Settings

Theme

We Sandbox AI Agents in Production

gobii.ai

3 points by ai-christianson 12 hours ago · 1 comment

Reader

ai-christiansonOP 12 hours ago

I’m Andrew I. Christianson (co-author) from Gobii. This post is the production sandbox we built for running untrusted agent workloads: per-agent isolation (gVisor), default-deny egress with proxy-only outbound, deterministic filespace sync, and audit logs for every tool call.

Happy to answer anything, especially threat model edge cases and failure modes. Code links are in the post if you want to go straight to implementation.

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection