SYSTEM Cited by 1 source
cloudflare/debian-trixie¶
cloudflare/debian-trixie is a Cloudflare-managed, ready-to-use base
system image for Cloudflare Containers,
introduced with the 2026-09 agent-sandbox rearchitecture. It bundles Debian
Trixie Slim and Node.js 24.20.0 LTS, and is aimed at
agents that configure their environment at runtime rather than baking a custom
Dockerfile.
(Source: sources/2026-09-30-cloudflare-containers-rebuilt-to-scale-agent-sandboxes)
Why it exists¶
As the scheduling path got faster (see sources/2026-09-30-cloudflare-containers-rebuilt-to-scale-agent-sandboxes), image preparation became a larger share of the remaining startup wait: before a Container can start, its image must be on the host and unpacked into a filesystem. If that work happens after the request arrives, the agent waits.
cloudflare/debian-trixie removes that from the user-visible path in two ways:
- No build step. An agent starts a Linux sandbox without authoring a
Dockerfile, building an image, or pushing it to Cloudflare — then uses
exec()to clone a repo, install packages, and configure for its task. - Pre-distribution. Because Cloudflare controls the image, it is distributed and unpacked onto eligible Containers hosts before requests arrive — startups don't download or unpack the base image while the user waits. This is cold-start mitigation via image locality (the scheduler already favors hosts holding the image or snapshot locally).
Usage¶
this.ctx.container.start({
image: "cloudflare/debian-trixie",
instance: "standard-2",
enableInternet: true,
entrypoint: ["/bin/sleep", "infinity"]
});
Composition with snapshots¶
The prepared image composes with native
filesystem snapshots: an agent starts
from cloudflare/debian-trixie, sets up its environment with exec(), then
saves the result as a snapshot. Future sandboxes start from that snapshot with
the repo, dependencies, and toolchain already in place — the prepared base image
is the zero-of-the-chain, snapshots are the incremental checkpoints on top.
Seen in¶
- sources/2026-09-30-cloudflare-containers-rebuilt-to-scale-agent-sandboxes — introduced as the ready-to-use agent base image (Debian Trixie Slim + Node.js 24.20.0 LTS), pre-distributed to hosts so image download/unpack leaves the user-visible startup path.
Related¶
- systems/cloudflare-containers — the runtime this image starts on.
- systems/cloudflare-durable-objects — the controller that selects this image
at runtime via
ctx.container.start. - systems/nodejs — bundled runtime (24.20.0 LTS).
- systems/firecracker — micro-VM the image boots inside.
- concepts/cold-start — the problem pre-distribution attacks.
- patterns/warm-pool-zero-create-path — the broader "prepare work before the request" discipline this image participates in.
- companies/cloudflare — operator.