Running coding agents safely: microVM/gVisor sandbox + tart macOS VMs in practice

craigbalding · x · 2026-09-18

A practitioner shares his working setup for running codex/claude/pi coding agents inside microVM/gVisor containers with root access but constrained by a controlled proxy. For macOS needs: tart runs a macOS Tahoe VM on the same Mac mini, the agent drives it via a shell bridge (folder drop + tart exec) for xcode builds; a seatbelt-restricted, network-isolated shell path enables vz testing and MLX experiments, with files streamed in via ssh over HTTP CONNECT.

Related event: Running Codex/Claude Agents Safely in microVM+gVisor Sandboxes(2 posts)→

Original post →

More from coding & agent

coding & agent channel →