Product
Product Oct 4, 2026 5 min read

Boat.dev vs Freestyle

Boat.dev is cheaper. Freestyle builds stable, consistent Linux VMs for businesses, with memory snapshots, advanced networking, and credentials held outside the sandbox.

Boat.dev and Freestyle provide Linux sandboxes for agents to run code, install tools, and work on projects. Freestyle builds full Linux virtual machines for businesses that need consistent performance, stable environments, and control over their infrastructure.

Price

Boat is cheaper than Freestyle. If minimizing VM cost is your deciding factor, it can be a good fit. Freestyle is built around quality, consistency, and performance for businesses whose agents need to work reliably.

Extremely cost-sensitive workloads may not need a VM at all. Consider Cloudflare Dynamic Workers for lightweight code execution, AgentOS from Rivet for an embedded agent runtime, Archil serverless execution for commands against stored files, or Browser Use for browser-only work.

Networking

Boat gives each sandbox a public IPv4 or IPv6 address and generated HTTPS URLs. But its published API does not document managed custom domains, private VPCs, or controls for choosing and reserving the assigned public IP. Those gaps leave businesses building and maintaining their own networking integrations.

Freestyle gives you:

Your frontend, API, and database can share a private network, while your browser agent uses an authenticated SOCKS5 proxy through a configured endpoint. You control these relationships through Freestyle's API.

Network secrets injection

Boat's secrets system puts credentials inside the sandbox, where the agent can read and copy them. Deleting a variable or file cannot revoke an extracted credential. Boat does not document network-layer injection that keeps real credentials outside the VM. That is a serious gap for businesses running untrusted code: you hand over the key or build the missing credential proxy yourself.

Freestyle's network secrets injection keeps real credentials at the edge. Your controller defines the permitted service, path, and method; Freestyle injects authentication when connecting upstream. The agent gets access without the real key entering its files, environment, or snapshots.

This supports model API access, private Git repositories, Postgres credential brokering, and authenticated SOCKS5 egress.

Build S3-backed volumes on Freestyle

Freestyle lets you build an S3-backed workspace using FUSE and rclone:

  1. Give each workspace a bucket prefix, such as workspaces/customer-123/.
  2. Mount it with rclone under systemd, using a local VFS cache and background uploads.
  3. Keep disposable build directories such as node_modules and target on local disk.

Add Freestyle's S3 signing transform, and the guest uses placeholder keys. The edge enforces bucket, prefix, and operation permissions before signing requests with the real credentials. Each agent can access its workspace without receiving your storage key.

Flush pending uploads before relying on bucket durability, and use separate prefixes for independently writing branches. S3 filesystem semantics differ from local disk; VM snapshots do not version the external bucket.

Boat does not document equivalent managed S3 signing or bucket-prefix authorization. Those access controls are left for you to implement.

Snapshots: save the running computer

Boat's snapshots save the filesystem, not running processes or memory. Restoring behaves like rebooting: your application has to reconstruct its runtime state.

Freestyle snapshots memory and disk, with less than 1 ms of interruption and less than 50 ms to snapshot readiness. You can checkpoint a loaded browser, preserve a running development environment, or branch after expensive initialization. Each branch starts with the saved process state. External connections may need to reconnect.

Pause and resume preserve memory too, so an agent waiting for approval can continue with its processes intact.

Virtualization quality and consistency

Boat's machine documentation exposes a consistency problem: when standard hosts run out of capacity, new sandboxes fall back to older Hetzner cloud VMs at the same price. Boat reports roughly three times slower builds on those machines, which also lack /dev/kvm.

The same sandbox request can produce substantially different performance and capabilities depending on capacity. A workflow that worked on one machine can slow down or fail on the next without a code change. Businesses need predictable infrastructure.

Freestyle builds around that need for consistency, with full root access, Docker, systemd, FUSE, eBPF, nested virtualization, and normal Linux networking. Agents can run containers, mount filesystems, and build complex environments on a full Linux VM.

Larger VMs and flexible sizing

Boat's largest published size is 16 vCPUs and 32 GB RAM. Freestyle Pro supports 32 vCPUs and 64 GiB per VM, with 64 vCPU, 128 GiB base images available under custom account limits.

Freestyle lets CPU, memory, and disk grow independently, including adding CPU and memory to a running VM without rebooting. A workspace can grow as its repository, services, and browser workload grow. Downsizing requires a new VM.

Choose Freestyle for a business that depends on agents

When customers depend on your agents, consistency and stability are requirements. Your environment needs to behave predictably, retain its state, and keep credentials and network access under your control.

That is what we're building Freestyle for. Memory snapshots, advanced networking, isolated credentials, S3-backed workspaces, and larger, flexible VMs give businesses the foundation for reliable agent workflows. For purely cost-sensitive users who need sandboxes, Boat is the best option today.

esc