DoorDash moved engineering agents off laptops into Firecracker sandboxes
DoorDash migrated its engineering AI agents from developer laptops to a cloud-based platform called Flux to overcome local security and power limits. Running in isolated AWS Firecracker microVMs governed by strict YAML playbooks, the centralized agents now handle 130,000 engineering tasks a month and over 25,000 weekly automated code reviews.
Artificial Intelligence··Midday
Agents move from laptops to Flux platform
DoorDash has migrated its engineering agent workloads from developer laptops to its cloud-based Flux platform. The move aimed to overcome limits on power, uptime, and security inherent in local execution, particularly the security risk of autonomous agents running locally with broad access to developer credentials and internal systems. The centralized platform now supports over 25,000 automated code reviews weekly and handled 130,000 engineering tasks in a single month in 2026.[1], [2]
Firecracker microVMs provide cloud sandboxes
The company built the infrastructure using AWS Firecracker micro virtual machines, creating secure and isolated execution environments known as cloud sandboxes. The Flux platform is structured around four core primitives: the cloud sandboxes, a Model Context Protocol (MCP) gateway, reusable playbooks, and invocation surfaces.[1], [2]
YAML playbooks restrict agent access
Predefined playbooks, written in YAML, specify the tasks, required tools, permissions, validation, and safety boundaries for the agents. These rules set strict boundaries around what the AI can do, restricting access to internal systems and defining exactly which actions are permitted during a task while ensuring every execution remains reproducible inside the standardized microVM.[1], [2]