NewManaged GitHub Actions runners on microVMs

Give your agents a real computer.

Kanvify boots isolated microVMs in seconds — persistent machines your AI agents live in, and a fresh one for every CI job. Governed from outside the box. Billed by the second.

  • Billed per second
  • No seats, no minimums
  • Spend caps on by default
per 2 vCPU x64 runner, billed per second
$0.0033/min
machines reused between CI jobs
0
of YAML to move a workflow over
1line
and up to 16 GB per sandbox
8vCPU

Plays well with the tools you already run

  • GitHub Actions
  • Claude
  • Codex
  • MCP
  • Docker
  • docker compose
  • Testcontainers
  • Ubuntu
  • REST API
  • OAuth
  • Go CLI
  • WebSocket PTY
One platform · two kinds of machine

Machines that remember. Machines that vanish.

Your agents need a computer that keeps its state. Your pipeline needs one that leaves nothing behind. Kanvify runs both on the same metal, the same isolation model and the same meter.

Agent computers

A machine your agent lives in.

Persistent sandboxes that keep their files between sessions. Suspend when idle, resume exactly where the agent stopped, and checkpoint before anything risky.

  • Suspend and resume with state intact
  • Checkpoints and restore
  • Egress policy and token budgets
CI runners

A fresh machine for every job.

Ephemeral microVMs pick up your GitHub Actions jobs, run real Docker, and are destroyed at exit. There is no standing fleet to secure.

  • One line of YAML
  • dockerd in the VM — no DinD
  • Per-second billing

Same metalSame isolationOne meter

$0.10 / vCPU-hour for both
Lifecycle

It naps when idle. It wakes up exactly where it left off.

One API call boots a machine. The lifecycle takes it from there — and compute stops whenever your agent does.

running · compute metered per secondcompute this session $0.000000
Governance

Governed from outside the box.

Controls sit between the agent and the world — not inside the prompt, where a clever agent could talk its way around them.

Default-drop egress

Per-sandbox allow and deny rules. If a domain isn’t on the list, the connection never leaves the box.

LLM gateway, your key

Model calls route through the proxy with your provider key — budgets enforced per call, caching and fallbacks included, no Kanvify LLM charge.

Checkpoints

A point-in-time image of the disk. Roll back to a known-good state when a run goes sideways.

Spend caps

Metered per second, attributed per sandbox, and stopped by an account-level cap before runaway usage becomes a bill.

Audit trail

Sandbox activity is logged to an audit trail you can review after the fact.

Developer platform

Built to be driven by agents.

Everything on this page is an API call.

REST API & scoped keys
Script the full sandbox lifecycle with keys scoped to read, write or exec.
OAuth provider
Let third-party tools act on a user’s behalf with scoped tokens.
MCP server
Connect Claude and other MCP clients to your Kanvify workspace over OAuth.
Web terminal
Drop into any sandbox from the browser and see what your agent sees.
sandbox:readsandbox:writesandbox:exec
# one static binary, standard library only
$ export KANVIFY_API_KEY=knv_… KANVIFY_WORKSPACE=ws_…
$ kanvify create --image ubuntu:22.04 --name agent --cpu 2 --memory 4
sbx_Q7mK2vP9xLr4  agent  running
$ kanvify cp ./task.md agent:/workspace/task.md
uploaded ./task.md -> agent:/workspace/task.md
$ kanvify exec -s agent -- make test   # exits with the real code
$ kanvify exec -s agent --interactive  # or just drop in
CI runners

Swap one line. Every job gets its own machine.

Managed GitHub Actions runners on ephemeral microVMs — a real machine per job, real Docker, and a spec sheet instead of a slogan. We publish our numbers, including the ones we’re still improving.

  1. Install the GitHub App

    One command from your Kanvify workspace connects your GitHub org. Nothing to host, patch or scale on your side.

  2. Edit one line

    Change runs-on: to kanvify in any workflow. Your steps, actions and secrets stay untouched.

  3. Push and watch

    Each queued job boots a microVM that registers just-in-time. Cold queue-to-pickup is about 60 seconds today; we publish it because we intend to shrink it.

