ComputerConfig when the SDK creates a Modal Sandbox. Use daemon environment variables only when you launch the daemon directly.
All configuration models reject unknown fields. A misspelled field fails validation.
Build one configuration object
Choose each configuration family
Use configuration model reference for every field and accepted value.
Set lifecycle bounds
runtime.timeout_seconds limits the total Sandbox lifetime. runtime.idle_timeout_seconds is a Modal idle policy.
budgets.max_idle_seconds is different. The daemon enforces it from budget-counted activity.
Warm-pool configurations cannot set runtime.idle_timeout_seconds. They also cannot set an explicit VNC password.
Set ingress and network policy
ComputerConfig.ingress defaults to attested-tunnel. Use connect when network.block_all=True.
network.block_all cannot be combined with a network allowlist. It also requires VNC to be off.
Pin runtime.modal_region only after you measure from the real caller. The requested region is part of the configuration hash.
Configure noVNC explicitly
Use one string value:Understand precedence
Values passed toComputerConfig replace Pydantic defaults. The explicit expose_vnc= argument to create() replaces config.expose_vnc. The explicit image= argument replaces SDK image selection.
A directly launched daemon reads its process environment when settings are created. It does not read a daemon configuration file.
Treat tokens, passwords, startup URLs, daemon URLs, and noVNC URLs as sensitive.
