Running Codex, Claude and Pi Agents Safely: gVisor Sandboxes Plus tart macOS VMs

craigbalding · x · 2026-09-18

A detailed first-hand setup for running coding agents (codex, claude, pi) safely: all harnesses run in gVisor-protected microvms where agents get root and can install anything, yet stay sandboxed. For macOS work, tart on the same Mac mini runs a Tahoe VM, accessed by the agent via a shell bridge that executes commands with tart exec. Separate seatbelt-restricted SSH access enables first-class vz testing and structured MLX experiments with no network in/out — files are downloaded via a controlled proxy in the container and streamed over SSH via HTTP CONNECT.

Related event: Running Codex/Claude Agents Safely in microVM+gVisor Sandboxes(2 posts)→

Original post →

More from coding & agent

coding & agent channel →