.github/workflows/ci.yml — full diff+1 −1
jobs:  build:-   runs-on: ubuntu-latest+   runs-on: kanvify    steps:      - uses: actions/checkout@v4      - run: docker compose up -d   # real dockerd — just works      - run: pnpm test
Unit spec · per jobKV-CI-01 · REV 2026-07
Execution unit
1 microVM, single-tenant
Lifetime
one job, then destroyed
Runner registration
just-in-time, per job
Docker
dockerd in the VM — no DinD
Arch / OS
x64 · Ubuntu Linux
Queue → pickup (cold)
~60 s today · improving
Billing
per second — pure usage, no tiers

Priced like a utility.

A 61-second job costs 61 seconds. No rounding up, no included-minute buckets.

  • GitHub hosted$0.006/min

    Rounds each job up to a full minute · shared-pool VM

  • Challenger field (Blacksmith · Depot · WarpBuild)$0.004/min

    Mostly per-minute · varying isolation

  • Kanvify$0.0033/min

    Per-second — fresh microVM per job, destroyed at exit

  • Budget floor (Ubicloud)$0.0016/min

    Per-minute · ephemeral VM, more DIY

Comparison for a 2 vCPU x64 Linux runner. Market rates as commonly published, 2026-07.

Billing policies

Granularity
per-second, quoted per-minute
Queue time
billed once the sandbox starts
Infra-interrupted jobs
runtime consumed is billed
Base / platform fee
none — no subscription minimum

Nothing is reused; nothing is left behind for the next run to find.

Savings calculator

2 vCPU x64 Linux
min / month

GitHub-hosted at $0.006/min vs. Kanvify at $0.0033/min — 2 vCPU × $0.10/vCPU-hour, billed per second.

GitHub-hosted
$60.00 / month
Kanvify
$33.33 / month

You save

$26.67/ month

$320.00/ year

New accounts start with $5 of compute credit (about 1,500 runner minutes, valid 90 days). Card required.

Estimates cover 2 vCPU runner compute only. They exclude storage and cache (billed separately at $0.0001/GB-hour) and GitHub’s included free minutes. GitHub-hosted rate as published January 2026.

GitHub-hosted: $60.00 a month. Kanvify: $33.33 a month. You save $26.67 a month, $320.00 a year.
Pricing

Pure usage. One invoice.

Compute, sandbox storage, and cache storage are three separately metered invoice lines. Bring your own LLM provider key; Kanvify does not charge for model usage.

Meter 01 · Compute

Runners + agent computers

$0.10/ vCPU-hour

vCPU-hours while a sandbox is running. Ephemeral CI runners and persistent agent computers use the same rate; suspended computers do not accrue compute charges.

Meter 02 · Sandbox storage

Filesystems + checkpoints

$0.0001/ GB-hour

GB-hours for sandbox filesystems and retained checkpoints. Retained checkpoints continue to accrue storage usage after their source sandbox is suspended or destroyed.

Meter 03 · Cache storage

Retained CI cache data

$0.0001/ GB-hour

GB-hours for retained compressed CI cache data. Cache uploads, downloads, transfer bytes, and R2 operation counts are not billed.

LLM proxy · Bring your own key

We don’t charge for LLM usage

You pay your provider directly. The proxy still adds caching, routing, cost visibility, and keeps your key out of the sandbox.

No tiers. No seats. No minimum. Pay for what you run.

Honest roadmap

Not on the page yet.

  • Fork a running machine
  • Humans and agents on one machine, live
  • Stable preview URLs across suspend and resume
  • Bring your own cloud
  • ARM runners
  • macOS / Windows runners
  • Layer-cache add-on
  • Sticky disks
  • Static egress IPs

We list what we don’t do so you can trust what we say we do. These are on the roadmap; nothing above is.

Your agents are ready.
Give them a computer.

Boot a sandbox, hand it to your agent, point a workflow at runs-on: kanvify. Self-serve, and billed only for what you run.

Self-serve. Spend caps on by default.