feat: add Tenki sandbox provider (#17305)

### Summary

Adds a `tenki` sandbox provider that runs each agent code execution in a
disposable Tenki (https://tenki.cloud) microVM (create → exec → destroy,
no volumes or snapshots).
Registration mirrors PR #15039, configure `api_key` and `project_id` in
Admin > Sandbox Settings.

Both runtimes are covered:
- Python: `agent/sandbox/providers/tenki.py` (structured results +
artifact collection).
- Go: `internal/agent/sandbox/tenki.go`, mirroring the e2b provider and
wired into the provider manager.

`tenki-sandbox` is an optional dependency (it requires `protobuf>=6.31`,
which differs from RAGFlow's pinned gRPC stack), lazily imported with a
clear error when missing; installation is documented in the sandbox
quickstart.

Unit tests cover execution, structured results, artifacts
(symlink/size/extension limits), non-zero exit, timeout, error mapping,
and idempotent destroy.

---------

Co-authored-by: yiming.wang <yiming.wang@luxor.com>
This commit is contained in:
yiming wang
2026-07-28 19:24:39 +08:00
committed by GitHub
parent 73860170ae
commit dcadd8d837
14 changed files with 1636 additions and 7 deletions

View File

@@ -6,6 +6,7 @@ import { useMutation, useQuery, useQueryClient } from '@tanstack/react-query';
import {
LucideChevronDown,
LucideCloud,
LucideCloudLightning,
LucideLink,
LucideLoader2,
LucideMonitor,
@@ -62,6 +63,7 @@ const PROVIDER_ICONS: Record<string, React.ElementType> = {
ssh: LucideTerminal,
aliyun_codeinterpreter: LucideCloud,
e2b: LucideZap,
tenki: LucideCloudLightning,
};
function AdminSandboxSettings() {