frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Ask HN: How are you sandboxing your coding agents?

3•kwar13•1h ago
I've seen a few articles here using bubblewrap, vagrant, VMs, even docker to sandbox coding agents to avoid the inevitable disaster. I've personally been using a headless VM but it's quite resource intensive and I'm wondering if there are better ways to do this.

Comments

gnabgib•1h ago
Recent related Ask HN: How are you sandboxing coding agents? (46 points, 25 days ago, 32 comments) https://news.ycombinator.com/item?id=46400129
kwar13•1h ago
thank you!
burntoutgray•1h ago
I use a physically separate system.

i.e. DEV and PROD are completely airgapped.

bitkin_dev•1h ago
Standard VMs are definitely overkill for per-agent instances due to the resource overhead.

If you need strict isolation for untrusted code but want container-like speed, look into Firecracker (MicroVMs) or gVisor (userspace kernel).

Firecracker is what AWS Lambda uses. It strips down the kernel to the bare minimum, so you get VM-level isolation with millisecond boot times and a tiny memory footprint. It’s essentially the sweet spot between "insecure" Docker and "heavy" full VMs.

handfuloflight•1h ago
Orbstack VM.
rubenflamshep•40m ago
Currently I'm using docker-ized git worktrees so I can dangerously skip permissions. It's not great. Worktrees are not the way to go and Claude Code treats docker as a second-class citizen (e.g., going through the MacOS auth flow deletes the linux-based auth tokens you need to mount in the container)
SafeDusk•17m ago
Using https://github.com/aperoc/toolkami which just spins up a worktree with pre-configured Docker containers.

Rugs of War

https://rugsofwar.wordpress.com/
1•dmbche•4m ago•0 comments

Ask HN: How does YC / HN think about founder voting splits vs. equity splits?

2•cofounder1999•5m ago•0 comments

How long would you survive with no DNA? [video]

https://www.youtube.com/watch?v=s3oLIDaElaE
1•surprisetalk•8m ago•0 comments

Fundamental Engineering Principles

https://blog.tdhttt.com/post/fundamental-engineering-principles/
1•tdhttt•10m ago•0 comments

Canada's Prime Minister Mark Carney's Full Speech at Davos

https://www.cbc.ca/news/politics/mark-carney-speech-davos-rules-based-order-9.7053350
1•qkeast•12m ago•1 comments

Machine with Concrete – Arthur Ganson [video]

https://www.youtube.com/watch?v=5q-BH-tvxEg
1•o4c•13m ago•0 comments

DevOps Didn't Fail – We Just Gave It the Tools It Deserved

https://devops.com/devops-didnt-fail-we-just-finally-gave-it-the-tools-it-deserved/
1•milkglass•14m ago•0 comments

Libbbf: Bound Book Format, A high-performance container for comics and manga

https://github.com/ef1500/libbbf
1•zdw•17m ago•0 comments

Google Health AI Overviews Cite YouTube More Than Any Hospital Site

https://www.searchenginejournal.com/google-health-ai-overviews-cite-youtube-more-than-any-hospita...
1•randycupertino•24m ago•0 comments

OpenFlexure Microscope

https://openflexure.org/projects/microscope/
1•o4c•28m ago•1 comments

A series of distributed systems challenges brought to you by Fly.io

https://fly.io/dist-sys/
3•meistro•30m ago•0 comments

I got into an argument on Discord about how inefficient CBR/CBZ is, so I wrote

https://old.reddit.com/r/selfhosted/comments/1qi64pr/i_got_into_an_argument_on_discord_about_how/
1•todsacerdoti•33m ago•0 comments

Virology Lectures 2025 [video]

https://www.youtube.com/watch?v=3pX0x3mC4Io&list=PLGhmZX2NKiNm2iEUtVslIUHTW9i2zAG72
2•shpx•34m ago•0 comments

Drift

https://github.com/dadbodgeoff/drift
1•handfuloflight•35m ago•0 comments

Using RL to Double an Agent's Effectiveness in Production Debugging

https://www.dbow.me/rl.html
4•anyekwest•42m ago•0 comments

Show HN: DoceraX – Open "Please wait cannot display this document" PDFs Mac

http://fastHNReader.com
1•coolwulf•45m ago•0 comments

Can AI Pass Freshman CS? [video]

https://www.youtube.com/watch?v=56HJQm5nb0U
1•thethirdone•48m ago•1 comments

Explore medieval life and death with these 5 fun interactive maps (2023)

https://weirdmedievalguys.substack.com/p/explore-medieval-life-and-death-with
1•crescit_eundo•49m ago•0 comments

Migrating 13,000 Comments from Drupal to Hugo

https://www.jeffgeerling.com/blog/2026/migrating-13000-comments-from-drupal-to-hugo/
2•zdw•49m ago•0 comments

An 800 year old prayer book that's decorated with puns (2023)

https://weirdmedievalguys.substack.com/p/an-800-year-prayer-book-thats-decorated
3•crescit_eundo•51m ago•0 comments

Air Force One Returns to Joint Base Andrews After 'Minor Electrical Issue'

https://www.wsj.com/livecoverage/greenland-trump-tariffs-trade-eu/card/air-force-one-returns-to-j...
3•thm•51m ago•1 comments

How Birds Got Human Names (2025)

https://weirdmedievalguys.substack.com/p/how-birds-got-human-names
1•crescit_eundo•54m ago•0 comments

Why Not Tail Recursion?

https://futhark-lang.org/blog/2026-01-20-why-not-tail-recursion.html
2•todsacerdoti•57m ago•0 comments

Incremental AI Adoption for E-Commerce – Arcturus Labs

http://arcturus-labs.com/blog/2026/01/18/incremental-ai-adoption-for-e-commerce/
1•JnBrymn•1h ago•0 comments

Everything Moe

https://ianbarber.blog/2026/01/20/everything-moe/
1•phpencil•1h ago•0 comments

Shingles vaccine may help keep older people biologically younger

https://www.thetimes.com/uk/science/article/shingles-vaccine-news-bz55zstn5
7•ValentineC•1h ago•1 comments

Disaster planning for regular folks (2015)

https://lcamtuf.coredump.cx/prep/index-old.shtml
40•AlphaWeaver•1h ago•16 comments

Create video resumes without any recording - perfectclips.netlify.app

1•perfectclips•1h ago•1 comments

DOGE employees may have improperly accessed social security data, DOJ says

https://www.axios.com/2026/01/20/doge-employees-social-security-information-court-filing
6•handfuloflight•1h ago•2 comments

ChatGPT recommended a scam and I spent $300

https://old.reddit.com/r/soylent/comments/1qii7d5/soylent_aus_is_this_a_scam_i_just_spent_so_much/
2•aendruk•1h ago•0 comments