Reddit Guide: Sandbox Untrusted Vibecoded Docker Apps With a socat Gateway and Internal Network
dtdisapointingresult · reddit · 2026-10-07
A Reddit user shares a practical recipe to stop untrusted (possibly malicious or leaky) vibecoded apps from uploading your data: put the service in a docker-compose internal: true isolated network with no ports mapping, and front it with a tiny alpine/socat gateway (1.2MB RAM) that forwards inbound requests via TCP4-LISTEN:8000,fork,reuseaddr TCP4:service:8000. The service can reply but never connect out. Optional hardening includes capdrop: NETADMIN/NETRAW and no-new-privileges. The author also recommends always using compose files—asking any LLM to convert docker run commands—for repeatability and version control.
More from coding & agent
- Dreadnode releases ScopeBench, a benchmark for agent scope adherence in offensive security — dyn___ · 2026-10-07
- Brett Adcock shows off Handoff, a computer-use agent for shopping and travel — adcock_brett · 2026-10-07
- EvalRouter adds Traces: auto-trace every agent benchmark with a few lines of code — ycombinator · 2026-10-07
- Decisions API is out; users pitch baking it into ChatGPT for real-time gameplay — flowersslop · 2026-10-07
- Feeding years of WhatsApp and Instagram data to a personal AI agent — we93 · 2026-10-07
- AgentMail launches AgentID, a 'Sign in with Google' for AI agents — ycombinator · 2026-10-07