Sandbox a systemd service with ProtectSystem
ProtectSystem, PrivateTmp, DynamicUser and NoNewPrivileges explained: what each directive blocks, what it breaks, and how to debug a unit that stops starting.
Filtering by topic #sandboxing · clear
ProtectSystem, PrivateTmp, DynamicUser and NoNewPrivileges explained: what each directive blocks, what it breaks, and how to debug a unit that stops starting.
Self-host OpenBot so each AI coworker gets its own container and browser. How the gateway decides every action, and what that costs you in RAM.
OneCLI hands every person a sandboxed agent and keeps the keys in one gateway. Self-host it on a VPS: Docker Compose, PostgreSQL, and real sizing numbers.
Run HRConvert2 on your own VPS so client files never touch a free converter site. Docker or Apache install, bubblewrap sandboxing, upload limits and cleanup.
Run SandBase Harness v0.3.2 on your own VPS: tagged install, agent YAML, MCP servers, sandbox modes, and pointing the Anthropic SDK at your box.
Run Rakazo on your own VPS: Node 22, pnpm, Postgres and Graphile Worker in Docker Compose, the sandbox provider choice, key handling, and honest sizing.
A coding agent runs on text an attacker can write. Map the real injection surfaces on a server, then rank the defences that actually shrink the damage.
Firecracker needs /dev/kvm, and most VPS plans never pass it through. Check yours in three commands, read the result, and know what to run when it is missing.
AI coding agents belong on a machine you can destroy. Blast radius, clean state per task, snapshots, and the VPS pattern that keeps it cheap.