3 ms·
Run coding agents in a docker container with limited permissions. FWIW, I run it with --cap-drop=ALL --pids-limit=4096 --runtime=runsc
by AlexCoventry 4mo ago
Run coding agents in a docker container with limited permissions. FWIW, I run it with
--cap-drop=ALL
--pids-limit=4096
--runtime=runsc
- chrisweekly 4mo agoOr put it in a microvm using eg smolmachines.
- causal 4mo agoI've never used smolmachines but I'm curious; why this over a container?
- apitman 4mo agoContainers are not security boundaries. Vulnerabilities in containers are much more common than in VMs.
- chrisweekly 4mo agoKernel-level isolation is a significant security differentiator, for starters. https://github.com/smol-machines/smolvm#comparison https://github.com/smol-machines/smolvm#comparison shows a good comparison table.
- bionade24 4mo agoUsing runsc instead of runsc means that there's a hypervisor layer (gvisor, probably) in-between the kernel and the container userland
- flexagoon 4mo agoIf you're on Linux, you can also easily run it in bwrap to properly sandbox without running a full container
- worik 4mo agoI run mine on their own machine, without root access. Currently a Raspberry Pi 5 I am very pleased with it. My Idiot Savant Pet