code-airlock: Isolating Coding Agents in Ephemeral microVMs
Trivo_ · reddit · 2026-07-05
A developer open-sourced code-airlock, a tool that runs AI coding agents inside ephemeral microVMs (Docker Sandboxes). It clones the repository within the sandbox, allowing the agent to install dependencies, build, launch containers, and modify files without accessing the host filesystem or credentials. Users then review the diff and pull the necessary changes. The design uses total environment isolation to replace fragile deny rules, currently supporting Claude Code, Codex, and OpenCode.
More from coding & agent
- A 9B Ollama agent can run a fully local DJ radio with tools, memory, and TTS — pinku1 · 2026-07-27
- Bugbot rejects an MCP permission flag because it would break path-scoped isolation — zeeg · 2026-07-27
- One GPT-5.6 agent is guarding a Blink security system while another makes a parody rap album — repligate · 2026-07-27
- An agent got unblocked by reusing a logged-in browser, not stealth tricks — armanidev_ · 2026-07-27
- Paper argues graph topology can become the core operating system for AI agents — theomitsa · 2026-07-27
- Claude Code desktop adds UI markup feedback for smoother visual editing — EricBuess · 2026-07-27