A container per agent does not scale to hundreds of millions, then billions, of concurrent agents. That shortfall is why the industry is scrambling for CPU compute, not just GPU compute.
The agent loop is the brain; the sandbox where work actually lands is the hands. Once they are separated, the hands no longer have to be a container — an isolate can hold the pen for most of the job.
“This separates the hands (the sandbox where work is done) from the brain (the agent loop).” Matt Carey & Aron Carroll · The Cloudflare Blog
@cloudflare/computer keeps a single durable workspace and swaps the engine underneath it per operation.
Agents are surprisingly good at picking the right environment for the task, so the cheapest engine that can do the job is the one that runs.
Parsing findings, indexing an OpenAPI schema, diffing observed fields against declared ones, writing the patch.
IsolateJavaScriptBackendLocating the serializer and reading git history — shell ergonomics without booting a machine to get them.
WorkerBackendInstalling dependencies and running the test suite — the one job that genuinely needs a full Linux environment.
ContainerBackend
API Shield flags GET /api/orders/{id} returning undeclared PII — email, phone and a partial card number absent from the OpenAPI schema.
The SecurityTriageAgent works the finding across nine steps and stops at a commit for human review.
Eight of those steps never leave an isolate or a shell. Step 8 is the only one that reaches for a container.
“Our goal with @cloudflare/computer is to provide an agent with a runtime where a container is required for less than 10% of its work.”
The Engine Ledger computes container share as container operations over total operations, every time it is read. Whatever the number says on stage is the number the run actually produced.