9 ms·
Deno Sandbox
- johnspurlock 8mo ago"Over the past year, we’ve seen a shift in what Deno Deploy customers are building: platforms where users generate code with LLMs, and that code runs immediately without review. That code frequently calls LLMs itself, which means it needs API keys and network access. This isn’t the traditional “run untrusted plugins” problem. It’s deeper: LLM-generated code, calling external APIs with real credentials, without human review. Sandboxing the compute isn’t enough. You need to control network egress and protect secrets from exfiltration. Deno Sandbox provides both. And when the code is ready, you can deploy it directly to Deno Deploy without rebuilding."
- twosdai 8mo agoLike the emdash, whenever I read: "this isn't x it's y" my dumb monkey brain goes "THATS AI" regardless if it's true or not.
- lucacasonato 8mo agoI can confirm Ryan is a real human :)
- zamadatix 8mo agoIs there a chance you could ask Ryan if he had an LLM write/rewrite large parts of this blog post? I don't mind at all if he did or didn't in itself, it's a good and informative post, but I strongly assumed the same while reading the article and if it's truly not LLM writing then it would serve as a super useful indicator about how often I'm wrongly making that assumption.
- javier123454321 8mo agoAs someone that has a habit of maybe overusing em dashes to my detriment, often times, and just something that I try to be mindful of in general. This whole thing of assuming that it's AI generated now is a huge blow. It feels like a personal attack.
- zamadatix 8mo ago"—" has always seemed like an particularly weak/unreliable signal to me, if it makes you feel any better. Triply so in any content one would expect smart quotes or formatted lists, but even in general. RIP anyone who had a penchant for "not just x, but y" though. It's not even a go-to wording for me and I feel the need to rewrite it any time I type it out of fear it'll sound like LLMs.
- zbentley 8mo ago> RIP anyone who had a penchant for "not just x, but y" though I felt that. They didn’t just kidnap my boy; they massacred him.
- adastra22 8mo agoIt’s about more than the emdash. The LLM writing falls into very specific repeated patterns that become extremely obvious tells. The first few paragraphs of this blog post could be used in a textbook as it exhibits most of them at once.
- calebhwin 8mo ago[dead]
- bonsai_spool 8mo agoThere are multiple signs of LLM-speak: > Over the past year, we’ve seen a shift in what Deno Deploy customers are building: platforms where users generate code with LLMs and that code runs immediately without review This isn't a canonical use of a colon (and the dependent clause isn't even grammatical)! > This isn’t the traditional “run untrusted plugins” problem. It’s deeper: LLM-generated code, calling external APIs with real credentials, without human review. Another colon-offset dependent paired with the classic, "This isn't X. It's Y," that we've all grown to recognize. > Sandboxing the compute isn’t enough. You need to control network egress and protect secrets from exfiltration. More of the latter—this sort of thing was quite rare outside of a specific rhetorical goal of getting your reader excited about what's to come. LLMs (mis)use it everywhere. > Deno Sandbox provides both. And when the code is ready, you can deploy it directly to Deno Deploy without rebuilding. Good writers vary sentence length, but it's also a rhetorical strategy that LLMs use indiscriminately with no dramatic goal or tension to relieve. 'And' at the beginning of sentences is another LLM-tell.
- jonny_eh 8mo ago> It’s deeper: LLM-generated code, calling external APIs with real credentials, without human review. This also follows the rule of 3s, which LLMs love, there ya go.
- johnfn 8mo agoYeah, I feel like this is really the smoking gun. Because it's not actually deeper? An LLM running untrusted code is not some additional level of security violation above a plugin running untrusted code. I feel like the most annoying part of "It's not X, it's Y" is that agents often say "It's not X, it's (slightly rephrased X)", lol, but it takes like 30 seconds to work that out.
- jonny_eh 8mo agoIt's not just different way of saying something, it's a whole new way to express an idea.
