Redditor isolates AI agent in a VM with VLAN and OPNsense firewall, reviews changes via Gitea PRs

Awkward_Education704 · reddit · 2026-09-21

A Reddit user shares a security-first setup for running AI agents locally: since he doesn't trust an agent loose on his machine, he runs it inside a Linux VM on the free VMware Workstation Pro, on a VLAN fully cut off from the host network, with a separate OPNsense VM as the firewall.

The agent can only make changes through pull requests on a self-hosted Gitea instance, adding a manual review gate. He asks the community whether this is over-paranoid and how others sandbox their agents.

Original post →

More from coding & agent

coding & agent channel →