Skip to main content

Code Executor Configuration

The Code Executor runs Python code in isolated Kubernetes sandbox pods with enforced resource limits and security policies. Every execution request is dispatched to a sandbox pod, keeping user-supplied code isolated from the CodeMie API.

There are two sandbox modes selected with CODE_EXECUTOR_SANDBOX_MODE:

  • jobs (sandbox-jobs, default and recommended)
  • shared (sandbox-shared, deprecated and not recommended for production).

Sandbox Modes​

Each execution is submitted as a Kubernetes Job. A fresh pod runs the user code and is torn down afterwards.

Enabling the Code Executor​

The Code Executor is disabled by default. To make it available, set CODE_EXECUTOR_ENABLED=true in the CodeMie API environment:

extraEnv:
- name: CODE_EXECUTOR_ENABLED
value: "true"

While disabled, the tool is neither listed in the tools catalog nor executed at runtime.

Setting the Executor Image​

Set CODE_EXECUTOR_DOCKER_IMAGE to the image matching your CodeMie version:

extraEnv:
- name: CODE_EXECUTOR_DOCKER_IMAGE
value: "codemie/codemie-python:<codemie-version>"

RBAC Configuration​

Enable RBAC so the CodeMie API service account can manage pods/Jobs in the executor namespace:

features:
tools:
code_executor:
rbac:
enabled: true

Namespace Configuration​

Code executor runs in the codemie-code-executor namespace by default, matching the CODE_EXECUTOR_NAMESPACE default. Set namespace.create to true to have the chart manage it:

features:
tools:
code_executor:
namespace:
create: true

To use a different namespace, set the name and CODE_EXECUTOR_NAMESPACE to match:

features:
tools:
code_executor:
namespace:
name: "<namespace>"

extraEnv:
- name: CODE_EXECUTOR_NAMESPACE
value: "<namespace>"

Applying CodeMie API Settings​

helm upgrade codemie-api \
oci://europe-west3-docker.pkg.dev/or2-msq-epmd-edp-anthos-t1iylu/helm-charts/codemie \
--version <version> \
-f codemie-api/values-<cloud>.yaml \
--namespace codemie

Environment Variables Reference​

For the full list of available environment variables, see API Configuration — Code Executor & Python Sandbox.

Legacy Topics​

The topics below only apply to niche or deprecated setups. Most deployments can skip this section.

Dedicated Cluster via kubeconfig (will be deprecated)

It is also possible to point Code Executor at a namespace in a different cluster by mounting a kubeconfig secret instead of relying on in-cluster RBAC:

extraVolumeMounts: |
- name: executor-kubeconfig
mountPath: "/secrets/kubeconfig"
subPath: kubeconfig
readOnly: true

extraVolumes: |
- name: executor-kubeconfig
secret:
secretName: codemie-executor-kubeconfig

extraEnv:
- name: CODE_EXECUTOR_NAMESPACE
value: "codemie-code-executor"
- name: CODE_EXECUTOR_KUBECONFIG_PATH
value: "/secrets/kubeconfig"
Pre-warming the Pod Pool (sandbox-shared only)

Pre-warming only applies to the deprecated sandbox-shared mode. sandbox-jobs always creates a fresh Job pod per execution, so there is no pool to pre-warm.

In sandbox-shared mode, CodeMie API creates executor pods on demand by default, and the first execution request waits for a pod to start. To avoid this, deploy the codemie-code-executor chart to keep pods running and ready for discovery, into the same namespace as CODE_EXECUTOR_NAMESPACE:

helm upgrade --install codemie-runtime \
oci://europe-west3-docker.pkg.dev/or2-msq-epmd-edp-anthos-t1iylu/helm-charts/codemie-runtime \
--version <version> \
-f codemie-code-executor/values.yaml \
--namespace <executor-namespace>

To control how many pods are kept ready, set replicaCount in your codemie-code-executor/values.yaml:

replicaCount: 5