When to use this profile
Choose a custom image when preparation dominates execution or a task needs software outside the base profiles. Build the toolchain once, keep user data and credentials out of the image, and run a deterministic smoke test before publishing a new version. An OCI build is a way to describe the filesystem; it does not by itself implement a microVM execution service.
Prepare a repeatable environment
- Pin the base image by digest and record package versions.
- Keep the image free of tokens, private datasets, SSH keys and machine-specific configuration.
- Define a smoke test that checks binaries, filesystem permissions and the expected command.
sh /work/smoke-test.shReturn results the agent can use
- An image digest and build manifest.
- The smoke-test result for that exact version.
- A documented input, output and network contract.
Rebuild from a clean environment, compare the recorded inputs, and execute the smoke test without host mounts or production credentials.
Resources and boundaries
Start with 2 vCPU and 4 GB of RAM, then measure peak memory and task duration on a representative fixture. These are workload planning values, not a benchmark or a provisioned configuration. Use the sandbox cost calculator to estimate running time and retained snapshots.
- Custom image support depends on the runtime adapter and image conversion pipeline.
- A large image increases storage and preparation costs; retain only dependencies needed at runtime.
- Rebuild and retest after security updates rather than treating an old snapshot as permanently safe.
Keep model inference separate from this execution profile. A hosted model or gpuOS can decide the next action while the CPU environment runs it. The quickstart describes the account workflow and the proposed runtime contract.