- 8mo ago
- Bnjoroge 8mo agocouldnt agree more. It's frankly very fatiguing
- bangaladore 8mo agoAnother common tell nowadays is the apostrophe type (’ vs '). I don't know personally how to even type ’ on my keyboard. According to find in chrome, they are both considered the same character, which is interesting. I suspect some word processors default to one or the other, but it's becoming all too common in places like Reddit and emails.
- int_19h 8mo agoWord (you know, the most popular word processor out there) will do that substitution. And on macOS & iOS, it's baked into the standard text input widgets so it'll do that basically everywhere that is a rich text editor.
- signal11 8mo agoIf you work with macOS or iOS users, you won’t be super surprised to see lots of “curly quotes”. They’re part of base macOS, no extra software required (I cannot remember if they need to be switched on or they’re on by default), and of course mass-market software like Word will create “smart” quotes on Mac and Windows. I ended up implementing smart quotes on an internal blogging platform because I couldn’t bear "straight quotes". It’s just a few lines of code and makes my inner typography nerd twitch less.
- deathanatos 8mo ago> According to find in chrome, they are both considered the same character, which is interesting. Browsers do a form of normalization in search. It's really useful, since it means "resume" will match résumé, unless of course you disable it (in Firefox, this is the "Match Diacritics" checkbox). (Also: itʼs, it's; if you want to see it in action on those two words.)
- aiahs 8mo agoFor me it's the "why this matters", "why this works", etc
- TheTaytay 8mo agoUgh - yes. I’m seriously close to writing a chrome extension just to warn me or block pages that have that phrase…it’s irrational because there are so many legitimate uses, but they are dead to me.
- FooBarWidget 8mo agoI don't know man, I feel emboldened to keep using emdash exactly because I want to protest against people equating emdash with "AI reply" even though there are very legitimate uses for emdash.
- signal11 8mo agoI’ve been using em-dashes since high school — publishing the school paper and everything. I remain slightly bemused by people discovering em-dashes for the first time thanks to LLMs. Also, “em-dashes are something only LLMs use” comes perilously close to “huh, proper grammar, must’ve run this by a grammar checker”.
- Latty 8mo agoI started using them when I discovered the compose key and it became easy to type them, but I've genuinely considered stopping using for this reason.
- pawelduda 8mo agoit's the <<<<gold-standard>>>> for spotting LLMs in the wild (that's what Gemini would say)
- yawnxyz 8mo agothe problem with this is that people are adapting their REAL SPEECH to this pattern, so people are actually saying this in real conversations (we do this all the time; eg. a new popular saying lands in an episode of a tv show, and then other people start adopting it, even subconsciously)
- deleted 8mo ago[deleted]
- ttoinou 8mo agoWhat happens if we use Claude Pro or Max plans on them ? It’ll always be a different IP connecting and we might get banned from Anthropic as they think we’re different users Why limit the lifetime on 30 mins ?
- lucacasonato 8mo agoWe'll increase the lifetime in the next weeks - just some tech internally that needs to be adjusted first.
- mrkurt 8mo agoFor what it's worth, I do this from about 50 different IPs and have had no issues. I think their heuristics are more about confirming "a human is driving this" and rejecting "this is something abusing tokens for API access".
- paxys 8mo agoWhat's the use case for this? Trying to get raw API access through a monthly plan? Or something else?
- ttoinou 8mo agoSimply using your subscription in a sandbox ?
- andrewmcwatters 8mo ago[dead]
- emschwartz 8mo ago> In Deno Sandbox, secrets never enter the environment. Code sees only a placeholder > The real key materializes only when the sandbox makes an outbound request to an approved host. If prompt-injected code tries to exfiltrate that placeholder to evil.com? Useless. That seems clever.
- perfmode 8mo agoI was just about to say the same thing. Cool technique.
- motrm 8mo agoReminds me a little of Fly's Tokenizer - https://github.com/superfly/tokenizer https://github.com/superfly/tokenizer It's a little HTTP proxy that your application can route requests through, and the proxy is what handles adding the API keys or whatnot to the request to the service, rather than your application, something like this for example: Application -> tokenizer -> Stripe The secrets for the third party service should in theory then be safe should there be some leak or compromise of the application since it doesn't know the actual secrets itself. Cool idea!
