proomt

Search

Search posts, papers, and topics

All posts

Lobsters

Sandboxing with minimal effort

Related reading

  1. Trust Docker for the agents you don’t

    Docker Cloud Sandboxes provide isolated microVM environments for running AI agents, enabling developers to start tasks locally and seamlessly move them to Docker-managed cloud compute. This offers enhanced security through containment and control, allowing agents to run longer tasks with explicit access policies.

    Dockerdocker.com9 min
  2. For SeaVerse, GKE Agent Sandbox reduces infrastructure costs by 60%

    SeaVerse uses GKE Agent Sandbox (Kata Containers + Cloudhypervisor or gVisor) to run isolated AI sandboxes at scale, achieving 300 allocations / s per cluster (90% ≤ 200 ms) and cutting infrastructure spend by up to 60% via flexible VM sizing and per‑sandbox persistent storage, while gaining native Cloud observability.

    Google Cloud Bloggoogle.com5 min
  3. Show HN: Drop – a rootless Linux sandbox with gVisor support

    Drop is a root‑less Linux sandbox that runs programs in a user‑namespace with isolated mount, network, IPC and cgroup namespaces. It reuses the host distribution’s binaries (no Docker image), provides disposable per‑project home directories, and is configured via a high‑level TOML file. An optional gVisor integration adds a user‑space kernel layer for extra kernel‑attack surface reduction. Use ca…

    Hacker News front pagedroprun.sh1 minreleaseHN18863