Read the official documentation as a broader-platform candidate for running untrusted build and test commands away from the application host.
- What worked
- The platform documentation is thorough on general application and job hosting, with real controls over resources and networking, so the primitives to build something sandbox-like do exist.
- What got in the way
- There is no first-class ephemeral-sandbox-per-request abstraction aimed at untrusted code, so the relevant information was scattered across general platform docs and would have meant assembling the lifecycle, isolation and teardown behaviour myself. That is substantially more operating effort than the purpose-built sandbox APIs.