- tptacek 8mo agoIt's exactly the tokenizer, but we shoplifted the idea too; it belongs to the world! (The credential thing I'm actually proud of is non-exfiltratable machine-bound Macaroons). Remember that the security promises of this scheme depend on tight control over not only what hosts you'll send requests to, but what parts of the requests themselves.
- e12e 8mo agoLooks promising. Any plans for a version that runs locally/self-host able? Looks like the main innovation here is linking outbound traffic to a host with dynamic variables - could that be added to deno itself?
- ianberdin 8mo agoFirecrackervm with proxy?
- jonthepirate 8mo agoseems it.
- simonw 8mo agoNote that you don't need to use Deno or JavaScript at all to use this product. Here's their Python client SDK: https://pypi.org/project/deno-sandbox/ https://pypi.org/project/deno-sandbox/ from deno_sandbox import DenoDeploy sdk = DenoDeploy() with sdk.sandbox.create() as sb: # Run a shell command process = sb.spawn("echo", args=["Hello from the sandbox!"]) process.wait() # Write and read files sb.fs.write_text_file("/tmp/example.txt", "Hello, World!") content = sb.fs.read_text_file("/tmp/example.txt") print(content) Looks like the API protocol itself uses websockets: https://tools.simonwillison.net/zip-wheel-explorer?package=deno-sandbox#deno_sandbox/sandbox.py--L187 https://tools.simonwillison.net/zip-wheel-explorer?package=d...
- koakuma-chan 8mo agoBecause the sandbox is on their cloud, not on your local machine, which wasn't obvious to me.
- sli 8mo agoIt's stated under the "Sandboxes?" heading. > Deno Sandbox gives you lightweight Linux microVMs (running in the Deno Deploy cloud) ...
- ChatGPTBanger 8mo ago[dead]
- rdhyee 8mo agoTook this idea and ran with it using Fly's Sprites, inspired by Simon's https://simonwillison.net/2026/Feb/3/introducing-deno-sandbox/ https://simonwillison.net/2026/Feb/3/introducing-deno-sandbo.... Use case: Claude Code running in a sandboxed Sprite, making authenticated API calls via a Tokenizer proxy without credentials ever entering the sandbox. Hit a snag: Sprites appear network-isolated from Fly's 6PN private mesh (fdf:: prefix inside the Sprite, not fdaa::; no .internal DNS). So a Tokenizer on a Fly Machine isn't directly reachable without public internet. Asked on the Fly forum: https://community.fly.io/t/can-sprites-reach-internal-fly-services-6pn-internal/27059 https://community.fly.io/t/can-sprites-reach-internal-fly-se... @tptacek's point upthread about controlling not just hosts but request structure is well taken - for AI agent sandboxing you'd want tight scoping on what the proxy will forward.
- Tepix 8mo agoIf you can create a deno sandbox from a deno sandbox, you could create an almost unkillable service that jumps from one sandbox to the next. Very handy for malicious purposes. ;-) Just an idea…
- nihakue 8mo agoSee also Sprites (https://news.ycombinator.com/item?id=46557825 https://news.ycombinator.com/item?id=46557825) which I've been using and really enjoying. There are some key architecture differences between the two, but very similar surface area. It'll be interesting to see if ephemeral + snapshots can be as convenient as stateful with cloning/forking (which hasn't actually dropped yet, although the fly team say it's coming). Will give these a try. These are exciting times, it's never been a better time to build side projects :)
- alooPotato 8mo agowhat are the key architectural differences?
- tptacek 8mo agoSprites aren't ephemeral. They're like deli cups: "semi-disposable". You keep them around as long as you feel like, and you don't feel bad about throwing them away.
- tomComb 8mo agoYes, sprites looks great too – would certainly be interested in a comparison.
- snehesht 8mo ago50/200 Gb free plus $0.5 / Gb out egress data seems expensive when scaling out.
