frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Docker Sandboxes – Disposable, isolated sandboxes for AI agents

https://www.docker.com/products/docker-sandboxes/
66•etoxin•1h ago•36 comments

What Happened to HackerOne?

https://blog.teknogeek.io/posts/what-happened-to-hackerone/
169•hipparchus•4h ago•63 comments

Auto mode is now the default in Claude Code

https://claude.com/blog/auto-mode-default-in-claude-code
153•sbehere•3h ago•132 comments

Run Android ARM64 VR APKs on Apple Vision Pro

https://github.com/shinyquagsire23/Klepton
43•LorenDB•4h ago•3 comments

Show HN: Voice driven murder mystery, Interview AI suspects with your voice

https://www.whodunnitai.com/
55•MrRowTheBoat•3h ago•16 comments

How I use LLMs to learn complex topics

https://laurentiugabriel.github.io/blog/articles/how-i-use-llms-to-learn/
592•laurentiurad•11h ago•336 comments

The Philippines' big offshoring industry is growing despite AI

https://www.economist.com/asia/2026/08/06/the-philippines-big-offshoring-industry-is-growing-desp...
18•nlpnerd•2h ago•16 comments

How We Pushed CDC into Postgres

https://www.snowflake.com/en/blog/engineering/postgres-to-snowflake-replication-mirroring/
79•craigkerstiens•6h ago•6 comments

Turn satellite imagery into a paper globe you fold yourself

https://foldingglobes.com/
37•dango2506•4h ago•8 comments

Slap ROM Patcher

https://nyuu.page/projects/slap/
10•apsec112•3d ago•1 comments

Taxi drivers rarely die of Alzheimer's

https://theconversation.com/taxi-drivers-rarely-die-of-alzheimers-how-complex-mental-maps-and-spa...
267•jader201•15h ago•185 comments

Nearest Pint

https://knowwhereconsulting.co.uk/maps/pubs/
21•bookofjoe•5d ago•3 comments

An Interesting Fourier Transform – 1/F Noise

https://www.dsprelated.com/showarticle/40.php
11•q7m•3d ago•2 comments

Ask HN: What are you working on? (August 2026)

230•david927•13h ago•792 comments

ATProto for Distributed Systems Engineers

https://atproto.com/articles/atproto-for-distsys-engineers
59•LelouBil•3d ago•12 comments

The tragedy of the commons, AI edition

https://www.economist.com/britain/2026/08/06/the-tragedy-of-the-commons-ai-edition
110•simonpure•11h ago•63 comments

Picophysics: Single file physics for games on platforms like N64, PSX, DC

https://gitlab.com/Kazade/picophysics
48•klaussilveira•4d ago•11 comments

Cool URIs Don't Change (1998)

https://www.w3.org/Provider/Style/URI
225•Klaster_1•16h ago•54 comments

New Zealand lost its music media, and what we're building to replace it

https://propelmusic.co.nz/articles/the-sound-went-quiet-nz-music-media
107•berghoffer•10h ago•66 comments

Tuxedo No. 2 – Cocktail recipes

https://tuxedono2.com
82•smartmic•10h ago•22 comments

"The Persian MâR-Nâmeh Or, the Book for Taking Omens from Snakes" (1892)

https://publicdomainreview.org/collection/marnameh/
50•Thevet•3d ago•6 comments

Everything you do is being recorded

https://www.theatlantic.com/technology/2026/05/ai-wearable-surveillance-countermeasures/687203/
275•ike_usawa•19h ago•218 comments

I made tinnitus my friend, then it disappeared [video]

https://mynoise.net/vlog.php?ep=20260803
113•gregsadetsky•12h ago•84 comments

Andrew Wiles on proving Fermat’s Last Theorem (1995) [video]

https://www.youtube.com/watch?v=GS7CxAtV5Ks
51•jackdoe•3d ago•36 comments

The Ambition Project

https://www.betonit.ai/p/the-ambition-project
34•herbertl•7h ago•1 comments

The German Mittelstand

https://kieranvelasquez.substack.com/p/on-the-german-mittelstand
37•Michelangelo11•3d ago•13 comments

OpenChamber: An Agentic Development Environment

https://openchamber.dev/
134•hexomancer•13h ago•73 comments

Windows 11's built-in Weather app wastes more than 1 GB of RAM

https://www.notebookcheck.net/Windows-11-s-built-in-Weather-app-wastes-more-than-1-GB-of-RAM.1364...
483•akyuu•16h ago•399 comments

How Golden Is Silence, Actually?

https://www.newyorker.com/magazine/2026/08/10/silence-kate-mcloughlin-book-review
59•tintinnabula•3d ago•31 comments

Reviving a four year old reMarkable 2

https://oskrim.github.io/hardware/2026/08/09/remarkable-over-ssh.html
140•oskrim•19h ago•95 comments
Open in hackernews

Docker Sandboxes – Disposable, isolated sandboxes for AI agents

https://www.docker.com/products/docker-sandboxes/
66•etoxin•1h ago

Comments

c0rruptbytes•59m ago
Reminds me of sandboxy - https://github.com/apple/containerization/tree/main/examples...

