Problem
The custom Cosmos session-storage example scopes documents by trusted user and hosted sandbox and uses create-only/ETag writes, but each stored response can create another host-generated snapshot key. The example currently does not require expiry, a per-scope quota or a server-managed lifecycle for reclaiming abandoned snapshots. Namespace isolation and optimistic concurrency do not bound accumulated storage or cost.
Raised in the review of #8899: #8899 (comment) . The maintainer explicitly chose to track retention and quotas separately instead of expanding that Responses integration/isolation PR.
Scope
python/samples/04-hosting/foundry-hosted-agents/responses/custom_storage/main.py and its README/configuration guidance.
- Any reusable storage lifecycle support should preserve the existing canonical lookup-key, trusted user/sandbox and per-key concurrency contracts.
Acceptance criteria
- Define operator-controlled snapshot retention and implement server-driven reclamation, such as verified container/item TTL or a managed cleanup lifecycle.
- Ensure configured TTL actually takes effect; document the required container configuration and fail explicitly when a mandatory retention policy is not supported or disabled.
- Define and enforce a per-scope capacity policy or admission/cleanup mechanism that remains safe under concurrent creates and conditional updates.
- Preserve ETag/create-only protection, inner MAF session IDs, trusted user/sandbox separation and canonical response/conversation lookup keys.
- Document expiration effects on response/conversation continuation, quota errors, cleanup ownership and recovery expectations without silently falling back to unscoped or unretained storage.
- Validate boundary limits, concurrent accounting, expiry/deletion and failure behavior without a real Cosmos account; live resource setup remains separately authorized.
Related: #8746, #8899 and #8900. No Cosmos provisioning, configuration changes or live deployment have been performed for this follow-up.
Problem
The custom Cosmos session-storage example scopes documents by trusted user and hosted sandbox and uses create-only/ETag writes, but each stored response can create another host-generated snapshot key. The example currently does not require expiry, a per-scope quota or a server-managed lifecycle for reclaiming abandoned snapshots. Namespace isolation and optimistic concurrency do not bound accumulated storage or cost.
Raised in the review of #8899: #8899 (comment) . The maintainer explicitly chose to track retention and quotas separately instead of expanding that Responses integration/isolation PR.
Scope
python/samples/04-hosting/foundry-hosted-agents/responses/custom_storage/main.pyand its README/configuration guidance.Acceptance criteria
Related: #8746, #8899 and #8900. No Cosmos provisioning, configuration changes or live deployment have been performed for this follow-up.