- ATechGuy 8mo ago> allowNet: ["api.openai.com", "*.anthropic.com"], How to know what domains to allow? The agent behavior is not predefined.
- CuriouslyC 8mo agoThe idea is to gate automatic secret replacement to specific hosts that would use them legitimately to avoid exfiltration.
- falcor84 8mo agoWell, this is the hard part, but the idea is that if you're working with both untrusted inputs and private data/resources, then your agent is susceptible to the "lethal trifecta"[0], and you should be extremely limiting in its ability to have external network access. I would suggest starting with nothing beyond the single AI provider you're using, and only add additional domains if you are certain you trust them and can't do without them. [0] https://simonwillison.net/2025/Jun/16/the-lethal-trifecta/ https://simonwillison.net/2025/Jun/16/the-lethal-trifecta/
- mrpandas 8mo agoWhere's the real value for devs in something like this? Hasn't everyone already built this for themselves in the past 2 years? I'm not trying to sound cheeky or poo poo the product, just surprised if this is a thing. I can never read what's useful by gut anymore, I guess.
- slibhb 8mo ago> Hasn't everyone already built this for themselves in the past 2 years? Even if this was true, "everyone building X independently" is evidence that one company should definitely build X and sell it to everyone
- falcor84 8mo ago> Hasn't everyone already built this for themselves in the past 2 years? The short answer is no. And more so, I think that "Everyone I know in my milieu already built this for themselves, but the wider industry isn't talking about it" is actually an excellent idea generator for a new product.
- ATechGuy 8mo agoIn the last one year, we have seen several sandboxing wrappers around containers/VMs and they all target one use case AI agent code execution. Why? perhaps because devs are good at building (wrappers around VMs) and chase the AI hype. But how are these different and what value do they offer over VMs? Sounds like a tarpit idea, tbh. Here's my list of code execution sandboxing agents launched in the last year alone: E2B, AIO Sandbox, Sandboxer, AgentSphere, Yolobox, Exe.dev, yolo-cage, SkillFS, ERA Jazzberry Computer, Vibekit, Daytona, Modal, Cognitora, YepCode, Run Compute, CLI Fence, Landrun, Sprites, pctx-sandbox, pctx Sandbox, Agent SDK, Lima-devbox, OpenServ, Browser Agent Playground, Flintlock Agent, Quickstart, Bouvet Sandbox, Arrakis, Cellmate (ceLLMate), AgentFence, Tasker, DenoSandbox, Capsule (WASM-based), Volant, Nono, NetFence
- ushakov 8mo agowhy? because there’s a huge market demand for Sandboxes. no one would be building this if no one would be buying. disclaimer: i work at E2B
- zenmac 8mo ago>Deno Sandbox gives you lightweight Linux microVMs (running in the Deno Deploy cloud) The real question is can the microVMs run in just plain old linux, self-hosted.
- echelon 8mo agoEveryone wants to lock you in. Unfortunately there's no other way to make money. If you're 100% liberally licensed, you just get copied. AWS/GCP clone your product, offer the same offering, and they take all the money. It sucks that there isn't a middle ground. I don't want to have to build castles in another person's sandbox. I'd trust it if they gave me the keys to do the same. I know I don't have time to do that, but I want the peace of mind.
- ushakov 8mo agowe have 100% open-source Sandboxes at E2B git: https://github.com/e2b-dev/infra https://github.com/e2b-dev/infra wiki: https://deepwiki.com/e2b-dev/infra https://deepwiki.com/e2b-dev/infra
- echelon 8mo agoThis is what I like to see! Not sure what your customers look like, but I'd for one also be fine with "fair source" licenses (there are several - fair source, fair code, Defold license, etc.) These give customers 100% control but keep Amazon, Google, and other cling-on folks like WP Engine from reselling your work. It avoids the Docker, Elasticsearch, Redis fate. "OSI" is a submarine from big tech hyperscalers that mostly take. We should have gone full Stallman, but fair source is a push back against big tech.
