Reddit Guide: Sandbox Untrusted Vibecoded Docker Apps With a socat Gateway and Internal Network

dtdisapointingresult · reddit · 2026-10-07

A Reddit user shares a practical recipe to stop untrusted (possibly malicious or leaky) vibecoded apps from uploading your data: put the service in a docker-compose internal: true isolated network with no ports mapping, and front it with a tiny alpine/socat gateway (1.2MB RAM) that forwards inbound requests via TCP4-LISTEN:8000,fork,reuseaddr TCP4:service:8000. The service can reply but never connect out. Optional hardening includes capdrop: NETADMIN/NETRAW and no-new-privileges. The author also recommends always using compose files—asking any LLM to convert docker run commands—for repeatability and version control.

Original post →

More from coding & agent

coding & agent channel →