Skip to main content

Follow one ownership sequence

  1. Enter AsyncComputerSandbox.create() once.
  2. Wait for desktop readiness.
  3. Call owner.session_handle() once.
  4. Send the handle to one deployed Function.
  5. Enter handle.borrow_async() once inside that Function.
  6. Run the complete model trajectory.
  7. Release the lease.
  8. Let the owner terminate the desktop.
The handle carries versioned routing identity. Borrow entry resolves fresh access and verifies the live target.

Require verifiable placement

Set the same supported selector on the owner configuration and Function decorator. Pass that selector to borrow_async(function_region=...). Public narrow selectors such as us-west can resolve to provider-native values such as us-west-2, us-west1, or westus3. A granted granular selector such as us-west-2 must match the observed runtime region exactly. Missing, broad, mismatched, malformed, or unverifiable placement fails before mutation. Broad selectors such as us and eu are invalid for handoff. The caller must establish the placed Function topology explicitly.

Keep one borrow

The borrow reuses one lease, pooled HTTP client, and attested authentication state. Requests still cross authenticated Modal ingress.

Handle cancellation and result loss

Keep the owner open until a remote or spawned Function call reaches a terminal outcome. Function cancellation leaves the desktop and earlier input intact for explicit recovery. When mutation completed but its result was lost, use the explicit observation and receipt recovery interfaces. Never repeat the action automatically. Native async provisioning keeps cleanup cancellation-safe. Cold allocation and desktop startup retain their normal Modal timing.