- ushakov 8mo agowe aren’t worried about that. when we were starting out we figured there was no solution that would satisfy our requirements for running untrusted code. so we had to build our own. the reason we open-sourced this is because we want everyone to be able to run our Sandboxes - in contrast to the majority of our competitors who’s goal is to lock you in to their offering. with open-source you have the choice, and luckily Manus, Perplexity, Nvidia choose us for their workloads. (opinions my own)
- MillionOClock 8mo agoCan this be used on iOS somehow? I am building a Swift app where this would be very useful but last time I checked I don't think it was possible.
- lucacasonato 8mo agoIt’s a cloud service - so you can call out to it from anywhere you want. Just don’t ship your credentials in the app itself, and instead authenticate via a server you control.
- koolala 8mo agoThe free plan makes me want to use it like Glitch. But every free service like this ever has been burned...
- LAC-Tech 8mo agoAs a bit of an aside, I've gotten back into deno after seeing bun get bought out by an AI company. I really like it. Startup times are now better than node (if not as good as bun). And being able to put your whole "project" in a single file that grabs dependencies from URLs reduces friction a surprising amount compared to having to have a whole directory with package.json, package-lock.json, etc. It's basically my "need to whip up a small thing" environment of choice now.
- eric-burel 8mo agoCan it be used to sandbox an AI agent, like replacing eg Cursor or Openclaw sandboxing system?
- bopbopbop7 8mo agoNow I see why he was on twitter saying that the era of coding is over and hyping up LLMs, to sell more shovels...
- latexr 8mo ago> evil.com That website does exist. It may hurt your eyes.
- lucacasonato 8mo agoWe honestly should have just linked to oracle.com instead of evil.com
- dangoodmanUT 8mo agoLove their network filtering, however it definitely lacks some capabilities (like the ability to do direct TCP connections to Postgres, or direct IP connections. Those limitations from other tools was exactly why I made https://github.com/danthegoodman1/netfence https://github.com/danthegoodman1/netfence for our agents
- EGreg 8mo agoWe already have a pretty good sandbox in our platform: https://github.com/Qbix/Platform/blob/main/platform/plugins/Q/web/js/methods/Q/Sandbox/run.js https://github.com/Qbix/Platform/blob/main/platform/plugins/... It uses web workers on a web browser. So is this Deno Sandbox like that, but for server? I think Node has worker threads.
- Bnjoroge 8mo agoIgnoring the fact that most of the blog post is written by an LLM, I like that they provide a python sdk. I dont believe vercel does for their sandbox product.
- GreenWatermelon 8mo agoI can't ignore that fact. The post was suffocating to read. LLMs have an obnoxious style.
- yakkomajuri 8mo agoSecret placeholders seems like a good design decision. So many sandbox products these days though. What are people using in production and what should one know about this space? There's Modal, Daytona, Fly, Cloudflare, Deno, etc
- ushakov 8mo agoFactory, Nvidia, Perplexity and Manus are using E2B in production - we ran more than 200 million Sandboxes for our customers
- ATechGuy 8mo agoThese are all wrappers around VMs. You could DIY these easily by using EC2/serverless/GCP SDKs.
- easton 8mo agoYou can and can’t, at least in AWS. For instance, you can’t launch a EC2 to a point you can ssh in less than 8-10 seconds (and it takes a while to get EBS to sync the entire disk from s3). Many a time I have tried to figure a self scaling EC2 based CI system but could never get everything scaled and warm in less than 45 seconds, which is sucky when you’re waiting on a job to launch. These microvm as a service thingys do solve a problem. (You could use lambda, but that’s limited in other ways).
- thundergolfer 8mo agoModal engineer here. This isn’t correct. You can DIY this but certainly not by wrapping EC2 which is using the Nitro hypervisor and is not optimized for startup time. Nearly all players in this space use Gvisor or Firecracker.
