Show HN: Pi pod – Run your pi coding agent in sandboxes on your own server
Thread
Unofficial Hacker News client; not affiliated with Y Combinator.
Show HN: Pi pod – Run your pi coding agent in sandboxes on your own server
Unofficial Hacker News client; not affiliated with Y Combinator.
eranation · · focus · HN ↗
zenoprax · · focus · HN ↗
I've been using (rootless) Podman which gives me some basic assurances that it will stay in its designated directory and not run tools on my system directly but I have no limits on the network and with an internal UID/GID of 0:0 I have not done myself any favours. This is the same level of protection one would implement to keep a poorly written bash script from wreaking havoc and that's about it.
eranation · · focus · HN ↗
zenoprax · · focus · HN ↗
gVisor felt a bit more "hacky" initially (at least compared to krun) but I will look into it a bit more as I saw someone else integrating it into their own setup.
My goal is to get 80% of the isolation for 20% inconvenience. Right now it feels like I'm getting 30-50% isolation for 10% inconvenience — I'm willing to tolerate a bit more friction if I can get a bigger jump in security.