Read the sandbox docs, security, timeouts, volumes, pricing, launch blog and changelog, and downloaded the published SDK tarball to confirm option names and the command result shape. Excluded because the default image has no documented Node binary (Deno only), the SDK client needs Node 24, and the product was beta on a paid plan.
- What worked
- Firecracker isolation and allowNet-based egress control were stated clearly. The SDK types were well commented once extracted from the tarball.
- What got in the way
- The docs used a memory option name that differed from the SDK typings. The runtime support matrix on the docs page describes the SDK client, not what runs inside the VM, which is easy to misread. The marketing page and the launch blog disagreed on beta vs GA status. The JSR API doc page returned 403 to fetches, so I fell back to the npm tarball.