- sebmellen 8mo agoDo you know Eric Zhang by chance? I went to school with him and saw that he was at Modal sometime back. Potentially the smartest person I’ve ever met… and a very impressive technical mind. Super impressed with what you’ve all done at Modal!
- WatchDog 8mo agoIf you achieve arbitrary code execution in the sandbox, I think you could pretty easily exfiltrate the openai key by using the openai code interpreter, and asking it to send the key to a url of your choice.
- Soerensen 8mo ago[flagged]
- rob 8mo agoI feel like this is a bot account. Or at least, everything is AI generated. No posts at all since the account was created in 2024 and now suddenly in the past 24 hours there's dozens of detailed comments that all sort of follow the same pattern/vibe.
- Soerensen 8mo agoWould love to hear your thoughts: https://news.ycombinator.com/item?id=46901199 https://news.ycombinator.com/item?id=46901199
- deleted 8mo ago[deleted]
- chacham15 8mo agoI am so confused at how this is supposed to work. If the code, running in whatever language, does any sort of transform with the key that it thinks it has, doesnt this break? E.g. OAuth 1 signatures, JWTs, HMACs... Now that I think further, doesnt this also potentially break HTTP semantics? E.g. if the key is part of the payload, then a data.replace(fake_key, real_key) can change the Content Length without actually updating the Content-Length header, right? Lastly, this still doesnt protect you from other sorts of malicious attacks (e.g. 'DROP TABLE Users;')...Right? This seems like a mitigation, but hardly enough to feel comfortable giving an LLM direct access to prod, no?
- nusl 8mo agoMy understanding is that it only surfaces the real keys when the request is actually sent under the hood, and doesn't make it available to the code itself, so that LLMs aren't able to query the key values. They have placeholder values for what seems to be obfuscation purposes, so that the LLM receives a fake value if it tries, which would help with stuff like prompt injection since that value is useless.
- deleted 8mo ago[deleted]
- _pdp_ 8mo agoVery interesting. Might copy it. We recently built our own sandbox environment backed by firecracker and go. It works great. For data residency, i.e. making sure the service is EU bound, there is basically no other way. We can move the service anywhere we can get hardware virtualisation. As for the situation with credentials, our method is to generate CLIs on the fly and expose them to the LLMs and then they can shell script them whichever way they want. The CLIs only contain scoped credentials to our API which handles oauth and other forms of authentication transparently. The agent does not need to know anything about this. All they know is that they can do $ some-skillset search-gmail-messages -q "emails from Adrian" In our own experiments we find that this approach works better and it just makes sense given most of the latest models are trained as coding assistants. They just love bash, so give them the tools.
- eis 8mo agoWhat's with the pricing of these sandbox offerings recently? I assume just trying to milk the AI trend. It's about 10x what a normal VM would cost at a more affordable hoster. So you better have it run only 10% of the time or you're just paying more for something more constrained. A full month of runtime would be about $50 bucks for a 2vCPU 1GB RAM 10GB SSD mini-VM that you can get easily for $5 elsewhere.
- freakynit 8mo agoDitto... but it's more like 30x. Mentioned the same in this comment as well: https://news.ycombinator.com/item?id=46881920 https://news.ycombinator.com/item?id=46881920
- freakynit 8mo agoIt's always the exorbitant price with such offerings. A 2 vCPU, 4GB Ram and 40GB Disk instance on Hetzner cost 4.13 USD. The same here is: $127.72 without pro plan, and $108.72 with pro plan. This means to break even, I can only use this for 4.13/127.72*730 = 23.6 hours every month, or, less than an hour daily.
- nusl 8mo agoThe article mentions that it's compute time spent deploying the code and not "wall clock" time, so I don't think it's quite this bad?
- sibellavia 8mo agoI just run a local microVM. I built a small CLI that wraps lima to make my life easier. With a few commands I have a VM running locally with all batteries included (CC/Codex, ssh, packages I need, ...). With this I'm not saying Deno or Docker sandboxes are useless.
