3 ms·
Does this support Linux yet? When I previously looked it did not (the reason being that they were already using VMs on Windows/macOS but not on Linux). Every ti
by d2p 2mo ago
Does this support Linux yet? When I previously looked it did not (the reason being that they were already using VMs on Windows/macOS but not on Linux). Every time I see an announcement I think "great, they must've added Linux now then", but the linked pages always have Windows + macOS instructions but not Linux.
All the open GH issues about supporting Linux that I subscribed to have gone unresponded to.
OpenShell looks like a good alternative, but it still has "Do not use in production" plastered all over the website, which doesn't fill me with confidence yet
- SwellJoe 2mo agoI think Linux has a better solution than Docker. I wrote a tool to use `bubblewrap` to containerize any agent (at least all the agents I've used a couple of times), and bind mount the system stuff read-only, so the agent has your "usual" environment, but they can only see the project. Their history persists (either through a bind mount or a "shadow" copy of the history that only the wrapped agent sees), the agent can still create and manage containers of its own using podman's rootless mode, etc. It's nearly instant to start because it's just a namespace (plus a few copied files for the container support and session history); no container needs to be built/fetched/updated/whatever. bubblewrap is extremely well-tested as it is used by flatpak and several other large projects, so I trust it quite a bit (more than I trust Docker). https://github.com/swelljoe/flar https://github.com/swelljoe/flar
- fg137 2mo agobubblewrap may work well for you and your specific workflows/projects but not in an enterprise setting where everyone already has a different setup on the host and needs something different inside the container. It's impossible to deploy a solution like that with bubblewrap -- configuration itself is going to be a nightmare. Which is why Docker Sandbox is aimed at teams/enterprises.
- SwellJoe 2mo agoYeah, Podman would be a better basis for that kind of use case. I'd built an early implementation of `flar` with Podman first, but it was more annoying than simply having my regular dev environment instantly available in the container. But if you need a bunch of different dev environments, instead of just your usual one, then sure, a bunch of different custom containers makes sense. But, Docker is rarely the right way to manage containers on Linux, IMHO.
- fg137 2mo ago"Docker Sandbox" is not docker. Completely different (and almost unrelated) products.
- codethief 2mo agoBubblewrap is not nearly as secure as a proper VM.
- duxuev 2mo agoI also hit the same issue recently. No Linux and no Windows on arm. AI sandboxing has a lot of options but none feel complete just yet. It's hard to commit to something, especially if reviewing tools to aide in company policies. Regardless, I'm hoping something that isn't behind a login screen is going to win out.
- cpuguy83 2mo agoI'm fairly certain that docker sandbox is based on https://github.com/containerd/nerdbox https://github.com/containerd/nerdbox which you can run on Linux.
- narinciye 2mo agoIt must be a joke that this tool is not supported on linux yet, although docker is built on top of linux containers. Shame on docker.
- codethief 2mo agoIt is supported on Linux… https://docs.docker.com/ai/sandboxes/#get-started https://docs.docker.com/ai/sandboxes/#get-started has instructions for Ubuntu.
- Narushia 2mo agoI was able to install it on Fedora from the .rpm distributed on their GitHub releases: https://github.com/docker/sbx-releases/releases https://github.com/docker/sbx-releases/releases
- kthadaka 2mo agoI work on OpenShell and we definitely see folks using it for production use cases. We're updating the language on our docs to reflect that. I'd recommend giving it a shot!
- d2p 2mo agoI have - and it's probably my preferred of all the sandboxes I've tried out. But when it comes with this disclaimer about being Alpha and not to use in production, it makes it seem like you don't think it's ready yet :) Btw - any plans for a web app to manage network approvals etc.? It feels so archiac monitoring in the console (honestly, I don't know what the obsession is with terminal UIs lately... Yes it's great that they work via SSH, but if I can SSH to a box I can also probably connect a browser to it )