13 chapters · 55 min
Skills
Chapter 7 of 13
Use when porting a Cloudflare Sandbox app from stable @cloudflare/sandbox to @cloudflare/sandbox@next (Sandbox SDK 1.0 preview), or when the user asks to migrate or upgrade to…
3 minutes · 551 words · 12 sections
@next)Perform the port. Follow the steps in order. Depth lives in docs—fetch the linked page when a step needs detail.
Human guide: Migrate (opens in a new tab) · 1.0 preview (opens in a new tab)
New projects should start on @next (sandbox-next), not this skill. Day-to-day stable work → sandbox-stable. Deprecated-API cleanup without moving to @next → 2026 deprecation guide (opens in a new tab) first if needed.
Existing apps should migrate when you can, so you are ready when 1.0 becomes the stable release. Do not force production cutover without the user agreeing.
Prefer installed @next types and the migrate doc over memory.
Stop after any step that needs a user decision.
@next line.@next control protocols are incompatible both ways; gradual rollout leaves a broken mixed window. In-flight container work can stop.await sandbox.exec(...) means process started, not command finished.timeout / AbortSignal cancel the wait only, not the process.gitCheckout on core, process stdin, string-exec completion helper).| Stable | @next |
|---|---|
SANDBOX_TRANSPORT / transport / setTransport | Remove — RPC only |
await sandbox.exec("cmd") → buffered result | await sandbox.exec(argv) → handle, then output / waits |
execStream / startProcess | Same handle: logs, waitFor*, kill |
| Default / named sessions | Gone — cwd/env per launch, or one shell script |
sandbox.terminal(request) / session terminal | createTerminal + terminal.connect(request) |
xterm sessionId | terminalId |
Interpreter methods on Sandbox | withInterpreter → sandbox.interpreter.* |
gitCheckout | argv git via exec |
| String kill signals | Numeric only |
Files, mounts, backups, ports, tunnels, proxyToSandbox | Mostly unchanged (ignore session/transport bits on stable pages) |
Depth: Migrate (opens in a new tab) · after port, day-to-day → sandbox-next
rg 'SANDBOX_TRANSPORT|transport:|setTransport|enableDefaultSession|createSession|getSession|deleteSession|execStream\(|startProcess\(|killProcess\(|sandbox\.terminal\(|sessionId|gitCheckout\(|SandboxTransport|ExecutionSession'Also: string exec(, cd then a later exec, bare createCodeContext / runCode on Sandbox.
--containers-rollout=immediate (live processes/terminals/streams may stop)?-python image variant?npm install @cloudflare/sandbox@nextFROM cloudflare/sandbox:next
# Python: cloudflare/sandbox:next-pythonSame prerelease tag on Worker and image when not on floating next.
Apply replacements from the map. For each area, implement from the doc—not from stable habits:
| Area | Doc |
|---|---|
| Commands / handles / waits | Processes (opens in a new tab) · Processes API (opens in a new tab) |
cwd / env / secrets | Environment (opens in a new tab) · Outbound traffic (opens in a new tab) |
| Drop sessions | Migrate · |
Commands (shape):
// Before (stable)
const result = await sandbox.exec("npm test");
// After (@next)
const process = await sandbox.exec(["/bin/bash", "-lc", "npm test"]);
const result = await process.output({ encoding: "utf8" });const server = await sandbox.exec(["/bin/bash", "-lc", "npm run dev"], {
cwd: "/workspace/app",
});
await server.waitForPort(3000, { timeout: 60_000 });
await server.kill(); // numeric; default 15Terminals (shape):
const terminal = await sandbox.createTerminal({ command: ["bash"], cwd: "/workspace" });
const t = await sandbox.getTerminal(terminal.id);
if (!t) return new Response("terminal gone", { status: 410 });
return t.connect(request, { cursor, cols, rows });Interpreter (shape):
import { Sandbox as BaseSandbox } from "@cloudflare/sandbox";
import { withInterpreter } from "@cloudflare/sandbox/interpreter";
export class Sandbox extends BaseSandbox<Env> {
interpreter = withInterpreter(this);
}Git (shape):
const clone = await sandbox.exec(
["git", "clone", "--depth", "1", "--", repoUrl, "/workspace/repo"],
{ cwd: "/workspace" },
);
const result = await clone.output({ encoding: "utf8" });Delete transport settings entirely. Remove session APIs. Isolate users with separate sandbox IDs.
Staging/branch first. Production is one deploy of matching Worker + image:
npx wrangler deploy --containers-rollout=immediateLeave rollout_active_grace_period at default 0 (or set 0 if raised). After cutover, pre-deploy process/terminal IDs are invalid. Details: Migrate (opens in a new tab) · Container rollouts (opens in a new tab)
@next line@nextexec + output({ encoding: "utf8" })--containers-rollout=immediateThen day-to-day work uses sandbox-next.
@next Worker with stable image (or reverse)await exec as command completioncd / exports persist across exec callsgitCheckout, process stdin, or undocumented APIssetEnvVars / launch envInstall this repository
npx skills add cloudflare/skills/plugin marketplace add cloudflare/skillsSkills install per repository, not per chapter — the CLI has no documented per-skill form, so we do not print one.
Use when porting a Cloudflare Sandbox app from stable @cloudflare/sandbox to @cloudflare/sandbox@next (Sandbox SDK 1.0 preview), or when the user asks to migrate or upgrade to Sandbox 1.0 / @next. Not for day-to-day stable work (sandbox-stable) or new @next apps (sandbox-next).
The verbatim description from this skill’s front matter — the string an agent matches on to decide whether to load it.
main, last pushed 7 August 2026.SKILL.md, not by matching a directory convention. One layout observed: skills/*/SKILL.md.h1 and no skipped levels:.claude-plugin/marketplace.json by Cloudflare, declaring 1 plugin. It is read for editorial metadata only — never as the skill index, which is always the repository tree./cloudflare/skills.md, and each chapter at its own URL.| Terminals | Terminals (opens in a new tab) |
| Interpreter | Interpreter (opens in a new tab) |
| Errors | Errors (opens in a new tab) |
| Durable job across requests | Process execution — lifetime / durability (opens in a new tab) |
.md