‹ BackHN Continuity

Thread

Show HN: Drop – A rootless Linux sandbox with gVisor support

193 points · 63 comments · mixedbit

  1. joserobles84 · · focus · HN ↗
    Worth being explicit about the threat model, because it decides the design. Isolating against a compromised dependency needs filesystem and egress control. Isolating against your own agent getting prompt-injected needs the credentials to never be inside the sandbox at all. Most setups I see do the first and assume it covers the second.
    1. naman_307 · · focus · HN ↗
      For agent workloads, how are you separating "where the code runs" (namespace/gVisor/microVM) from "what credentials and egress ever enter that guest"?
      1. piterrro · · focus · HN ↗

        [dead]

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.