Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This is why I started https://nono.sh , agents start with zero trust in a kernel isolated sandbox.


I had O4.5 build me this project to throw on a VPS or server, works well for me:

https://github.com/jgbrwn/vibebin


What's the benefit over using docker?


Can't speak for the benefits of https://nono.sh/ since I haven't used it, but a downside of using docker for this is that it gets complicated if you want the agent to be allowed to do docker stuff without giving it dangerous permissions. I have a Vagrant setup inspired by this blogpost https://blog.emilburzo.com/2026/01/running-claude-code-dange..., but a bug in VirtualBox is making one core run at 100% the entire time so I haven't used it much.


> but a bug in VirtualBox is making one core run at 100% the entire time

FYI they fixed it in 7.2.6: https://github.com/VirtualBox/virtualbox/issues/356#issuecom...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: