and IDE access, and persistent volumes.
Apache-2.0, with a DCO.
Everything public is licensed under Apache-2.0, the same license as Firecracker. You can embed OmniRun in your own product, modify it and run it commercially, and you get the patent grant. Contributions use a Developer Certificate of Origin instead of a CLA, so you keep the copyright to your work.
- Pick an issue. Look for good first issue, or open one to discuss a bigger change first.
- Read the guide. CONTRIBUTING.md covers the build, the tests and the review process.
- Sign off your commits. Use git commit -s and open a pull request.
- Security issues go private. Report them by email, not in a public issue.
Run it on your own box.
The quickstart above takes you from a fresh Linux machine to your first sandbox. If you would rather not run hardware, we can run it for you.