Just ... use systemd nspwan ... stop reinventing the wheel ...
it has all the options you would ever want, and is actually deeply aware of the kernel capabilities.
every day someone comes with a new sandbox solution because they are too lazy to read one page documentation.
show comments
ulimn
I'll be sure to check this out but in the meantime, I'd like to ask: Isn't it generally a good practice to run coding agents in a VM? It provides a security boundary so that the agent is restricted to the VM.
How does this compare? I see it's an "isolated sandbox", but what exactly does that mean?
show comments
joostdevries
Interesting!
Personally I'm not eager to spend tokens on having my own harness, sandbox etc.
It's much much more feasible by spending tokens. But it does feel like a distraction and that I end up owning it. As in: a continuing distraction.
So I've been experimenting for these purposes with omnigent as a way to be less locked into a single provider and for its sandbox abstraction. And I've also tried openshell for sandboxing. Hoping those two will keep improving.
lofties
Super cool! I have a similar system that incorporates Forgejo and Pi into a system that functions a little bit more like a software team: https://bakedpi.dev
It's definitely more manual than some other solutions, but I prefer to know what my agents want to do before they do it.
It's not exactly isolated in their own VMs though. It's using Docker which isn't the safest solution out there but also... well, it is what it is.
yt1998
Maybe not a sandbox or VM I want, but a cloud computer. In this way, I don’t need to worry about storage, permissions and so on. It is for agents only.
show comments
jorl17
I've been working on a personal alternative harness to Claude Code and a very very small part of it was doing precisely this :) The project has been loads of fun.
To be fair: I support sandboxing and microVMs.
I'm pretty sure there's thousands of us, all implementing our own harnesses. The era of truly personal computing!
embik
Note: this does not appear to be a Kubernetes-based solution, the "pod" part just heavily sounds like it.
show comments
ineptech
Hi, I think I might be your target audience, I currently run pi on the server in my basement, in a minimalist docker container that gives it access to my code workspace and a config dir. Give me an idea what benefit I get on top of that by using the self-hosted pi pod?
show comments
antonyragleap
Self-hosting pi pods makes sense for us too. How are you handling network isolation between pods?
Footprint0521
Dude do you have any screenshots of the iOS app or website?
ContinuityLab
Running coding agents securely within sandboxed environments on self-hosted infrastructure hits the sweet spot for sovereign and private development workflows. Great implementation.
NicoJuicy
Did anyone run their own sandbox with Kata containers out kind ( kubernetes in docker)?
fallinditch
Interesting, thanks, will keep an eye on this
lowbloodsugar
The barrier to create this myself is so low that 1: I can do it and 2: bad actors can do it. I’d like to use a shared tool that will get iterated on, but I just don’t want to risk it at this point given I can get “good enough” doing it myself.
eranation
Daily reminder that containers are not considered a safe security boundary, and never were. If you really need to run untrusted code, use a MicroVM.
I spent lots of time on this topic, and had a similar path. Meanwhile the tool also supports a quick way to add custom or local providers to agents: https://vibepod.dev/news/vibepod-cli-0-24/
This looks very interesting, letting people run these in any box they own. I very much agree with the sentiment that there are no proper tools that let you run any coding agent without being locked to a single provider. I just want to run opencode or pi somewhere in a box without having to spin up all of them in my machine, let alone being able to trigger them from within another prouduct as a background agent.
Would pi-pod allow me to standardize pi config on a team/project level so that other people in my org can also use them on the same private infra?
Just ... use systemd nspwan ... stop reinventing the wheel ...
it has all the options you would ever want, and is actually deeply aware of the kernel capabilities.
every day someone comes with a new sandbox solution because they are too lazy to read one page documentation.
I'll be sure to check this out but in the meantime, I'd like to ask: Isn't it generally a good practice to run coding agents in a VM? It provides a security boundary so that the agent is restricted to the VM.
How does this compare? I see it's an "isolated sandbox", but what exactly does that mean?
Interesting! Personally I'm not eager to spend tokens on having my own harness, sandbox etc. It's much much more feasible by spending tokens. But it does feel like a distraction and that I end up owning it. As in: a continuing distraction.
So I've been experimenting for these purposes with omnigent as a way to be less locked into a single provider and for its sandbox abstraction. And I've also tried openshell for sandboxing. Hoping those two will keep improving.
Super cool! I have a similar system that incorporates Forgejo and Pi into a system that functions a little bit more like a software team: https://bakedpi.dev
It's definitely more manual than some other solutions, but I prefer to know what my agents want to do before they do it.
It's not exactly isolated in their own VMs though. It's using Docker which isn't the safest solution out there but also... well, it is what it is.
Maybe not a sandbox or VM I want, but a cloud computer. In this way, I don’t need to worry about storage, permissions and so on. It is for agents only.
I've been working on a personal alternative harness to Claude Code and a very very small part of it was doing precisely this :) The project has been loads of fun.
To be fair: I support sandboxing and microVMs.
I'm pretty sure there's thousands of us, all implementing our own harnesses. The era of truly personal computing!
Note: this does not appear to be a Kubernetes-based solution, the "pod" part just heavily sounds like it.
Hi, I think I might be your target audience, I currently run pi on the server in my basement, in a minimalist docker container that gives it access to my code workspace and a config dir. Give me an idea what benefit I get on top of that by using the self-hosted pi pod?
Self-hosting pi pods makes sense for us too. How are you handling network isolation between pods?
Dude do you have any screenshots of the iOS app or website?
Running coding agents securely within sandboxed environments on self-hosted infrastructure hits the sweet spot for sovereign and private development workflows. Great implementation.
Did anyone run their own sandbox with Kata containers out kind ( kubernetes in docker)?
Interesting, thanks, will keep an eye on this
The barrier to create this myself is so low that 1: I can do it and 2: bad actors can do it. I’d like to use a shared tool that will get iterated on, but I just don’t want to risk it at this point given I can get “good enough” doing it myself.
Daily reminder that containers are not considered a safe security boundary, and never were. If you really need to run untrusted code, use a MicroVM.
You should add an entry to https://pleasedonotescape.com
Is it different than running any harness in an lxc container or vm in your proxmox (or any) server?
I did that with T3 code.
Hi, creator of VibePod here (https://github.com/VibePod/vibepod-cli)
I spent lots of time on this topic, and had a similar path. Meanwhile the tool also supports a quick way to add custom or local providers to agents: https://vibepod.dev/news/vibepod-cli-0-24/
Hi there, creator of Epho here (https://epho.io).
This looks very interesting, letting people run these in any box they own. I very much agree with the sentiment that there are no proper tools that let you run any coding agent without being locked to a single provider. I just want to run opencode or pi somewhere in a box without having to spin up all of them in my machine, let alone being able to trigger them from within another prouduct as a background agent.
Would pi-pod allow me to standardize pi config on a team/project level so that other people in my org can also use them on the same private infra?