paperclip/packages/plugins/sandbox-providers/cloudflare/bridge-template
Nicky Leach d6e235cbcf
perf(sandbox-providers): drop nvm sourcing from exec wrappers (#10443)
## Thinking Path

> - Paperclip keeps agent work on a controlled execution plane.
> - Sandbox exec wrappers run on the hot path for agent commands.
> - The current change removes the explicit `nvm.sh` load step from
those wrappers.
> - The sandbox image already restores PATH through profile startup.
> - This pull request keeps profile sourcing where the wrapper still
needs it and drops only the `nvm.sh` load step.
> - The result is a smaller command path with the same node and agent
CLI resolution.

## Linked Issues or Issue Description

No public GitHub issue exists for this change.

Problem:
The sandbox exec wrappers spent extra time sourcing `nvm.sh` before each
command.
The sandbox image already restores PATH in
`/etc/profile.d/00-restore-env.sh`, so that explicit `nvm.sh` work was
redundant.

Proposed solution:
Remove the `nvm.sh` source step from all six wrappers.
Keep the profile sourcing that the provider still needs for PATH setup.

Alternatives considered:
Keep the existing shell setup and accept the launch cost.
That keeps the current behavior, but it leaves the hot path slower than
needed.

Roadmap alignment:
This change keeps the sandbox command path small and predictable.
It does not change the adapter contract or the node resolution rules.

## What Changed

- Removed `nvm.sh` sourcing from all six sandbox exec wrappers.
- Kept profile sourcing where the provider still needs it for PATH
setup.
- Switched Modal to a non-login shell because the script now sources
profiles itself.
- Updated wrapper tests to assert that built commands do not source
`nvm.sh`.

## Verification

- Local TypeScript typecheck passed in each changed package.
- Focused provider tests passed for Daytona, E2B, Modal, exe-dev,
Cloudflare bridge, and adapter-utils.
- One Daytona test failure is pre-existing and unrelated to this change.

## Risks

- This change alters shell startup for sandbox exec paths.
- A provider that depends on implicit shell setup may need a follow-up.
- The current tests cover command shape, but they do not cover every
runtime shell path.

## Model Used

OpenAI Codex, GPT-5, tool use.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used with version and capability
details
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal or instance-local Paperclip issues
or links
- [x] My branch name describes the change and contains no internal
Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-07-29 12:40:16 -07:00
..
src perf(sandbox-providers): drop nvm sourcing from exec wrappers (#10443) 2026-07-29 12:40:16 -07:00
Dockerfile Add Cloudflare sandbox provider plugin (#5687) 2026-05-11 07:33:13 -07:00
README.md Add Cloudflare sandbox provider plugin (#5687) 2026-05-11 07:33:13 -07:00
package.json refactor(deps-dev): bump vitest from 3.2.4 to 4.1.8 (#7581) 2026-06-05 21:11:32 -07:00
tsconfig.json Add Cloudflare sandbox provider plugin (#5687) 2026-05-11 07:33:13 -07:00
vitest.config.ts Add Cloudflare sandbox provider plugin (#5687) 2026-05-11 07:33:13 -07:00
wrangler.jsonc Harden Cloudflare sandbox execution (#5967) 2026-05-13 22:00:10 -07:00

README.md

Cloudflare Sandbox Bridge Template

This Worker is the operator-facing bridge used by @paperclipai/plugin-cloudflare-sandbox.

It exposes a small authenticated JSON API under /api/paperclip-sandbox/v1 and translates Paperclip lease and command requests into Cloudflare Sandbox SDK calls.

What it does

  • health and probe
  • acquire, resume, release, and destroy leases
  • execute commands in a sandbox session
  • clean up timed-out sessions so Paperclip does not inherit wedged background processes

Prerequisites

  1. Cloudflare account with Sandbox / Containers access
  2. wrangler configured for that account
  3. Docker running locally for wrangler deploy
  4. A bridge auth token set as a Worker secret:
npx wrangler secret put BRIDGE_AUTH_TOKEN

Local development

cd bridge-template
pnpm install --ignore-workspace --no-lockfile
pnpm test
pnpm typecheck
pnpm dev

Deploy

pnpm deploy

After deploy, configure Paperclip with:

  • bridgeBaseUrl: your Worker URL
  • bridgeAuthToken: the same bearer token value stored in BRIDGE_AUTH_TOKEN

Notes

  • reuseLease: true should only be used together with keepAlive: true
  • .workers.dev is fine for bridge HTTP traffic, but preview/wildcard host flows are intentionally out of scope here
  • keep the Docker image aligned with the installed @cloudflare/sandbox version