‹ BackHN Continuity

Thread

Show HN: Share your AI Setup, Learn from others

251 points · 140 comments · steveybrown

  1. johnsmith1840 · · focus · HN ↗
    Ec2 + codex or claude and tmux so you can move about. Control EC2 permissions outside the node. Not really much value beyond that.

    Only layer beyond this I want is the permission scoping, stronger sandboxing per session and centralized control. I have not seen a clean product around this though where I own the compute.

    1. adunsulag · · focus · HN ↗
      I've been developing my own sandboxing environment using Nvidia's Openshell.

      Works like Claude code but with stronger guarantees for me on file system and network access. Still playing around with it, but so far I've been liking the setup.

      I still run the sandbox inside a VM for now, but I feel far more comfortable in running Claude Code in unsupervised mode because I restrict the outbound network access and secrets never hit inside the sandbox.

      1. johnsmith1840 · · focus · HN ↗
        Why not a virtual machine or container? I'm playing around myself with some but can't shake that a VM is the right shape for it. That's my infra brain though.
    2. ahmed89 · · focus · HN ↗
      Is that mainly an EC2/shell problem for you or does the same session end up touching things like GitHub, AWS, MCP or other systems too?
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.