Developer Platform Developer Platform Developer Platform Trung cấp Intermediate កម្រិតមធ្យម ~8 phút đọc · ~690 từ ~8 min read · ~623 words

Sandbox trên Cloudflare: chạy code không tin cậy an toàn hơn Cloudflare Sandbox: running untrusted code more safely Cloudflare Sandbox៖ រត់ code មិនទុកចិត្តបានយ៉ាងសុវត្ថិភាពជាង

Workers chạy code bạn deploy — tin cậy. Khi user hoặc agent gửi script cần thực thi, bạn cần “hộp cát” tách biệt: Sandbox trên Cloudflare là lớp đó. Workers run code you deploy — trusted. When users or agents send scripts to execute, you need a separate sandbox: Cloudflare Sandbox is that layer. Workers រត់ code ដែលអ្នក deploy — ទុកចិត្តបាន។ នៅពេលអ្នកប្រើ ឬ agent ផ្ញើ script ត្រូវប្រតិបត្តិ អ្នកត្រូវការ sandbox ដាច់ដោយឡែក៖ Cloudflare Sandbox គឺជាស្រទាប់នោះ។

Hình 1: Cloudflare Developer Platform

Ứng dụng fullstack Fullstack applications Fullstack applications

Ví dụ fullstack trên Developer Platform — Workers/Pages, storage và AI services trong một kiến trúc thực tế. A practical example of how these services come together in a real fullstack application architecture. A practical example of how these services come together in a real fullstack application architecture.

Thuật ngữ: Concepts: Concepts: Workers · Pages · D1 · R2 · KV · Durable Objects

Sơ đồ chính thức ↗ Official diagram ↗ Official diagram ↗ · Serverless Serverless Serverless

Workers thường vs code không tin cậy: ranh giới quan trọng Regular Workers vs untrusted code: an important boundary Regular Workers vs untrusted code: an important boundary

Cloudflare Workers chạy JavaScript/Wasm do bạn viết và deploy — bạn tin code đó. Mô hình isolate của Workers mạnh cho request/response ngắn, nhưng khi sản phẩm cho phép user chạy Python snippet, agent tự sinh shell command, hoặc “code interpreter” trong chat AI, bạn đang thực thi input không tin cậy. Cloudflare Workers run JavaScript/Wasm you write and deploy — you trust that code. The Workers isolate model is strong for short request/response work, but when your product lets users run Python snippets, agents generate shell commands, or a chat AI includes a “code interpreter,” you are executing untrusted input. Cloudflare Workers run JavaScript/Wasm you write and deploy — you trust that code. The Workers isolate model is strong for short request/response work, but when your product lets users run Python snippets, agents generate shell commands, or a chat AI includes a “code interpreter,” you are executing untrusted input.

Chạy untrusted code trong cùng context với logic chính rủi ro: đọc secret binding, truy cập network không mong muốn, hoặc treo tài nguyên. Sandbox SDK trên Cloudflare cung cấp môi trường cách ly — container-like trên nền Workers — để chạy script trong “hộp” riêng, giới hạn hơn Worker production của bạn. Running untrusted code in the same context as core logic risks reading secret bindings, unwanted network access, or hanging resources. The Cloudflare Sandbox SDK provides an isolated environment — container-like on the Workers platform — to run scripts in a separate “box,” more constrained than your production Worker. Running untrusted code in the same context as core logic risks reading secret bindings, unwanted network access, or hanging resources. The Cloudflare Sandbox SDK provides an isolated environment — container-like on the Workers platform — to run scripts in a separate “box,” more constrained than your production Worker.

Trên blog.cloudflare.com/tag/sandbox/, Cloudflare mô tả use case agent và developer platform: khi AI agent cần thực thi tool do user hoặc model đề xuất, isolation không phải tùy chọn mà là yêu cầu kiến trúc. Bài này nối Sandbox với Workers intro và Developer Platform trên hub. On blog.cloudflare.com/tag/sandbox/, Cloudflare describes agent and developer platform use cases: when an AI agent must run tools proposed by users or models, isolation is an architecture requirement, not an option. This post connects Sandbox to Workers intro and Developer Platform on the hub. On blog.cloudflare.com/tag/sandbox/, Cloudflare describes agent and developer platform use cases: when an AI agent must run tools proposed by users or models, isolation is an architecture requirement, not an option. This post connects Sandbox to Workers intro and Developer Platform on the hub.

Hình 1: Cloudflare Developer Platform

Ứng dụng fullstack Fullstack applications Fullstack applications

Ví dụ fullstack trên Developer Platform — Workers/Pages, storage và AI services trong một kiến trúc thực tế. A practical example of how these services come together in a real fullstack application architecture. A practical example of how these services come together in a real fullstack application architecture.

