Azure Container Apps Express Goes GA With Subsecond Sandboxes
In this article
Microsoft has made Azure Container Apps Express generally available alongside Azure Container Apps Sandboxes, the isolated compute layer on which Express runs, InfoQ reports. Express removes the environment-provisioning step and uses opinionated defaults: developers provide a container image, region and application configuration, while Microsoft provisions compute, ingress and scaling.
Apps use consumption CPU with per-second billing, scale to zero when idle and incur no environment-provisioning fee. Microsoft says Express is available in more than 40 Azure regions, covering almost every public region where Container Apps is offered.
The more consequential component for AI infrastructure teams is the sandbox beneath that simplified deployment model. Microsoft says Express is built entirely on Container Apps Sandboxes, which provision workloads from prewarmed pools for subsecond startup. Each workload runs within what Microsoft describes as a hardware-isolated microVM boundary, and the platform can burst to thousands of concurrent sandboxes.
Sandboxes also support suspension and resumption. Microsoft says the service snapshots full state, including memory and disk, and can restore it in under a second. This is an infrastructure-level improvement rather than a change to model weights, matching a pattern AI Mastery has examined in 2026 AI gains driven by infrastructure rewrites.
The sandbox beneath Express
Developers can use Sandboxes directly, and Microsoft positions them for agent platforms and secure code-execution services. The top-level Azure Resource Manager resource is Microsoft.App/SandboxGroups, a management boundary for sandboxes that share configuration, comparable to a Container Apps environment.
InfoQ cites Reddit commenter MuhBlockchain as saying Sandboxes already underpin Azure services including Foundry Hosted Agents, although Microsoft’s material does not make that claim. Other commenters described using Python sandboxes for a customer-facing agent harness and deploying them through Bicep with scale-to-zero behavior.
Another commenter, brianveldman, distinguished Sandboxes from Container Apps jobs by lifecycle: jobs are intended for run-to-completion and batch tasks, while Sandboxes provide programmable isolated environments with lifecycle control.
InfoQ compares Microsoft’s approach with Google Kubernetes Engine. GKE combines Pod snapshots, which checkpoint CPU and GPU memory through gVisor, with GKE Agent Sandbox for untrusted agent code. Both approaches target isolated execution that can cost nothing while idle and return in under a second.
The isolation description remains Microsoft’s claim rather than an independently demonstrated property in the supplied material. InfoQ also records skepticism from one Reddit commenter about the “hardware-isolated microVM” wording, although the commenter did not elaborate.
What Express includes—and leaves out
Express includes scale-to-zero operation, multiple replicas, HTTP ingress on a Microsoft-managed domain, environment variables, manual secrets, IP restrictions and log streaming. It can autoscale using HTTP, CPU or memory rules.
| Capability | Express status |
|---|---|
| Scale to zero and multiple replicas | Included |
| HTTP ingress on a Microsoft-managed domain | Included |
| HTTP, CPU and memory autoscaling | Included |
| Custom domains and zone redundancy | Excluded |
| Key Vault references, Easy Auth and OpenTelemetry | Excluded |
| Dapr, jobs and workload profiles | Excluded |
| GPU workloads | Excluded |
| Multiple revisions, traffic splitting and system-assigned managed identities | Excluded |
Service discovery is absent, so applications communicate through public URLs, and ingress supports HTTP only. Outbound subnets cannot be changed after configuration, while per-replica storage has additional constraints. Microsoft recommends a standard Container Apps environment when teams require greater networking control, GPU compute, advanced configuration or environment-level capabilities such as Dapr.
Express requires an account backed by Microsoft Entra ID; personal Microsoft accounts are unsupported. Dedicated views are available at containerapps.azure.com and sandboxes.azure.com, but the regular Azure portal can still manage the resources.
Existing standard environments can migrate through archive and restore. Microsoft says the process preserves application and environment configuration, takes about 15 minutes and does not alter the consumption-free grant. Organizations can use an opt-out form when additional approval or coordination is required. Inactive environments with no running apps or jobs and no recent activity may be archived and put to sleep.
Microsoft also says customers created thousands of Express apps during the public preview.
AI Mastery analysis
Snapshot-based suspension is more important than Express’s simplified API. Preserving memory and disk across scale-to-zero could make stateful agent sessions practical without keeping compute active. However, the available material does not answer operational questions about snapshot retention, encryption, open network connections or in-flight credentials after restoration.
The exclusions also limit Express as a general production replacement for standard Container Apps. Teams needing custom domains, OpenTelemetry, Key Vault references, service identities, Dapr or GPUs will encounter that boundary quickly. Express is better suited to ephemeral agents, prototypes and isolated code execution whose requirements fit its constrained feature set.
For untrusted code, isolation is the product rather than an optional feature. As AI Mastery has previously argued, execution-layer isolation matters more than model guardrails for safe agent deployment. Microsoft’s microVM design is directionally appropriate, but security-sensitive adopters will still need evidence and controls beyond the vendor’s architectural description.
Sources
Frequently asked questions
How quickly can Azure Container Apps Sandboxes start and restore?
Microsoft says prewarmed pools enable subsecond startup. Sandboxes can also snapshot memory and disk during suspension and restore that state in under a second.
Does Azure Container Apps Express support GPU workloads?
No. Express excludes GPU workloads and workload profiles; Microsoft directs teams needing GPU compute or greater infrastructure control to a standard Container Apps environment.
Which features are excluded from Azure Container Apps Express?
Express excludes custom domains, zone redundancy, Key Vault secret references, Easy Auth, OpenTelemetry, Dapr, jobs and system-assigned managed identities. It also lacks multiple revisions and traffic splitting, while ingress is limited to HTTP.
How long does migration to Container Apps Express take?
Microsoft says self-migration through archive and restore takes about 15 minutes. The company says it preserves app and environment configuration without changing the consumption-free grant.
Where is Azure Container Apps Express available?
Microsoft reports that Express reaches more than 40 Azure regions. That covers almost every public Azure region where Container Apps is offered.
Related Reading
DoorDash Flux Handles 130,000 Tasks/Month via Cloud Agent Platform
DoorDash's Flux platform processed 130,000 engineering tasks in one month, with 25,000 automated code reviews weekly and sub-5-second sandbox setup.
Three Async Patterns Cut Lambda Idle Cost in Bedrock AgentCore Pipelines
AWS authors show how task-token callback, direct integration, and durable functions cut Lambda idle cost when calling Bedrock AgentCore agents.

Cloudflare Kitesurf: A Browser Built for AI Agents, Not Humans
Cloudflare's Kitesurf is a cloud-hosted browser built for AI agents on its Workers platform, prioritising token costs and prompt-injection defence over visual rendering.