Guide
Coding agents are most useful when they can act without asking, and that is exactly when you need a boundary around them. A good sandbox limits four things: the files the agent can touch, the credentials it can use, the network it can reach, and how hard its mistakes are to undo.
Get started| What it stops | What it does not | |
|---|---|---|
| A separate OS user | Reading your home directory and keys | Anything that user can still reach on the machine and network |
| A container | Most access to the host’s files and processes | Kernel exploits: containers share the host kernel |
| A virtual machine | Access to the host, through a separate kernel | Whatever you put inside it, or let it reach on the network |
| A hosted workspace | Access to your machine entirely | What you grant it: the repository, the tokens you connect |
Only the tokens the task needs, scoped to one repository and short-lived. Never mount your personal SSH keys or cloud credentials into the sandbox.
Agents need the public internet for packages, git and model APIs. They rarely need your private network: block private address ranges where you can.
Run the agent on a branch in a disposable checkout. If it breaks something, discard the checkout instead of repairing it.
Isolation limits the damage; review stops bad changes from shipping. Gate merges on a diff you, or a second agent, have read.
Each workspace runs in its own Kata Container, a virtual machine with its own guest kernel. Agents run as a non-root user with Linux capabilities dropped, default-deny network policies block the private address space, and credentials are delivered per session and never shared with other workspaces. Every lane is a separate git clone on its own branch, so throwing work away is one click. That is why agents there run without permission prompts.
It is a big improvement over running on your laptop, especially with no host directories mounted and no credentials passed in. For code you do not trust at all, prefer a virtual machine, because a container shares the host kernel.
Sign in with GitHub, open a workspace on your repository, and put your first agent to work in a few minutes.
Get started