Redditor isolates AI agent in a VM with VLAN and OPNsense firewall, reviews changes via Gitea PRs
Awkward_Education704 · reddit · 2026-09-21
A Reddit user shares a security-first setup for running AI agents locally: since he doesn't trust an agent loose on his machine, he runs it inside a Linux VM on the free VMware Workstation Pro, on a VLAN fully cut off from the host network, with a separate OPNsense VM as the firewall.
The agent can only make changes through pull requests on a self-hosted Gitea instance, adding a manual review gate. He asks the community whether this is over-paranoid and how others sandbox their agents.
More from coding & agent
- KDE Drafts AI Policy: Use LLMs, But Don't Tell Anyone — carsonfarmer · 2026-09-21
- 9 practical Jev API recipes: browser agent flies through Google Flights in 7 seconds — alexcovo_eth · 2026-09-21
- GitHub's 17.4k-Star stop-slop Teaches LLMs to Strip AI Writing Tells — tom_doerr · 2026-09-21
- Solo attorney running agent fleet: evidence gates to stop coding-agent regression loops — Specialist_Call_1257 · 2026-09-21
- Code review classification saves 122k tokens, author says even 10% savings is a free win — draginol · 2026-09-21
- Microsoft open-sources IQ Solution Accelerator unifying enterprise data, knowledge and decisions — adnan_hashmi · 2026-09-21