Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • I did that with T3 code.
  • Is it different than running any harness in an lxc container or vm in your proxmox (or any) server?
  • The barrier to create this myself is so low that 1: I can do it and 2: bad actors can do it. I’d like to use a shared tool that will get iterated on, but I just don’t want to risk it at this point given I can get “good enough” doing it myself.
  • Daily reminder that containers are not considered a safe security boundary, and never were. If you really need to run untrusted code, use a MicroVM.
  • Interesting, thanks, will keep an eye on this
  • Hi, I think I might be your target audience, I currently run pi on the server in my basement, in a minimalist docker container that gives it access to my code workspace and a config dir. Give me an idea what benefit I get on top of that by using the self-hosted pi pod?
  • Note: this does not appear to be a Kubernetes-based solution, the "pod" part just heavily sounds like it.
  • I'll be sure to check this out but in the meantime, I'd like to ask: Isn't it generally a good practice to run coding agents in a VM? It provides a security boundary so that the agent is restricted to the VM.

    How does this compare? I see it's an "isolated sandbox", but what exactly does that mean?

Explore Birbla archives