logoalt Hacker News

Docker Sandboxes – Disposable, isolated sandboxes for AI agents

295 pointsby etoxintoday at 6:02 AM169 commentsview on HN

Comments

navigate8310today at 7:26 AM

Here's another sandbox that I found interesting: https://github.com/ashishb/amazing-sandbox

show 1 reply
AmazingTurtletoday at 7:22 AM

So it's basically a container with a fancy name, innit?

runtime_lenstoday at 6:37 AM

TO me, that's the important distinction: sandboxing limits what the agent can do but it doesn't necessarily enforce that the agent must run inside the sandbox. You need a separate control layer to enforce that boundary.

show 1 reply
quantumwoketoday at 10:24 AM

Just a small meta note: most of the comments in this thread appear to be posting their own codebase (typically AI-generated) that accomplishes the same goal. It's interesting that this problem is simultaneously in high demand and yet considered trivial enough to vibe code per-user solutions to it.

globular-toasttoday at 7:42 AM

On Linux, you can skip Docker and use bubblewrap. Some inspiration: https://blog.gpkb.org/posts/ai-agent-sandbox/

show 1 reply
weebulltoday at 8:21 AM

...or...just hear me out now...we could limit it in the harness.

Don't give it shell access, just predefined tools.

show 1 reply
cryptoztoday at 6:38 AM

The linked page implies there is no linux support, I wonder why. It's there in the docs if you hunt for it.

show 1 reply
blueaquilaetoday at 6:32 AM

Docker management will fail their tech at every opportunity.

celrenheittoday at 10:31 AM

[dead]

claud_iatoday at 10:04 AM

[flagged]

pullruntoday at 11:45 AM

[dead]

liquid_spacetoday at 11:48 AM

[dead]

beernettoday at 7:15 AM

[flagged]

Esabelletoday at 8:22 AM

[dead]

KolibriFlytoday at 7:03 AM

[dead]

songhonglei1985today at 6:37 AM

[dead]

kmehtoday at 6:33 AM

[dead]

show 2 replies