Also if your thing doesn't work with `pi` out of the box, then low effort

laserlight•53m ago
Requires login. Garbage.
Alifatisk•50m ago
What? Does using sbx require login? Bummer.
dSebastien•47m ago
Yes and they have a specific subscription for managing sandbox policies across the enterprise: Docker AI Governance
dSebastien•46m ago
You can create those manually but if you want to enforce those then you need the subscription
binsquare•29m ago
I build a OSS lightweight, portable VM for those that don't want lock ins: https://github.com/smol-machines/smolvm
pixard•50m ago
Ah let's see, do they still want you to LOGIN, in order to use a local dev tool? Yes, yes they do. No thanks Docker. You can keep your buzzword reasoning as to why this is needed.
dSebastien•48m ago
The one thing I wonder about is how you enforce the usage of Docker Sandboxes vs running the agent on the host directly, apart from scanning machines for binaries
notsirius•44m ago
been using this for a while - works great! Has also had a lot of updates over the past year so worth checking out again if you tried it a while ago
zingar•24m ago
Do the agents come preinstalled in the images? Or do they somehow use whatever I’ve installed locally? The former makes sense to me but then I’m wondering whether the sandbox images stay up to date with new releases of each image.
blueaquilae•44m ago
Docker management will fail their tech at every opportunity.
outof•43m ago
Like many people, I suspect, I used Claude to write my own agent sandbox that suits my needs very well. Investing my time in a propietary product has become a hard sell.
zingar•25m ago
Were you following any patterns/standards/advice on what you needed to protect against? Anything you can point the rest of us to?
embedding-shape•18m ago
You want to prevent the agent/others from reaching your home directory and other things. As long as you don't mount/sync directories/files from/to the container, so no mounting like "-v $(pwd):/app", but instead copy in, then when done, copy out.

And of course, instead of doing the "copy in > copy out" process manually, get your local agent to write a bash script that does that for you, given what directory you're in, and you're basically G2G.

hvb2•17m ago
What specifically are you looking for? If you start from the premise that it runs as you right now, then that's something you can easily improve upon.

Start by mounting just your repo and passing in the keys for the agent. Take it from there, it's like software engineering, you iterate.

When you run into issues you expand the tools in the container available to it.

runtime_lens•39m ago
TO me, that's the important distinction: sandboxing limits what the agent can do but it doesn't necessarily enforce that the agent must run inside the sandbox. You need a separate control layer to enforce that boundary.
nezhar•27m ago
You design the sandbox so the agent starts in that layer. The next thing you can do is to limit the network access, this is what I'm working on right now.

Or do you mean something else?

cryptoz•38m ago
The linked page implies there is no linux support, I wonder why. It's there in the docs if you hunt for it.
etoxin•33m ago
The docs are here: https://docs.docker.com/ai/sandboxes/

The other url is their marketing page.

Yes, Linux is supported.

nezhar•37m ago
Open source alternative with podman support and local telemetry collection https://github.com/VibePod/vibepod-cli
reddozen•35m ago
If any AI company was doing serious engineering isolated containers would have been a prerequisite to using their tools.
alentred•33m ago
I am not sure I understand, how is this different from a devcontainer or other similar techniques?

On another topic, can't help but notice that "leading coding agents" somehow does not include Pi.

zmmmmm•29m ago
it's running a full VM so the agent can eg: run docker commands safely etc
karakanb•27m ago
I got excited for this not because this didn't exist before, but because Docker putting their weight on this would imply a broader adoption and better integration in the industry. I am sad that they are asking for a login here though, which doesn't make any sense to me.
KolibriFly•9m ago
That's docker, man. Tomorrow they're gonna add limits on sandbox runs without a premium account too
yellow_lead•20m ago
I know some people want to run their agents when their computer is off, but I imagine a solution like this will be much more common than paying for a remote sandbox (i.e on fly.io or exe.dev), especially because it'll be free.

Though, they need to remove the login requirement.

meffmadd•12m ago
I tried Docker Sandboxes but last time I checked you could not configure custom volume mounts, making more complex setups impossible. For work I need two directories for context for the agent to have access to…
pkhamre•7m ago
I started building my own isolated and security-hardened docker image for OpenCode about half a year ago. Been using it daily.

https://github.com/pkhamre/opencode-docker

Grimburger•6m ago
> Each agent runs inside a dedicated microVM with your dev environment

What's a "microVM" and what's the security model here compared to using real virtual machines with actual constraints on breakouts?

Is it marketing fluff?

Incus/LXD has had VM's for a long time now.

    incus launch images:ubuntu/26.04 my-ubuntu-vm --vm
    incus exec my-ubuntu-vm -- bash
frio•1m ago
It’s real VMs, firecracker style.
hokkos•1m ago
Wow, I hope one day Linux will be able to support the exclusive MacOs/Windows technology of Docker Sandboxes
dannyw•1m ago
I’d rather use another open source solution that doesn’t require a signup, and less likely to get rug pulled.

There is no reason to require a login for creating local mini sandboxes.