DeepSeek Elastic Compute (DSec) Infrastructure

DeepSeek Elastic Compute (DSec) is a production sandbox platform that enables large-scale agentic training and evaluation by providing isolated, stateful execution environments. It solves the challenge of managing millions of sandboxes in large bursts, handling heterogeneous isolation requirements and maintaining state across long interactions while optimizing resource utilization.

High-Density Sandbox Management

DSec achieves high-density execution through a combination of memory sharing, reclamation, and optimized CPU scheduling. A single production-scale unit of DSec spans approximately 160 CPU nodes with 30,000 cores and 250 TB of DRAM. This infrastructure supports the following performance metrics:

  • Concurrent Sandboxes: Peak concurrency reaches approximately 380,000 instances.
  • Daily Volume: A single scale unit serves about 3 million sandbox instances per day.
  • Creation Rate: The platform sustains a creation rate exceeding 5,000 instances per second.

Unified Sandbox Backends

To accommodate different isolation and functionality requirements, DSec exposes multiple sandbox backends through a unified SDK. This allows the system to select the appropriate level of isolation based on the task:

  • FnCall: For lightweight, function-calling tasks.
  • Containers: For standard isolated environments.
  • Container-based microVMs: For stronger isolation.
  • Full-VMs: For the most rigorous isolation requirements.

Distributed Image Distribution and Storage

DSec utilizes the Fire-Flyer File System (3FS), a cluster-wide distributed filesystem, to load image data on demand. This approach reduces environment setup overhead and minimizes the image-distribution bottleneck typically associated with large image corpora with limited reuse.

Co-design with Reinforcement Learning (RL) Frameworks

DSec is specifically co-designed with the reinforcement learning framework to optimize the GPU training loop. It decouples stateful rollout execution (where the agent interacts with the environment) from preemptible GPU training. This coordination allows the platform to preserve rollout state while reclaiming idle resources, which mitigates agent misbehavior such as reward hacking.

Community and Industry Perspectives

Industry observers and developers have noted the similarities between DSec and Google's Ax project, suggesting a parallel evolution in the infrastructure required for agentic AI. Community discussion highlights the scale of the operation, with users noting the 12 sandboxes per core ratio as particularly impressive.

"Within one scale unit, the platform spans nearly 160 CPU nodes with 30K cores and ∼250 TB of DRAM... peak concurrency reaching ∼380K and a creation rate exceeding 5,000 instances per second."

Additionally, security experts emphasize that as models become more capable, the necessity for secure, isolated sandboxes that prevent models from escaping their environment is becoming a critical requirement for safe AI deployment.

Sources

Related

  • Dispatch
  • Project
  • Project
  • Dispatch
  • Project