Hacker News
new
top
best
ask
show
job
Docker AI agent sandboxes with HyperVisor isolation
(
www.docker.com
)
4 points
by
pploug
4 hours ago
1 comment
pploug
4 hours ago
- Each agent runs in a dedicated microVM - agents can build and run Docker containers inside the MicroVM - no access to the host Docker daemon - network isolation with allow and deny lists - available for macOs and windows (linux support coming)
brunoborges
16 minutes ago
> no access to the host Docker daemon
I believe this is likely the only downside, but for good reasons!