> ## Documentation Index
> Fetch the complete documentation index at: https://docs.springwinter.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# How to Build Data Analysis Agent Sandboxes on AWS

> Design disposable Python and data-analysis agent sandboxes on AWS with scoped datasets, package controls, resource quotas, artifact handling, and reproducibility.

A data analysis agent runs generated Python, installs libraries, reads customer files, and creates charts or reports. The runtime needs strict data scope and predictable resource limits even when the code appears harmless.

*Updated October 9, 2026.*

**Mount or copy only the approved dataset into a fresh sandbox and export only reviewed artifacts.**

## Separate session data

Create a unique prefix or bucket access point for each session. The sandbox role should read only approved inputs and write only to its output prefix. Do not give a shared analytics role broad access to every customer's S3 objects.

Avoid embedding raw datasets in model prompts when the analysis can run locally. Send the model schemas, summaries, or tool results needed for reasoning, then keep bulk processing inside the customer's AWS boundary.

## Build a reproducible runtime

Bake common Python, numerical, plotting, and file-format libraries into a versioned image. Allowing unrestricted `pip install` during every session adds supply-chain risk, latency, and non-reproducible dependencies.

When dynamic packages are necessary, use an allowlisted proxy or internal package repository, pin versions and hashes, and record the resolved environment with the output.

## Bound compute and storage

Set CPU, memory, ephemeral disk, process count, wall time, and output limits. CSV joins, decompression bombs, image rendering, and accidental cartesian products can exhaust resources without malicious intent.

Fargate tasks can request expanded ephemeral storage within supported limits, but temporary disk is not durable. Upload notebooks, scripts, charts, and result files before the task exits.

## Control data exfiltration

Disable public egress by default. If packages or external APIs are required, route through explicit endpoints. Do not let generated code reach metadata, internal databases, unrelated buckets, or arbitrary web hosts.

Inspect artifact types and sizes before making them downloadable. Spreadsheet formulas, HTML reports, serialized Python objects, and archives can carry active or unsafe content.

## Make results reproducible

Store the code, image digest, package lock, input object versions, random seeds, runtime limits, and execution timestamps with the result. A chart without its derivation is difficult to audit.

## Springwinter fit

A Springwinter Worker can run trusted recurring analysis. Multi-tenant code-interpreter sessions should use one disposable task per session. Current Workers are long-lived services, so a controller must launch the actual sandbox through direct ECS, Batch, or another isolated execution system.

## Frequently asked questions

<AccordionGroup>
  <Accordion title="Should an analysis sandbox have internet access?">
    Default to no. Add narrowly controlled egress only for required package registries or APIs. Generated code with open internet can exfiltrate source data through ordinary HTTP requests.
  </Accordion>

  <Accordion title="Can outputs be trusted because the code ran successfully?">
    No. Validate types, size, provenance, and dangerous active content. Successful execution says nothing about analytical correctness or artifact safety.
  </Accordion>

  <Accordion title="What should be saved after the session?">
    Save selected code, environment metadata, input versions, logs, and approved artifacts. Delete the temporary filesystem and session credentials after retention requirements are met.
  </Accordion>
</AccordionGroup>

## Sources and further reading

* [Fargate ephemeral storage](https://docs.aws.amazon.com/AmazonECS/latest/APIReference/API_EphemeralStorage.html)
* [ECS task IAM roles](https://docs.aws.amazon.com/AmazonECS/latest/developerguide/task-iam-roles.html)
* [ECS container security best practices](https://docs.aws.amazon.com/AmazonECS/latest/developerguide/security-tasks-containers.html)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.