2 ms·
I hand rolled a sandbox with credential injections on call out using WSL and mitm and Windows credential manager. The only credential I had to have in the box w
by DubiousPusher 13d ago
I hand rolled a sandbox with credential injections on call out using WSL and mitm and Windows credential manager. The only credential I had to have in the box was a fine grained PAT with copilot response. I used some hacky git push/pull to move work in and out of the sandbox. For collaborative UX review I would switch the agent to limited perms and CDP back to my host browser.
Recently I moved to Docker Sandboxes. This removed most of what I was having to hand roll. Though I still own the renewal for short lived tokens. The git setup in docker sandbox is especially nice. The host is served as a remote 'host' in the sandbox and it can read but not write the host's origin.
On the host, each sandbox got is reachable as sandbox-[name].
https://www.docker.com/products/docker-sandboxes/ https://www.docker.com/products/docker-sandboxes/
- coder-pm 12d agoNice setup, I'm curious about the PAT. Even fine-grained permissions are working till the expiration so if the box will die someone has it for the whole time. Did you rotate it per session or it was on default expiration time?