There is a separation of concern:
Agent can access its own secret (api key) but does not have egress outside a restrict api pool.
Sidecar can access its own secret but can only reach registries
Nested containers have open egress. But cannot access secrets from sidecar and agent containers.
2/2
04.03.2026 06:14
👍 1
🔁 0
💬 1
📌 0
Yes the agent container itself by default has a deny-all/allow-some, it can obviously reach api endpoints for the service. That is also configurable too.
1/2
04.03.2026 06:13
👍 0
🔁 0
💬 1
📌 0
So, right now agent itself has only access to api endpoints. Nested containers have open egress, but they don't have access to any secret. You can have a deny-all network for nested containers too, network is fully customizable from outside the sandbox
04.03.2026 05:49
👍 0
🔁 0
💬 1
📌 0
GitHub - 89luca89/clampdown: Run AI coding agents in hardened container sandboxes.
Run AI coding agents in hardened container sandboxes. - 89luca89/clampdown
Happy to announce my new project: Clampdown!
Run AI coding agents in hardened container sandboxes, with Landlock FS isolation, iptables egress control, and more.
Keep your project tidy and your host safe!
github.com/89luca89/cla...
#linux #ai #agent #security
03.03.2026 22:36
👍 0
🔁 0
💬 1
📌 1
FOSDEM 2026 - Reproducible XFS Filesystems - Populating Images Without Mounting
The recording of my #fosdem talk is now available!
fosdem.org/2026/schedul...
#linux #filesystem #xfs #reproducible #builds
03.02.2026 22:16
👍 3
🔁 2
💬 0
📌 0
But you are too!
03.02.2026 17:10
👍 2
🔁 0
💬 1
📌 0
FOSDEM 2026 - Reproducible XFS Filesystems - Populating Images Without Mounting
Excited to announce I'll be speaking at FOSDEM 2026!
I'll be in the Kernel devroom talking about reproducible XFS filesystems — how to populate images directly from a directory tree at creation time, no mounting required.
fosdem.org/2026/schedul...
#FOSDEM #FOSDEM2026 #XFS #Linux #Kernel
19.12.2025 20:18
👍 2
🔁 0
💬 0
📌 1
Distrobox Chat
You can view and join @distrobox_chat_new right away.
Hi all
due to problems with the Telegram account I have to create a new group for #Distrobox
The matrix group remains unchanged, and it will be bridged with the telegram one.
I urge you to *leave the old group* and join the new one:
t.me/distrobox_chat_new
26.10.2025 09:24
👍 0
🔁 0
💬 0
📌 0
DistroShelf la gestione di Distrobox da GUI in Linux
DistroShelf è una soluzione pratica per gestire container Linux senza la complessità di configurazioni avanzate
DistroShelf la gestione di Distrobox da GUI in Linux
DistroShelf è una soluzione pratica per gestire container Linux senza la complessità di configurazioni avanzate
29.04.2025 18:39
👍 1
🔁 1
💬 0
📌 0
FOSDEM 2025 - Implementing a rootless container manager from scratch
Hi! In case you missed, my #FOSDEM talk about creating a #rootless #container manager from scratch is available!
We'll talk about the basic principles to build your own container manager, using #lilipod as an example project:
fosdem.org/2025/schedul...
#opensource #linux #container #distrobox
09.02.2025 20:41
👍 1
🔁 0
💬 0
📌 0
Beta version of Red Hat Enterprise Linux 10 (RHEL10) running inside of Podman with Distrobox on a Fedora Linux 41 system.
When you've installed subscription-manager on the base (in this case Fedora) system and activated the system, then the entire RHEL […]
[Original post on burningboard.net]
25.01.2025 12:09
👍 2
🔁 1
💬 0
📌 0
Release 1.8.1.2 · 89luca89/distrobox
Nvidia hotfix release:
init: improve nvidia symlinks resolution. Fix #1668
init: mask systemd-resolved in case we use host's network
Thanks everyone for reporting problems!
Full Changelog: 1.8.1.1....
#nvidia hotfix release for #distrobox 1.8.1.2:
init: improve #nvidia symlinks resolution. Fix #1668
init: mask systemd-resolved in case we use host's network
Thanks everyone for reporting problems!
github.com/89luca89/dis...
#podman #docker #linux #opensource #containers
25.01.2025 14:21
👍 0
🔁 0
💬 0
📌 0
Release 1.8.1 · 89luca89/distrobox
Another bugfix release! 🎉
Improvements and refinements all over the place, in pkg manager handling, in nvidia integration and in performance department! 💪
What's Changed
assemble: add clone in dis...
Hi All!
New release of #distrobox is on the way!
1.8.1 brings lots of improvements and refinements all over the place, in pkg manager handling, nvidia integration and in performance department! 💪
Also many many new contributors! 🎉
Check it out! github.com/89luca89/dis...
19.01.2025 16:16
👍 2
🔁 1
💬 0
📌 0
And for the ones using #Distrobox on #Aeondesktop or #Bluefin (or anywhere else), here's a small new year gift:
github.com/nunix/config...
@89luca89.bsky.social @castrojo.bsky.social assemble 😇
The appsvenger Corsair 🏴☠️
06.01.2025 08:18
👍 3
🔁 2
💬 1
📌 0
openSUSE Conference 2024 - Developing on Aeon with Distrobox
YouTube video by openSUSE
Adapting to Atomic systems like Aeon? Explore how #Distrobox can transform your development workflow. #openSUSE #DevOps #Containers youtu.be/24F3uFMrDtE?...
18.12.2024 07:48
👍 11
🔁 2
💬 0
📌 0