[HN Gopher] Building secure, scalable agent sandbox infrastructure
___________________________________________________________________
Building secure, scalable agent sandbox infrastructure
Author : gregpr07
Score : 40 points
Date : 2026-02-27 15:03 UTC (7 hours ago)
(HTM) web link (browser-use.com)
(TXT) w3m dump (browser-use.com)
| yakkomajuri wrote:
| I think this is pretty standard and similar to approaches that
| are evolving naturally (I've certainly used very similar
| patterns).
|
| I'd be pretty keen to actually hear more about the Unikraft setup
| and other deeper details about the agent sandboxes regarding the
| tradeoffs and optimizations made. All the components are there
| but has someone open-sourced a more plug-and-play setup like
| this?
| Bnjoroge wrote:
| maybe the usecase that makes unikernels alot more mainstream.
| Always found them intriguing
| eyberg wrote:
| Except this is very clearly running linux.
| lazharichir wrote:
| What can you NOT run on this, it's not very clear? Is it like
| MicroVMs on steroids where you can run more binaries than the
| strict minimum?
| jeremyjacob wrote:
| It's neat to see more projects adopting Unikernals. I've played
| around with Unikraft's Cloud offering about a year ago when it
| was CLI/API only and was impressed by the performance but found
| too many DX and polish issues to take it to production. Looks
| like they've improved a lot of that since.
| nderjung wrote:
| Howdy! We are hard at work at improving the DX, and as a result
| we've been working on a brand new CLI. We haven't made any
| announcements yet, but it's already open-source for early
| adopts if you'd like to give it a try!
|
| https://github.com/unikraft/cli
|
| Feedback is very much appreciated, we're listening! :)
| orf wrote:
| The first 3 "hardening" points are not great.
|
| Essentially it's just: remove .py files an execute del
| os.environ["SESSION_TOKEN"]? This doesn't really sound very
| secure, there are a number of ways to bypass both of these.
|
| It's just security through obscurity
| cedws wrote:
| The billion engineers building sandbox tools at the moment are
| missing the point. Sandboxing doesn't matter when the LLM is
| vulnerable to prompt injection. Every MCP server you install,
| every webpage it fetches, every file it reads is a threat. Yeah
| you can sit there and manually approve every action it takes, but
| then how is any of this useful when you have to supervise it
| constantly? Even Anthropic say that this doesn't work because
| reviewing every action leads to exhaustion and rubber stamping.
|
| The problem is not what the LLM shouldn't have access to, it's
| what it does have access to.
|
| The usefulness of LLMs is severely limited while they lack the
| ability to separate instructions and data, or as Yann LeCun said,
| predict the consequences of their actions.
| logicx24 wrote:
| Yup. I just wrote about this last week:
| https://tachyon.so/blog/sandboxes-wont-save-you
|
| Of all the problems in agent security, sandboxing solves the
| easiest problem.
___________________________________________________________________
(page generated 2026-02-27 23:00 UTC)