Getting Started with IBM Cloud Sandbox
The IBM Cloud Sandbox is a secure, scalable, and free-to-use trial environment designed to help customers explore and experience IBM Cloud VPC and next-generation infrastructure. It helps users understand how the IBM Cloud infrastructure performs, behaves, and scales for their use cases before making production..
It gives users a 2-week trial to experiment with, test, and assess their applications or workloads using IBM Cloud VPC features.
The IBM Cloud Sandbox is ideal for:
-
Existing IBM Cloud Classic customers running workloads on Classic Virtual Server or Bare Metal Server who want to explore VPC features, validate workload compatibility, and prepare for migration to next-generation VPC infrastructure.
-
Existing IBM Cloud users who want hands-on experience with IBM Cloud services and VPC infrastructure. Users who require a safe, isolated environment to test VPC configurations, evaluate new compute profiles, or deploy workloads without affecting production environments.
To provision the Sandbox service from the IBM Cloud catalog, the user must have administrator-level permissions to initiate the deployment. Users with minimal permissions cannot provision the service.
Before you begin
Before you access the Cloud Sandbox, ensure that the following requirements are met:
-
You need to have an active IBM Cloud account.
-
You have a valid IBMid for authentication.
-
You will receive Welcome to your IBM Cloud Sandbox email. You are all set to deploy the workloads, verify configurations, and experience how VPC helps build secure, scalable cloud solutions.
Understanding Sandbox boundaries and constraints
The Sandbox environment has specific limitations to ensure fair usage and maintain security:
Service availability
The Sandbox provides access to select IBM Cloud Infrastructure as a Service (IaaS) offerings, including:
- Virtual Server for VPC and Bare Metal Servers for VPC
- Block Storage and Instance Storage for VPC
- IBM Cloud Object Storage
- Virtual Private Cloud (VPC) networking components
- Load Balancer, Client VPN, and Transit Gateway
- DNS and Secrets Manager
Other IBM Cloud services outside of these IaaS offerings are not available in the Sandbox environment.
Resource constraints
The Sandbox enforces quota limits on compute, network, and storage resources to ensure optimal performance and fair usage. Key constraints include:
- Compute: Limited vCPU (128) and RAM (1028 GB) for Virtual Servers, and 1 Bare Metal Server
- Storage: Block Storage limited to 4096 GB per VSI, Instance Storage to 1024 GB, and IBM Cloud Object Storage to 4096 GB
- Network: Maximum of 2 VPCs, 4 subnets, 4 Floating IPs, and 10 security groups
- Services: 1 instance each for Load Balancer, VPN, Transit Gateway, DNS, and Secrets Manager
For more details on quota limits, see Sandbox quota limits.
Terms and conditions
By using the Sandbox, you agree to:
- Use the environment for evaluation and testing purposes only, not for production workloads
- Follow security best practices and usage guidelines as outlined in Limitations
- Accept that all resources will be automatically deleted after the 14-day trial period expires
- Comply with IBM Cloud terms of service and acceptable use policies
Creating Sandbox account
- An email notification is sent to all the allow-listed customers to experience the Cloud Sandbox environment.
- After clicking Request, you will be redirected to the Sandbox provisioning page to get started. Update the required information.
Accessing the IBM Cloud Catalog
After clicking Request in the email notification, you will be redirected to the Sandbox provisioning page. If you need to access it later, go directly to the Cloud Sandbox provisioning page.
For more information on provisioning, see Provisioning the IBM Cloud Sandbox topic.
Creating your Sandbox environment
Only users with administrator access in the Cloud Sandbox are authorized to create Sandbox accounts.
Perform the following steps to provision the Sandbox:
-
On the Sandbox provision page, enter the required details:
-
Sandbox name - Provide a unique, descriptive name for your Sandbox environment (for example, "sandbox-month-date")
-
Resource group - Choose an existing resource group or create a new one to organize your sandbox resources. For more information on creating a new resource group, see Creating a resource group.
-
Region - Select the geographic location where your Sandbox resources will be provisioned (for example, us-south, eu-de and so on).
The region cannot be changed after provisioning, and all resources will be created in the selected region.
-
Optional: Enter tags to help you organize and find your resources. You can add more tags later. For more information, see Working with tags.
-
Users - Select the users who will have access to Sandbox. All users are granted the same access level and permissions. For more information on creating/adding users, see Managing user access for Sandbox.
Users can be added only during the initial provisioning page, not during resource creation. Once users are added to a Sandbox account at the time of creation, they remain unchanged until the trial ends. No modifications can be made later, and the roles assigned to them at creation time also remain the same throughout the trial period.
-
-
Click Create sandbox to submit your request. The Sandbox provisioning process typically takes 5-10 minutes. You will receive an email when it is ready, or you can refresh and check the Resource List to see the instance.
-
After the Sandbox is created you can find them listed in the resource list of your account. You can edit the name, manage tags, or delete the Sandbox and all associated resources.
Only one Sandbox creation is allowed per allow-listed customer account.
Accessing your Sandbox through email
After your Sandbox is provisioned, an email is sent to all users with access details and supporting links to explore the Sandbox environment.
-
In the email, click the Access the link and explore the Sandbox link to open the Sandbox environment.
-
When prompted, provide your IBM Cloud credentials to authenticate.
-
If two-factor authentication is enabled on your account, complete the verification process by providing the required authentication code.
-
After successful authentication, you are redirected to the Sandbox trusted profile page.
Select a trusted profile -
If the Sandbox account is not visible on the account page, select the trusted profile from the account drop-down menu. The trusted profile is labeled with the tag
sandbox expires mm/dd. -
After switching to the trusted profile, you are navigated to the Sandbox trusted profile account.
-
Access the Sandbox Overview page (which is quickstart) to begin creating resources and exploring VPC capabilities.
The trusted profile provides secure, time-limited access to your Sandbox environment with appropriate IAM permissions. It automatically expires after the 14-day trial period.
Provisioning resources
In the Sandbox environment, you can create the resources from the Overview page.For more information, see Creating resources in Sandbox topic.
Exploring VPC capabilities
After provisioning resources, use your Sandbox environment to explore VPC features and capabilities.
Testing network features
Configure and validate network components by setting up the subnets, security groups, and network ACLs. Establish the public and private connectivity by testing latency and performance and experimenting with VPN and Transit Gateway configurations.
- For more information on transit gateway, see Creating a Transit Gateway.
- For more information on subnets, see Working with subnets.
- For more information on network ACL, see Creating a network ACL.
- For more information on security group, see Setting up a security group for your resource.
Evaluating compute options
Deploy and compare workloads across different compute profiles to evaluating the performance, scalability, bare metal versus VSI capabilities, and auto-scaling behavior.
For more information on bare metal, see Creating Bare Metal Servers on VPC.
Accessing storage solutions
Manage and evaluate storage by attaching block volumes, integrating IBM Cloud Object Storage (COS), and testing performance.
For more information on block volumes, see Creating Block Storage for VPC volumes.
Configuring load balancing
Configure and test application load balancing by distributing traffic across instances, setting up health checks and monitoring, and validating high availability scenarios.
For more information on load balancer, see Creating an application load balancer.
Monitor your sandbox lifecycle
Your Sandbox environment has a 14-day trial period. To track your remaining time:
-
View the trial period countdown on the Sandbox landing page.
-
Check your email for reminder notifications (typically sent at 7 days, 3 days, and 1 day before expiry).
After the 14-day trial period expires, all resources in the Sandbox environment are automatically deleted. You must save the configuration by downloading the Terraform package and running it in your own customer account.