Code Executor Configuration
The Code Executor runs Python code in isolated Kubernetes sandbox pods with enforced resource limits and security policies. Every execution request is dispatched to a sandbox pod, keeping user-supplied code isolated from the CodeMie API.
There are two sandbox modes selected with CODE_EXECUTOR_SANDBOX_MODE:
- jobs (
sandbox-jobs, default and recommended) - shared (
sandbox-shared, deprecated and not recommended for production).
Sandbox Modes
- sandbox-jobs (default)
- sandbox-shared
Each execution is submitted as a Kubernetes Job. A fresh pod runs the user code and is torn down afterwards.
CodeMie API discovers and reuses long-lived pods from a pool, or creates a new one on demand up to CODE_EXECUTOR_MAX_POD_POOL_SIZE. The same pod can be reused across many executions.
sandbox-shared is no longer supported and not recommended to use in production environments. Switch to sandbox-jobs.
extraEnv:
- name: CODE_EXECUTOR_SANDBOX_MODE
value: "sandbox-shared"
Enabling the Code Executor
The Code Executor is disabled by default. To make it available, set CODE_EXECUTOR_ENABLED=true in the CodeMie API environment:
extraEnv:
- name: CODE_EXECUTOR_ENABLED
value: "true"
While disabled, the tool is neither listed in the tools catalog nor executed at runtime.
Setting the Executor Image
Set CODE_EXECUTOR_DOCKER_IMAGE to the image matching your CodeMie version:
extraEnv:
- name: CODE_EXECUTOR_DOCKER_IMAGE
value: "codemie/codemie-python:<codemie-version>"
RBAC Configuration
Enable RBAC so the CodeMie API service account can manage pods/Jobs in the executor namespace:
features:
tools:
code_executor:
rbac:
enabled: true
Namespace Configuration
Code executor runs in the codemie-code-executor namespace by default, matching the CODE_EXECUTOR_NAMESPACE default. Set namespace.create to true to have the chart manage it:
features:
tools:
code_executor:
namespace:
create: true
To use a different namespace, set the name and CODE_EXECUTOR_NAMESPACE to match:
features:
tools:
code_executor:
namespace:
name: "<namespace>"
extraEnv:
- name: CODE_EXECUTOR_NAMESPACE
value: "<namespace>"
Applying CodeMie API Settings
helm upgrade codemie-api \
oci://europe-west3-docker.pkg.dev/or2-msq-epmd-edp-anthos-t1iylu/helm-charts/codemie \
--version <version> \
-f codemie-api/values-<cloud>.yaml \
--namespace codemie
Environment Variables Reference
For the full list of available environment variables, see API Configuration — Code Executor & Python Sandbox.
Legacy Topics
The topics below only apply to niche or deprecated setups. Most deployments can skip this section.
Dedicated Cluster via kubeconfig (will be deprecated)
It is also possible to point Code Executor at a namespace in a different cluster by mounting a kubeconfig secret instead of relying on in-cluster RBAC:
extraVolumeMounts: |
- name: executor-kubeconfig
mountPath: "/secrets/kubeconfig"
subPath: kubeconfig
readOnly: true
extraVolumes: |
- name: executor-kubeconfig
secret:
secretName: codemie-executor-kubeconfig
extraEnv:
- name: CODE_EXECUTOR_NAMESPACE
value: "codemie-code-executor"
- name: CODE_EXECUTOR_KUBECONFIG_PATH
value: "/secrets/kubeconfig"
Pre-warming the Pod Pool (sandbox-shared only)
Pre-warming only applies to the deprecated sandbox-shared mode. sandbox-jobs always creates a fresh Job pod per execution, so there is no pool to pre-warm.
In sandbox-shared mode, CodeMie API creates executor pods on demand by default, and the first execution request waits for a pod to start. To avoid this, deploy the codemie-code-executor chart to keep pods running and ready for discovery, into the same namespace as CODE_EXECUTOR_NAMESPACE:
helm upgrade --install codemie-runtime \
oci://europe-west3-docker.pkg.dev/or2-msq-epmd-edp-anthos-t1iylu/helm-charts/codemie-runtime \
--version <version> \
-f codemie-code-executor/values.yaml \
--namespace <executor-namespace>
To control how many pods are kept ready, set replicaCount in your codemie-code-executor/values.yaml:
replicaCount: 5