Dock vs Modal Sandboxes
Modal Sandboxes are built for scale and speed across many short sessions. Dock is built for machines that stay, with people able to step in.
Side by side
Modal Sandboxes in its own words: “Isolated environments for RL rollouts, coding agents, and untrusted code at massive scale.”
| Capability | Dock | Modal Sandboxes |
|---|---|---|
| Isolation | Firecracker microVMs on KVM bare metal (Standard, Premium); gVisor containers for the Nano tier. | gVisor by default; a VM runtime with its own kernel is available. |
| Persistence | Archive snapshots the filesystem; resume keeps the same dock identity. Stopped docks incur no compute charge. | Sessions default to 5 minutes and can run up to 24 hours; continue from snapshots after that. |
| Snapshots and forks | Branch any snapshot into independent, writable docks with recorded lineage. | Filesystem and directory snapshots with default expiry; memory snapshots in alpha. |
| Docker inside | Root, systemd, and Docker inside every dock. | With the VM runtime, by running dockerd yourself. |
| SSH | Native SSH and SCP, plus REST, TypeScript and Python SDKs, and the dock CLI. | No built-in SSH; run your own sshd behind a TCP tunnel. |
| Desktop | Full desktop or browser-only sessions with control locking for human takeover. | Not stated. |
| Network egress | Deny by default on every dock; allowed destinations set per Environment, enforced on the host. | Block network, CIDR allowlist, and a beta domain allowlist. |
| Secrets | Vault Gateway: the agent uses an approved credential without the secret entering the guest. | Modal Secrets are injected into the sandbox, plus OIDC identity tokens. |
| Audit | Flight Recorder: runs, prompts, commands, file changes, network decisions, and cost in one timeline. | Lifecycle events and exit codes. |
| Platform | Focused on agent computers. | Part of a wider serverless compute, GPU, and inference platform. |
Where Dock is different
- Long-lived machines
- A dock keeps its identity across archive and resume instead of ending at a session cap.
- SSH, Docker, and desktop included
- No tunnel setup or special runtime needed to get a full working machine.
- Credentials stay outside
- Vault Gateway brokers credential use, where Modal Secrets are readable inside the sandbox.
Where Modal Sandboxes is strong
- Proven scale
- Modal runs very large fleets of sandboxes and is used by well-known engineering teams.
- GPU and inference platform
- Sandboxes sit next to Modal functions, GPUs, and model serving.
Choose Dock if
each agent needs a persistent workstation it and a person can return to, with guardrails on by default.
Choose Modal Sandboxes if
you run very high volumes of short, disposable sandboxes such as RL rollouts next to GPU workloads.
Tell us what your agents need to run.
Private beta is open. Describe your workload and we will reply about access.