frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Ask HN: How are you sandboxing coding agents?

10•m-hodges•3h ago
I've seen people rely on built-in sandboxes, use git worktrees (sometimes inside devcontainers), or run the whole agent inside a Linux VM with minimal host mounts. On Linux, I’ve also seen firejail/bubblewrap mentioned.

For folks actually using these tools day-to-day:

What’s your default setup?

Have you had any "learned the hard way" moments?

What tradeoff (safety vs convenience vs parallelism) has mattered most in practice?

I'm less interested in theoretical best practices than what's actually holding up under real use.

Comments

netcoyote•3h ago
I use a Mac, and wanted to be able to run MacOS programs like Xcode and iOS simulator, so I wrote a couple of different sandbox projects:

- SandVault (https://github.com/webcoyote/sandvault) runs the AI agent in a low-privilege account

- ClodPod (https://github.com/webcoyote/clodpod) runs the AI agent inside a MacOS VM

In both cases I map my code directories using shares/mounts.

I find that I use the low-privilege account solution more because it's easier to setup and doesn't require the overhead of a full VM

sixhobbits•1h ago
I have time machine and just let them fly with --dangerously-skip-permissions on my Mac. Worst thing it's done is back up a database, delete the database, and then run git clean locally which also wiped out the backup, so I'm not saying there are no dangers but honestly I've made worse mistakes and probably more frequently so I generally trust Claude with about the same level of access as me now.

Most common is deleting files etc but if you're using git and have backups it's barely noticeable

OJFord•15m ago
How are you going to notice that while working on ~/projects/acme3000 it for some reason deleted ~/photos/2003/once-in-a-lifetime-holiday/?

Backups are great when you know you need to restore.

gl-prod•1h ago
I spin a Firecracker VM with a custom image that has all the things I need.
stavros•1h ago
I wrote a small utility that wraps commands in Docker: https://github.com/skorokithakis/dox
jomcgi•1h ago
I have a web ui for managing / interacting with opencode sessions. Everything runs as a pod in my homelab cluster so I can let them "bypass" permissions and just restrict the pods.

I wanted something like Claude code web with access to more models / local LLMs / my monorepo tooling, so far it's been great.

The output is a PR so it's hard for it to break anything.

The biggest benefit is probably that it makes it easier to start stuff when I'm out - feels like a much better use of downtime like I'm not waiting to get home to start a session after I have an idea.

The monorepo tooling is a bit win too, for a bunch of things I just have 1 way to do it and clear instructions for them to use the binaries that get bundled into new sessions so it gets things "right" more often.

aussieguy1234•40m ago
I run vscode based agents in Linux, mostly Kilo Code

After a bit of tinkering I was able to get it to all run fine in Firejail, I wrote a guide here https://softwareengineeringstandard.com/2025/12/15/ai-agents...

Fairly basic, limits the agents write access to my projects, all of which are backed up in git.

Ask HN: What did you read in 2025?

237•kwar13•22h ago•336 comments

Ask HN: How are you sandboxing coding agents?

10•m-hodges•3h ago•7 comments

Ask HN: What skills do you want to develop or improve in 2026?

217•meridion•1d ago•356 comments

Tell HN: Merry Christmas

1941•basilikum•2d ago•425 comments

Ask HN: What was the hardest bug you tracked down in 2025?

2•varshith17•6h ago•2 comments

Tell HN: I am afraid AI will take my job at some point

5•funnyfoobar•7h ago•14 comments

Postgres for everything, does it work?

5•saisrirampur•10h ago•5 comments

Ask HN: What are the best engineering blogs with real-world depth?

455•nishilpatel•4d ago•134 comments

Tell HN: Merry Christmas

91•franze•3d ago•56 comments

Ask HN: Is Dart a particularly optimised language for front-end development?

4•theanonymousone•16h ago•5 comments

Ask HN: What is the international distribution/statistics of HN visitors?

60•KellyCriterion•1d ago•26 comments

Ask HN: How many HN'ers Celebrate Christmas vs. ?

18•gist•2d ago•31 comments

Looking for Decent Conversation?

101•kmstout•2d ago•14 comments

Are you verifying that products are readable by AI shopping

2•David_0101•17h ago•0 comments

Ask HN: Why isn't there competition to LinkedIn yet?

58•antfie•4d ago•57 comments

Ask HN: Good uses cases for Fabrice's microquickjs

14•fud101•2d ago•5 comments

Ask HN: Useful (Non-Coding) Agents?

2•qaboutthat•21h ago•0 comments

Stronk.app – open-source gym lifts journal

63•apatheticonion•3d ago•29 comments

Ask HN: At 34, can I aspire to being more than a JavaScript widget engineer?

26•yesitcan•2d ago•21 comments

Google Cloud Run cost me $4,676 in 6 weeks with zero traff

49•creativesage•2d ago•30 comments

Ask HN: My mother was scammed out of all her savings. What should I do?

133•scapbi•4d ago•66 comments

Ask HN: What developer tool do you wish existed in 2026?

22•allenleee•5d ago•21 comments

Ask HN: Oberon et al., vs. Rust

17•mikethe•4d ago•30 comments

Ask HN: People who tried both, how does Waymo compare to Tesla Robotaxi?

6•Austin_Conlon•13h ago•2 comments

Ask HN: What do you consider fun?

22•IndySun•1d ago•13 comments

Ask HN: Why Do You Blog?

20•onesandofgrain•1d ago•11 comments

Are students replacing laptops with iPads in 2026?

4•xthe•1d ago•6 comments

Ask HN: What's the best lecture or talk you've seen in 2025?

23•hopefully_can•1d ago•2 comments

Tell HN: Merry Christmas

19•teruakohatu•3d ago•4 comments

Tell HN: Math academy and iPad and sleep issues solved = me learning math

5•mettamage•1d ago•5 comments