Running coding agents safely: microVM/gVisor sandbox + tart macOS VMs in practice
craigbalding · x · 2026-09-18
A practitioner shares his working setup for running codex/claude/pi coding agents inside microVM/gVisor containers with root access but constrained by a controlled proxy. For macOS needs: tart runs a macOS Tahoe VM on the same Mac mini, the agent drives it via a shell bridge (folder drop + tart exec) for xcode builds; a seatbelt-restricted, network-isolated shell path enables vz testing and MLX experiments, with files streamed in via ssh over HTTP CONNECT.
Related event: Running Codex/Claude Agents Safely in microVM+gVisor Sandboxes(2 posts)→
More from coding & agent
- Open-source repo collects the best JEV use cases in one place, PRs welcome — matchaman11 · 2026-09-18
- User: Astra in Codex is unusable even on a 20x subscription — OpenAI should copy Anthropic's usage-quota approach — CtrlAltDwayne · 2026-09-18
- Controlling the iOS simulator with Jev + AXe: ultra fast at a fraction of LLM cost — stefanjblos · 2026-09-18
- Jev reviews PRs at $0.00007 each, ~200x cheaper than Claude Opus with 14 typed checks — stefanjblos · 2026-09-18
- Developer who abandoned notebooks for agents says Codex made them fun again — intellectronica · 2026-09-18
- ScrapeGraphAI: open-source library that scrapes any site with one plain-English prompt — thisdudelikesAI · 2026-09-18