Function: createCompartmentRuntime()
ts
function createCompartmentRuntime(
globals: Record<string, (...args: unknown[]) => unknown>,
limits: GuestLimits,
modules?: Record<string, unknown>,
hostLockdown?: boolean,
): Promise<{
evaluate: Promise<GuestOutcome>;
kill: Promise<void>;
}>;Defined in: src/batteries/sandbox/js/compartment.ts:33
Construct a minimal SES-backed in-process guest.
Parameters
| Parameter | Type | Default value |
|---|---|---|
globals | Record<string, (...args: unknown[]) => unknown> | undefined |
limits | GuestLimits | undefined |
modules | Record<string, unknown> | {} |
hostLockdown | boolean | true |
Returns
Promise<{ evaluate: Promise<GuestOutcome>; kill: Promise<void>; }>
Remarks
In Node, SES lockdown is process-global: this hardens the whole host realm, not only the guest. Guest-scoped isolation requires a worker or child runtime.