Thuật ngữ: Concepts: Concepts: Workers · Pages · D1 · R2 · KV · Durable Objects

Sơ đồ chính thức ↗ Official diagram ↗ Official diagram ↗ · Serverless Serverless Serverless

Khi nào nên dùng Sandbox — và khi nào Workers đủ When to use Sandbox — and when Workers alone is enough When to use Sandbox — and when Workers alone is enough

Dùng Workers thường khi: API của bạn, redirect, auth check, ghép header, gọi D1/R2, inference Workers AI với prompt bạn kiểm soát. Dùng Sandbox khi: user upload code để chạy; agent loop “generate → execute → observe”; tutorial platform “chạy thử JavaScript/Python”; CI preview chạy script build trong môi trường tách. Use regular Workers when: your API, redirects, auth checks, header injection, D1/R2 calls, Workers AI inference with prompts you control. Use Sandbox when: users upload code to run; agent loops “generate → execute → observe”; tutorial platforms “try JavaScript/Python”; CI previews running build scripts in isolation. Use regular Workers when: your API, redirects, auth checks, header injection, D1/R2 calls, Workers AI inference with prompts you control. Use Sandbox when: users upload code to run; agent loops “generate → execute → observe”; tutorial platforms “try JavaScript/Python”; CI previews running build scripts in isolation.

Sandbox không thay thế Containers cho workload dài hàng giờ hoặc desktop GUI — nó nhắm tác vụ thực thi script có giới hạn thời gian và tài nguyên, gắn với workflow agent hoặc dev tool. Hiểu ranh giới giúp chọn đúng sản phẩm: Workers, Sandbox, Containers — mỗi cái một bài toán. Sandbox does not replace Containers for multi-hour jobs or desktop GUIs — it targets time- and resource-bounded script execution tied to agent or dev-tool workflows. Knowing the boundary helps pick the right product: Workers, Sandbox, Containers — each solves a different problem. Sandbox does not replace Containers for multi-hour jobs or desktop GUIs — it targets time- and resource-bounded script execution tied to agent or dev-tool workflows. Knowing the boundary helps pick the right product: Workers, Sandbox, Containers — each solves a different problem.

Kết hợp AI Gateway + Workers AI + Sandbox: Gateway kiểm soát chi phí và log LLM; Workers AI suy luận; Sandbox chạy tool code agent sinh ra — stack phổ biến cho agent platform trung cấp. Combine AI Gateway + Workers AI + Sandbox: Gateway controls LLM cost and logs; Workers AI infers; Sandbox runs tool code the agent generates — a common stack for intermediate agent platforms. Combine AI Gateway + Workers AI + Sandbox: Gateway controls LLM cost and logs; Workers AI infers; Sandbox runs tool code the agent generates — a common stack for intermediate agent platforms.

Thiết kế an toàn cơ bản cho Sandbox workload Basic safe design for Sandbox workloads Basic safe design for Sandbox workloads

Một: không đưa production secret vào Sandbox instance — dùng token scoped ngắn hạn nếu script cần gọi API ngoài. Hai: timeout cứng và giới hạn CPU/memory — script treo không kéo sập Worker chính. Ba: log output sandbox riêng, không trộn với log user session. Bốn: validate input trước khi exec — Sandbox không thay validation. One: do not put production secrets in the Sandbox instance — use short-lived scoped tokens if scripts need external APIs. Two: hard timeouts and CPU/memory caps — a hung script should not take down the main Worker. Three: log sandbox output separately from user session logs. Four: validate input before exec — Sandbox does not replace validation. One: do not put production secrets in the Sandbox instance — use short-lived scoped tokens if scripts need external APIs. Two: hard timeouts and CPU/memory caps — a hung script should not take down the main Worker. Three: log sandbox output separately from user session logs. Four: validate input before exec — Sandbox does not replace validation.

Năm: rate limit endpoint kích hoạt sandbox — abuse “free code runner” rất phổ biến. Sáu: network policy: chỉ allowlist domain cần thiết. Docs Sandbox trên developers.cloudflare.com/sandbox/ chi tiết API — hub có trang sản phẩm Sandbox trong Cloudflare 101. Five: rate limit the endpoint that triggers sandbox — abuse of “free code runners” is common. Six: network policy: allowlist only required domains. Sandbox docs at developers.cloudflare.com/sandbox/ detail the API — the hub lists Sandbox in Cloudflare 101. Five: rate limit the endpoint that triggers sandbox — abuse of “free code runners” is common. Six: network policy: allowlist only required domains. Sandbox docs at developers.cloudflare.com/sandbox/ detail the API — the hub lists Sandbox in Cloudflare 101.

