Show HN: Pi pod – Run your pi coding agent in sandboxes on your own server
Thread
Unofficial Hacker News client; not affiliated with Y Combinator.
Show HN: Pi pod – Run your pi coding agent in sandboxes on your own server
Unofficial Hacker News client; not affiliated with Y Combinator.
eranation · · focus · HN ↗
zenoprax · · focus · HN ↗
I've been using (rootless) Podman which gives me some basic assurances that it will stay in its designated directory and not run tools on my system directly but I have no limits on the network and with an internal UID/GID of 0:0 I have not done myself any favours. This is the same level of protection one would implement to keep a poorly written bash script from wreaking havoc and that's about it.
binsquare · · focus · HN ↗
I focus on being the batteries-included approach for microVMs. So network is off by default, and you can allow specific hosts (DNS is filtered too), so an agent can reach its model API and nothing else.
And then I also put a lot of work in the jailer-style hardening around the VMM process itself: seccomp allowlist, Landlock, separate unprivileged uid per VM, and cgroup limits.
So that users have security & knobs right out of the box.
fwiw i used to operate an AWS service using firecracker.
eranation · · focus · HN ↗
zenoprax · · focus · HN ↗
gVisor felt a bit more "hacky" initially (at least compared to krun) but I will look into it a bit more as I saw someone else integrating it into their own setup.
My goal is to get 80% of the isolation for 20% inconvenience. Right now it feels like I'm getting 30-50% isolation for 10% inconvenience — I'm willing to tolerate a bit more friction if I can get a bigger jump in security.