- jrvarela56 8mo agoJust wrapped up my own module for this. Remixed my worktree workflow with a lima wrapper. I wanted to go head first to giving Claude Code full autonomy but realized capability and prevention need to go hand in hand Next step for me is creating a secrets proxy like credit card numbers are tokenized to remove risk of exfiltrating credentials. Edit: It’s nice that Deno Sandbox already does this. Will check it out.
- PeterStuer 8mo agoNever used Deno before, and searching through docs and their GitHub still leaves me with questions: Can you configure Demo Sandbox to run on a self hosted installation of Deno Deploy (deployd), or is this a SaaS only offering?
- wsgeorge 8mo agoWhat I gather from the announcement: it's part of Deno Deploy (their SaaS offering). I too would love a self-hosted version.
- arjan_sch 8mo agoThis sandboxing solution list is getting long... created https://github.com/arjan/awesome-agent-sandboxes https://github.com/arjan/awesome-agent-sandboxes, PRs welcome :)
- nihakue 8mo agoNot sure if anyone from the deno team is monitoring this forum, but I was trying to stand up a dev-base snapshot and pretty quickly ran into a wall. Is it not currently possible to create a bootable volume from the CLI? https://docs.deno.com/sandbox/volumes/#creating-a-snapshot https://docs.deno.com/sandbox/volumes/#creating-a-snapshot has an example for the js API, but the CLI equivalent isn't specifying --from and the latest verson of the deno CLI installed fresh from deno.land has no --from option. Is the CLI behind, here? Or is the argument provided some other way?
- crowlKats 8mo agocould you try again? it should be available now (no need to update deno CLI)
- nihakue 8mo agoIt's working now, thanks. While I've got your attention, it was a little bit of effort to wrap my head around the APIs when `sandbox create` uses --root AND/or --volume, `snapshot create` uses positional args <volumeIdOrSlug> <snapshotSlug>, and `volumes create` uses --from I know that each of these things is subtly different, but they're similar enough that the bootable snapshot creation workflow (which I expect is a common one) has some sharp edges, since you have to interact with all three APIs at the same time. Also, the CLI doesn't give a useful error when you try to create a snapshot from a currently attached volume. Finally, updating a snapshot is more steps than I'd ideally like. I would much rather be able to make changes in a sandbox with a snapshot root and have them persist as a new snapshot. I kind of get why this isn't currently the case, but The volume/snapshot dance feels (for my usecase) like it's missing some abstraction. That said, now that I've got a snapshot set up it's a nice experience. I've got an alias for `deno sandbox create --root dev --ssh` and I can `claude` in yolo mode without much fear. Congratulations to the team :)
- tracker1 8mo agoNot mentioned, but something I would like/expect would be to have some kind of editor integration... VS Code remote extensions, as an example even... You can be in a remote code server with your local editor and terminal tab(s) within said editor on the remote system. I realize this is using other interactions, but I'd like a bit more observability than just the isolated environment... I'm not even saying VS Code specifically, but something similar at the least.
- earlence 8mo agoFun! Our work from 10 years ago introduced the secrets protection technique being used in Deno: https://www.earlence.com/assets/papers/flowfence_sec16.pdf https://www.earlence.com/assets/papers/flowfence_sec16.pdf and fly's tokenizer. We called it "opaque computation" and it did a lot more than secrets protection.
- regisb 8mo agoIs this Extism, but running as a service? https://extism.org/ https://extism.org/ It seems to me that a key feature of Extism is host functions (which can be called from the sandbox). But maybe I'm not comparing apples to apples?
- angristan 8mo agoVery neat idea! I implemented it into my self hosted remote coding agent: https://stanislas.blog/2026/02/netclode-self-hosted-cloud-coding-agent/#secret-proxy-api-keys-never-enter-the-sandbox https://stanislas.blog/2026/02/netclode-self-hosted-cloud-co...
- swyx 8mo ago> The real key materializes only when the sandbox makes an outbound request to an approved host. If prompt-injected code tries to exfiltrate that placeholder to evil.com? Useless. pretty smart. why isn't this the norm?