Skip to main content
Query resource usage for a running sandbox: CPU, memory, and more. Get a single point-in-time snapshot, or open a streaming subscription that delivers updates at a fixed interval. While a sandbox is paused, the runtime skips host page-residency scans and reports memory_host_resident_bytes as unavailable (null, None, or nil, depending on the SDK). Host residency can change even when guest execution is stopped, so the runtime does not reuse the previous value. Other metrics continue to be sampled; residency sampling returns on the next sample after resume. OCI sandboxes also expose optional upper filesystem fields for capacity dashboards. Guest-visible upper_used_bytes and upper_free_bytes are available when the protected bundled-kernel reporter is fresh. Host-observed upper_host_allocated_bytes is available when microsandbox can inspect the writable upper image from the host. SDKs surface those as nullable fields (Option, null, None, or nil) because custom kernels and non-OCI roots may not provide them.
Need continuous shipping to Grafana, Datadog, Prometheus, or any other OTel-compatible backend? See msb-metrics, a sidecar binary that reads the same data and ships it over OTLP.

Point-in-time

Streaming

Subscribe to metric updates at a regular interval. Each update arrives as a separate event.

Fleet-wide metrics

Get the latest metrics for every running sandbox at once. Useful for dashboards or capacity planning.
Fleet snapshots only include sandboxes whose runtime process is actually alive. A runtime that crashed without cleanup used to keep reporting its last sample as if the sandbox were running; readers now detect the dead owner and retire the entry on first read.

Metrics reports (Rust)

The Rust SDK additionally exposes reports: metrics joined with catalog context for presentation. A report resolves the CPU and memory allocations from the sandbox’s active config, so live resizes are reflected. It also carries a state field: Running, Stalled (runtime alive but no sample within three sampling intervals), or Exited (the preserved terminal sample of a stopped sandbox). This is what msb metrics renders.
Rust
Metrics reports are currently available only in the Rust SDK.

Reference

For exact per-sandbox metrics APIs, see TypeScript, Rust, Python, or Go. For local reports and fleet snapshots, see msb metrics.

Upgrading with running sandboxes

Upgraded SDK readers search both the registry derived from the normalized home and the legacy registry derived from its original spelling. Existing runtimes keep writing to their current registry and do not need restarting; each newly started run writes only to the normalized-home registry. All metrics APIs validate matches against the catalog and process identity and merge results without duplicate runs. This uses in-memory reader state only: there is no database migration, sidecar, config rewrite, or change to registry cleanup. Keep the original home spelling available when upgrading. Discovering a legacy registry after that spelling is lost is outside this lookup’s scope. Older readers do not automatically gain support for the new registry names.