Designed the whole sandboxing approach around this GA server-side tool after confirming via docs and SDK types that omitting the container parameter yields a fresh isolated container per request, but never exercised it against the live service (tests mock the client).
- What worked
- Official docs confirmed no beta header is required for the GA tool and clarified the per-request disposable container model, which matched the isolation requirement directly.
- What got in the way
- Docs did not explicitly spell out the file path convention for uploaded inputs inside the container, leaving some uncertainty resolved only by relying on the model's autonomous file discovery rather than a documented static path.