Sơ đồ fullstack-application trên reference architecture gắn Workers, Pages, D1, R2 — Sandbox thường ngồi trong lớp compute khi app fullstack có tính năng “chạy code”. The fullstack-application reference diagram ties Workers, Pages, D1, R2 — Sandbox usually sits in the compute layer when a fullstack app has a “run code” feature. The fullstack-application reference diagram ties Workers, Pages, D1, R2 — Sandbox usually sits in the compute layer when a fullstack app has a “run code” feature.

Lộ trình học: từ Worker đến Sandbox Learning path: from Worker to Sandbox Learning path: from Worker to Sandbox

Bước 1: deploy Worker hello và một API đơn giản (hub: Workers intro). Bước 2: thêm Workers AI hoặc agent đơn giản. Bước 3: khi agent cần “run tool”, đọc Sandbox docs và thử SDK với script an toàn (ví dụ tính toán số, không network). Bước 4: thêm rate limit, observability, và AI Gateway nếu agent gọi LLM. Step 1: deploy a hello Worker and simple API (hub: Workers intro). Step 2: add Workers AI or a simple agent. Step 3: when the agent needs to “run tools,” read Sandbox docs and try the SDK with safe scripts (e.g. math, no network). Step 4: add rate limits, observability, and AI Gateway if the agent calls LLMs. Step 1: deploy a hello Worker and simple API (hub: Workers intro). Step 2: add Workers AI or a simple agent. Step 3: when the agent needs to “run tools,” read Sandbox docs and try the SDK with safe scripts (e.g. math, no network). Step 4: add rate limits, observability, and AI Gateway if the agent calls LLMs.

Đọc blog.cloudflare.com/tag/developer-platform/ cho câu chuyện sản phẩm; lộ trình Developer Platform trên hub giữ thứ tự học ổn định. Sandbox là chủ đề trung cấp — đừng nhảy vào trước khi hiểu Workers và binding cơ bản. Read blog.cloudflare.com/tag/developer-platform/ for product stories; the Developer Platform track on the hub keeps learning order stable. Sandbox is intermediate — do not jump in before understanding Workers and basic bindings. Read blog.cloudflare.com/tag/developer-platform/ for product stories; the Developer Platform track on the hub keeps learning order stable. Sandbox is intermediate — do not jump in before understanding Workers and basic bindings.

Hình minh họa Cloudflare Cloudflare visuals Cloudflare visuals

Sơ đồ Reference Architecture chính thức và (khi có) ảnh Dashboard — giúp đối chiếu khi học. Official Reference Architecture diagrams and (when available) Dashboard screenshots — useful while you learn. Official Reference Architecture diagrams and (when available) Dashboard screenshots — useful while you learn.

Hình 1: Workers for Platforms: Main Flow

Nền tảng lập trình được (programmable platforms) Programmable Platforms Programmable Platforms

Workers for Platforms cung cấp hạ tầng an toàn, mở rộng, chi phí hợp lý cho nền tảng lập trình được, phủ toàn cầu. Workers for Platforms provide secure, scalable, cost-effective infrastructure for programmable platforms with global reach. Workers for Platforms provide secure, scalable, cost-effective infrastructure for programmable platforms with global reach.

Sơ đồ chính thức ↗ Official diagram ↗ Official diagram ↗ · Serverless Serverless Serverless

Câu hỏi thường gặp Frequently asked questions Frequently asked questions

Sandbox có thay Workers không? Does Sandbox replace Workers? Does Sandbox replace Workers?

Không. Workers là nền compute chính; Sandbox là môi trường cách ly cho code không tin cậy. App thường dùng Worker làm orchestrator gọi Sandbox. No. Workers are the main compute base; Sandbox is an isolated environment for untrusted code. Apps usually use a Worker as orchestrator calling Sandbox. No. Workers are the main compute base; Sandbox is an isolated environment for untrusted code. Apps usually use a Worker as orchestrator calling Sandbox.

Sandbox có liên quan Containers không? Is Sandbox related to Containers? Is Sandbox related to Containers?

Cùng họ “cách ly mạnh hơn isolate Worker”, nhưng Sandbox nhắm script ngắn cho agent/dev tool; Containers nhắm image và runtime dài hơn. Chọn theo workload. Both are “stronger isolation than a Worker isolate,” but Sandbox targets short scripts for agents/dev tools; Containers target images and longer runtimes. Choose by workload. Both are “stronger isolation than a Worker isolate,” but Sandbox targets short scripts for agents/dev tools; Containers target images and longer runtimes. Choose by workload.

