upvote
FANTASTIC question here. I've been locking down agents by running them as untrusted users (mostly linux here) as even docker boundaries aren't really great. Firecracker is a step in the right direction (older tech, sure, but useful). I really want a local hashicorp-like vault that I can give agents specific access permissions and it can take forever to review and manage those access boundaries.
reply
I guess buy a Mac then.
reply
There are many things that would be good to lock down. NPM install comes to mind.

I wonder if I will be able to integrate this with dev containers somehow, so my dev container could run in stricter isolation.

reply
I've seen folks using the VS Code workspaces concept for this. It's a bit limited but a good step in the direction I prefer.
reply
VS Code workspaces doesn't seem to offer any protection:

https://code.visualstudio.com/docs/editing/workspaces/worksp...

Maybe you use GitHub codespaces?

reply
No, I did mean VS Code workspaces. Now I'm going to go down this rabbit hole to better understand the boundary limits :)
reply
I did some reading of the docs and can't see anything in VS Code workspaces that would help.
reply