firecracker-containerd enables #containerd to manage containers as Firecracker microVMs

https://github.com/firecracker-microvm/firecracker-containerd

#linux #containers #microvm

GitHub - firecracker-microvm/firecracker-containerd: firecracker-containerd enables containerd to manage containers as Firecracker microVMs

firecracker-containerd enables containerd to manage containers as Firecracker microVMs - firecracker-microvm/firecracker-containerd

GitHub

#Docker shipped a simple CLI:

docker sandbox run claude ~/project

At first glance, this looks like a glorified docker run command, but under the hood Docker is using a completely different technology:

#microvm

https://rivet.dev/blog/2026-02-04-we-reverse-engineered-docker-sandbox-undocumented-microvm-api/

We Reverse-Engineered Docker Sandbox's Undocumented MicroVM API - Rivet

Docker ships with an undocumented API for spawning isolated microVMs. Here's how to use it for more than just AI agents.

Rivet
We Reverse-Engineered Docker Sandbox's Undocumented MicroVM API - Rivet

Docker ships with an undocumented API for spawning isolated microVMs. Here's how to use it for more than just AI agents.

Rivet

I started today's note yesterday, but ran out of energy.. As a bonus, I learned about the Chinese Room today so I included a link there:

https://divisionbyzero.net/notes/2026-05-06/

#fuck_ai #security #containers #microvm

Daily Note - Wednesday, May 6th, 2026 - divisonbyzero.net

i wear this chaos well

divisonbyzero.net
microvm

des VM qui démarrent encore plus vite sous proxmox : microvm

https://github.com/rcarmo/pve-microvm

#microvm #proxmox

GitHub - rcarmo/pve-microvm: Firecracker-like microVMs for Proxmox VE — KVM isolation, under 200 ms boot.

Firecracker-like microVMs for Proxmox VE — KVM isolation, under 200 ms boot. - rcarmo/pve-microvm

GitHub

There is no reliable and user-friendly way to isolate AI agents on macOS other than separate hardware. Every emerging sandboxing tool is a bundle of compromises that falls apart under real workflows.

I’m still exploring but what I’ve seen is that it’s either back to the Linux From Scratch times, pinky-promises built on deprecated dependencies or good ideas that only work for very simple demos.

#aiagent #security #agentsIsolation #agentsSandboxing #microVM #claude #opencode #hermesAgent

People of Proxmox, https://github.com/rcarmo/pve-microvm is now shipping, and works fine (although it still lacks a few creature comforts). #proxmox #microvm

https://news.ycombinator.com/item?id=47818220

"The infrastructure for the world needs to catch up with where AI agents are -- quite pointedly, agents break the container model." Mark Cavage, President and COO, Docker, Inc.

Now, #Docker and NanoCo (creators of NanoClaw) are working on that infrastructure with an integration between the minimalist alternative to #OpenClaw and #DockerSandboxes that further isolates #AIagents within a #microVM for safer business use. https://www.techtarget.com/searchitoperations/news/366640195/NanoClaw-AI-agents-find-a-home-in-Docker-Sandboxes

NanoClaw AI agents find a home in Docker Sandboxes

The minimal, containerized alternative to the viral OpenClaw gets an added dose of isolation from Docker microVMs, as 'AI claws' proliferate.

TechTarget

Is that art?

#microvm