Agent AI có bắt buộc Sandbox không? Is Sandbox mandatory for AI agents? Is Sandbox mandatory for AI agents?

Không bắt buộc cho mọi agent — agent chỉ đọc LLM không cần exec code. Khi agent thực thi tool/code do user/model sinh ra, isolation (Sandbox hoặc tương đương) nên là mặc định. Not mandatory for every agent — read-only LLM agents need no code exec. When agents run tools/code from users/models, isolation (Sandbox or equivalent) should be the default. Not mandatory for every agent — read-only LLM agents need no code exec. When agents run tools/code from users/models, isolation (Sandbox or equivalent) should be the default.

Học tiếp trên hub (on-page backlinks) Keep learning on this hub (on-page links) Keep learning on this hub (on-page links)

Nguồn tham khảo (blog.cloudflare.com) Sources (blog.cloudflare.com) Sources (blog.cloudflare.com)

Nội dung được viết lại để dễ hiểu hơn; luôn đọc bài gốc trên blog.cloudflare.com và docs chính thức khi cần chi tiết kỹ thuật hoặc cập nhật mới nhất. Content is rewritten for clarity; always read the original posts on blog.cloudflare.com and official docs for technical detail or the latest updates. Content is rewritten for clarity; always read the original posts on blog.cloudflare.com and official docs for technical detail or the latest updates.

What are Cloudflare Workers? Serverless at the edge, explained simply
Workers Workers Workers Cơ bản Entry កម្រិតចាប់ផ្តើម ~7 phút ~7 min ~7 នាទី

Cloudflare Workers là gì? Serverless ở “mép mạng” giải thích đơn giản What are Cloudflare Workers? Serverless at the edge, explained simply What are Cloudflare Workers? Serverless at the edge, explained simply

Workers giống thuê “người trực” ngay gần khách hàng: nhận request, xử lý nhanh, trả kết quả — bạn không phải tự mua và bảo trì cả tòa nhà server. Workers are like stationing helpers near customers: take a request, handle it quickly, return a result — without buying and maintaining a whole server building. Workers are like stationing helpers near customers: take a request, handle it quickly, return a result — without buying and maintaining a whole server building.

Đọc bài → Read post → អានអត្ថបទ →

Cloudflare Developer Platform: build global apps without managing servers yourself
Developer Platform Developer Platform Developer Platform Trung cấp Intermediate កម្រិតមធ្យម ~9 phút ~9 min ~9 នាទី

Cloudflare Developer Platform: xây ứng dụng toàn cầu mà không tự quản lý server Cloudflare Developer Platform: build global apps without managing servers yourself Cloudflare Developer Platform: build global apps without managing servers yourself

Developer Platform giống bộ lego edge: compute (Workers), hộp đựng (R2/KV/D1), AI, và lớp bảo vệ — lắp theo use case thay vì mua cả trung tâm dữ liệu. The Developer Platform is like an edge Lego set: compute (Workers), storage boxes (R2/KV/D1), AI, and protection layers — assemble by use case instead of buying a whole data center. The Developer Platform is like an edge Lego set: compute (Workers), storage boxes (R2/KV/D1), AI, and protection layers — assemble by use case instead of buying a whole data center.

Đọc bài → Read post → អានអត្ថបទ →

Controlling LLM cost with AI Gateway (practical for small teams)
AI AI AI Trung cấp Intermediate កម្រិតមធ្យម ~8 phút ~8 min ~8 នាទី

Kiểm soát chi phí LLM với AI Gateway (thực tế cho team nhỏ) Controlling LLM cost with AI Gateway (practical for small teams) Controlling LLM cost with AI Gateway (practical for small teams)

Chi phí LLM không “bùng” vì một đêm — nó tích lũy từ mỗi request không được đếm. AI Gateway giúp bạn nhìn token, giới hạn và cắt sớm trước khi hóa đơn gây choáng. LLM bills rarely explode overnight — they accumulate from every uncounted request. AI Gateway helps you see tokens, set limits, and cut early before the invoice stuns you. LLM bills rarely explode overnight — they accumulate from every uncounted request. AI Gateway helps you see tokens, set limits, and cut early before the invoice stuns you.

Đọc bài → Read post → អានអត្ថបទ →

Xem tất cả bài blog Browse all blog posts Browse all blog posts

Chuỗi bài AI · Security · CDN · Workers · Developer Platform — viết lại cho người mới và trung cấp. AI · Security · CDN · Workers · Developer Platform — rewritten for entry and intermediate learners. AI · Security · CDN · Workers · Developer Platform — rewritten for entry and intermediate learners.