The Ephemeral Sandbox: Architecting Secure Runtime Environments for AI Coding Agents with Firecracker MicroVMs