code-airlock: Isolating Coding Agents in Ephemeral microVMs
Trivo_ · reddit · 2026-07-05
A developer open-sourced code-airlock, a tool that runs AI coding agents inside ephemeral microVMs (Docker Sandboxes). It clones the repository within the sandbox, allowing the agent to install dependencies, build, launch containers, and modify files without accessing the host filesystem or credentials. Users then review the diff and pull the necessary changes. The design uses total environment isolation to replace fragile deny rules, currently supporting Claude Code, Codex, and OpenCode.
More from coding & agent
- Cognition's SWE-2 uses a KKT duality argument in RL to shift the effort Pareto curve — YouJiacheng · 2026-09-11
- First-ever Three.js Conference lands in Paris, with a panel on AI-shortened design workflows — OdinLovis · 2026-09-11
- Data engineering, not agent frameworks, is the real bottleneck for enterprise AI agents — dhruv2038 · 2026-09-11
- RTK Terminal Compression Cuts Tokens but Leaves Your AI Coding Bill Unchanged — Bartaseth · 2026-09-11
- GPT-6 Astra beats Factorio with enemies in 44 in-game hours at ~$4,500 API cost — liminal_bardo · 2026-09-11
- Investment Analyst Asks How to Build a Claude-Based Diligence Agent Stack — Careless_Tie2286 · 2026-09-11