4 ms·
How are you sandboxing your Pi coding harness? Directly only mounting certain folders, using capabilities to kill the network and not giving it all your shell e
by robertlagrant 4mo ago
How are you sandboxing your Pi coding harness? Directly only mounting certain folders, using capabilities to kill the network and not giving it all your shell env vars, that sort of thing? Or do you use a tool?
- throw10920 4mo agoAnd, is the sandboxing for security (avoid RCE on the host) or merely guardrails for the models? I've wanted the latter quite a bit for Pi, because weaker models like Deepseek V4 have extreme issues with obeying prompts (e.g. I'll instruct it to find a bug but not fix it, and it'll "helpfully" try to fix it anyway), so having a "read-only mode" actually backed by the OS would be very useful.
- SeriousM 4mo agoHaha, yes! Last time I asked it for options how to tackle a task and only do the research without touching any code. With xhigh rasoning, it echoed the options that many times until it was convinced that option A is the better choice and started implementing it.
- fidelramos 4mo agoI'm using firejail to sandbox Opencode, for security and to keep the agents from personal data. I documented it in my blog [1]. [1] https://blog.fidelramos.net/software/how-i-sandbox-ai-agents#how-i-sandbox-ai-agents https://blog.fidelramos.net/software/how-i-sandbox-ai-agents...
- robertlagrant 3mo agoThank you - great blog post.