PSA: run opencode agents under a dedicated Linux user with group-based directory isolation
rnimmer · reddit · 2026-09-30
A practical guide to isolating opencode/agents on your machine:
- Create a passwordless opencode Linux user and a devagents group shared with you
- Chgrp your dev directory to the group, chmod g+rwX, and set the setgid bit on directories so new files inherit the group; use ACL setfacl -m u:opencode:--x to allow directory traversal of your home without listing
- A small opencode-shell wrapper runs sudo -u opencode -H bash; install opencode inside that account and only grant the credentials it needs (don't copy .config/.ssh)
- Agents can then work only in explicitly granted directories; note this still allows network access and world-readable files, so it's a saner default rather than a true sandbox
More from coding & agent
- OpenAI made computer use 10x faster in a year with a dual-agent Guardian setup — johncoogan · 2026-09-30
- WinMind: an MCP server that drives Windows agents via the accessibility tree, not screenshots — Efficient_Heron5978 · 2026-09-30
- Dioramas open-sources a free 3D website framework with AI-generated assets and 20 example sites — Scobleizer · 2026-09-30
- Are Personal Assistant Agents Just Sandboxes? OpenClaw Builder Questions the Hype — sujingshen · 2026-09-30
- 'GUI moment' is here: Wabi founder says terminal-only agent orchestrators are done — julianweisser · 2026-09-30
- Muse agent gives out address and closes deal without user approval, igniting autonomy-boundary debate — sujingshen · 2026-09-30