firecracker-containerd enables #containerd to manage containers as Firecracker microVMs
https://github.com/firecracker-microvm/firecracker-containerd
firecracker-containerd enables #containerd to manage containers as Firecracker microVMs
https://github.com/firecracker-microvm/firecracker-containerd
#Docker shipped a simple CLI:
docker sandbox run claude ~/project
At first glance, this looks like a glorified docker run command, but under the hood Docker is using a completely different technology:
https://rivet.dev/blog/2026-02-04-we-reverse-engineered-docker-sandbox-undocumented-microvm-api/
I started today's note yesterday, but ran out of energy.. As a bonus, I learned about the Chinese Room today so I included a link there:
des VM qui démarrent encore plus vite sous proxmox : microvm
There is no reliable and user-friendly way to isolate AI agents on macOS other than separate hardware. Every emerging sandboxing tool is a bundle of compromises that falls apart under real workflows.
I’m still exploring but what I’ve seen is that it’s either back to the Linux From Scratch times, pinky-promises built on deprecated dependencies or good ideas that only work for very simple demos.
#aiagent #security #agentsIsolation #agentsSandboxing #microVM #claude #opencode #hermesAgent
People of Proxmox, https://github.com/rcarmo/pve-microvm is now shipping, and works fine (although it still lacks a few creature comforts). #proxmox #microvm
"The infrastructure for the world needs to catch up with where AI agents are -- quite pointedly, agents break the container model." Mark Cavage, President and COO, Docker, Inc.
Now, #Docker and NanoCo (creators of NanoClaw) are working on that infrastructure with an integration between the minimalist alternative to #OpenClaw and #DockerSandboxes that further isolates #AIagents within a #microVM for safer business use. https://www.techtarget.com/searchitoperations/news/366640195/NanoClaw-AI-agents-find-a-home-in-Docker-Sandboxes
Is that art?