Containarium – self-hosted sandbox for AI agents, MCP-native
Dual MCP server architecture lets agents safely exec shell commands inside isolated LXC containers.
Locki: AI sandboxing without the taste of sand
Single VM with LXC isolation beats spawning full VMs per worktree—starts in 10 seconds.
Developers running AI coding agents on real projects
Daytona · E2B · GitHub Codespaces
So here it is. Fresh container start takes <10s. Works best with VSCode, which will neatly show changes from all worktrees in the sidebar, letting you review, edit and commit them easily. Let me know what you think!
Dual MCP server architecture lets agents safely exec shell commands inside isolated LXC containers.
direnv auto-activation with bubblewrap sandboxing isolates agents per project.
Native macOS sandboxing stops AI agents from reading your SSH keys without Docker overhead.
Eliminates permission fatigue by sandboxing agents, then diffing before apply.
802 stars proves devs want this — sandbox AI agents before they rm -rf your home directory.
Docker sandbox for Claude Code's dangerous flag when Anthropic won't let you run it bare.