Maybe we should treat the agents like coworkers? I don't physically share my machine with my coworkers.
“Treat the agents like coworkers” - I’m working on this exact problem with daevix.com
Unique identity, dedicated and isolated compute, all ingress and egress monitored and audited as if I suspected the coworker (the agent) was secretly a DPRK spy.
Requiring separate machines for each agent is a nonstarter, esp. in the cloud where hardware is shared.
> I don't physically share my machine with my coworkers.
Yeah, you probably do - in fact you share physical machines with a TON of other people if you use EC2, GCE, Azure VM etc...