Sandbox creation takes several seconds and can fail at any point. I modeled the workflow as a state machine with pending, scheduling, assigned, starting and running states. PostgreSQL and River provide at-least-once job delivery. Each transition is atomic and idempotent, with conditional updates that prevent a retry from creating a second VM or overwriting a newer state.