Cloudflare Computer: An Agent Runtime Beyond Containers

The most capable AI agents share a simple trait: they get a computer to work with. A filesystem, a shell, tools, the ability to run code. Cloudflare’s answer to that problem now has a name — @cloudflare/computer — an open-source agent runtime that flips the current “one agent, one container” model on its head.

Why containers won’t scale for agents

Six months ago, spinning up a container and running an agent inside it was the norm. Today the industry is moving toward a split: the harness (the brain) runs the agent loop, while sandboxed code execution (the hands) happens in a separate environment. But even that split still assumes each agent gets its own container. Cloudflare’s argument: across all clouds and hyperscalers, there is nowhere near enough compute on earth to give hundreds of millions — then billions — of concurrent agents each their own containerized environment. That, they say, is why the industry is in a panicked scramble for CPU compute, not just GPU.

How Cloudflare Computer works

The package, installed via npm install @cloudflare/computer, centers on a workspace: a virtual filesystem backed by SQLite that can be populated from git repositories, storage buckets, or any files you choose. Every operation on it is gated, audited and observable. Against that filesystem, the runtime can execute work in three backends, all behind the same exec(string, options) interface:

  • Isolate shell — just-bash translates shell code into JavaScript, running in a Dynamic Worker with the filesystem attached via bindings.
  • Isolate JavaScript — ECMAScript modules in a fresh Dynamic Worker.
  • Container — a full Linux environment via Cloudflare Containers, with the filesystem mounted through FUSE and changes synced back.

The agent harness itself lives in a Durable Object — an isolate that hibernates when idle, persists state, and scales horizontally without limit. The container is attached on demand, as a tool call, only when a task needs Linux, npm or native binaries. Agents pick their environment through the exec tool’s backend argument, and Cloudflare reports that frontier models are surprisingly good at choosing the fast, cheap path and falling back to a container only when necessary.

A desk, not a workshop

The mental model: think of the isolate as a desk and the container as a full workshop. Most agent work — file edits, data processing, git operations, documentation — happens at the desk. Heavy lifting — compiling, running native binaries, package management — gets a trip to the workshop. The shared filesystem means nothing is lost in transit; tasks can move between the two seamlessly.

What this signals for the agent economy

This is more than a Cloudflare product release. It is a structural bet on the next phase of agentic computing:

  • The per-agent container is economically dead. If agent counts head toward billions, per-agent containers are physically impossible. The compute primitive that wins will be one that multiplexes cheaply.
  • Runtimes are becoming the battleground. Cloudflare is racing to be the default execution layer for agents, the way it became the default for static sites and serverless functions.
  • CPU is the new bottleneck. The panic over CPU capacity — not just GPUs — is real, and it will reshape how clouds price and provision general compute.

Cloudflare’s stated goal: a container should be needed for less than 10% of an agent’s work. If that holds, the cost curve of running agents collapses — and the constraint shifts from infrastructure to agent quality.

Try it today

Cloudflare Computer is an early preview, explicitly aimed at experimentation and prototyping. Grab it from the workspace repository on GitHub, walk the step-by-step tutorial, and test how well your model of choice routes work between isolates and containers. For a reference point on the local-compute side of the same tradeoff, see our guide to running Qwen3.8-27B on consumer GPUs.

Related News