's Avatar

@89luca89

27
Followers
46
Following
13
Posts
15.12.2024
Joined
Posts Following

Latest posts by @89luca89

There is a separation of concern:
Agent can access its own secret (api key) but does not have egress outside a restrict api pool.
Sidecar can access its own secret but can only reach registries
Nested containers have open egress. But cannot access secrets from sidecar and agent containers.
2/2

04.03.2026 06:14 👍 1 🔁 0 💬 1 📌 0

Yes the agent container itself by default has a deny-all/allow-some, it can obviously reach api endpoints for the service. That is also configurable too.
1/2

04.03.2026 06:13 👍 0 🔁 0 💬 1 📌 0

So, right now agent itself has only access to api endpoints. Nested containers have open egress, but they don't have access to any secret. You can have a deny-all network for nested containers too, network is fully customizable from outside the sandbox

04.03.2026 05:49 👍 0 🔁 0 💬 1 📌 0
Preview
GitHub - 89luca89/clampdown: Run AI coding agents in hardened container sandboxes. Run AI coding agents in hardened container sandboxes. - 89luca89/clampdown

Happy to announce my new project: Clampdown!

Run AI coding agents in hardened container sandboxes, with Landlock FS isolation, iptables egress control, and more.
Keep your project tidy and your host safe!

github.com/89luca89/cla...

#linux #ai #agent #security

03.03.2026 22:36 👍 0 🔁 0 💬 1 📌 1
Preview
FOSDEM 2026 - Reproducible XFS Filesystems - Populating Images Without Mounting

The recording of my #fosdem talk is now available!

fosdem.org/2026/schedul...

#linux #filesystem #xfs #reproducible #builds

03.02.2026 22:16 👍 3 🔁 2 💬 0 📌 0

But you are too!

03.02.2026 17:10 👍 2 🔁 0 💬 1 📌 0
Preview
FOSDEM 2026 - Reproducible XFS Filesystems - Populating Images Without Mounting

Excited to announce I'll be speaking at FOSDEM 2026!
I'll be in the Kernel devroom talking about reproducible XFS filesystems — how to populate images directly from a directory tree at creation time, no mounting required.

fosdem.org/2026/schedul...

#FOSDEM #FOSDEM2026 #XFS #Linux #Kernel

19.12.2025 20:18 👍 2 🔁 0 💬 0 📌 1
Preview
Release 1.8.2.0 · 89luca89/distrobox After some time a much needed release! lots of fixes and polishing all over the place! Thanks @dottorblaster for stepping in and welcome him as a new part of the maintainer team! And thank you to 2...

Distrobox 1.8.2.0 released! Tons of fixes and polish, new distros, 20 new contributors & a new co-maintainer @dottorblaster #linux #containers #distrobox #opensource

Check it out: github.com/89luca89/dis...

28.10.2025 09:33 👍 1 🔁 0 💬 0 📌 0
Preview
Distrobox Chat You can view and join @distrobox_chat_new right away.

Hi all
due to problems with the Telegram account I have to create a new group for #Distrobox

The matrix group remains unchanged, and it will be bridged with the telegram one.

I urge you to *leave the old group* and join the new one:

t.me/distrobox_chat_new

26.10.2025 09:24 👍 0 🔁 0 💬 0 📌 0
Preview
DistroShelf la gestione di Distrobox da GUI in Linux DistroShelf è una soluzione pratica per gestire container Linux senza la complessità di configurazioni avanzate

DistroShelf la gestione di Distrobox da GUI in Linux

DistroShelf è una soluzione pratica per gestire container Linux senza la complessità di configurazioni avanzate

29.04.2025 18:39 👍 1 🔁 1 💬 0 📌 0
Preview
FOSDEM 2025 - Implementing a rootless container manager from scratch

Hi! In case you missed, my #FOSDEM talk about creating a #rootless #container manager from scratch is available!

We'll talk about the basic principles to build your own container manager, using #lilipod as an example project:

fosdem.org/2025/schedul...

#opensource #linux #container #distrobox

09.02.2025 20:41 👍 1 🔁 0 💬 0 📌 0
Post image

Beta version of Red Hat Enterprise Linux 10 (RHEL10) running inside of Podman with Distrobox on a Fedora Linux 41 system.

When you've installed subscription-manager on the base (in this case Fedora) system and activated the system, then the entire RHEL […]

[Original post on burningboard.net]

25.01.2025 12:09 👍 2 🔁 1 💬 0 📌 0
Preview
Release 1.8.1.2 · 89luca89/distrobox Nvidia hotfix release: init: improve nvidia symlinks resolution. Fix #1668 init: mask systemd-resolved in case we use host's network Thanks everyone for reporting problems! Full Changelog: 1.8.1.1....

#nvidia hotfix release for #distrobox 1.8.1.2:

init: improve #nvidia symlinks resolution. Fix #1668
init: mask systemd-resolved in case we use host's network

Thanks everyone for reporting problems!

github.com/89luca89/dis...

#podman #docker #linux #opensource #containers

25.01.2025 14:21 👍 0 🔁 0 💬 0 📌 0
Preview
nvidia-container-toolkit/internal/discover/graphics.go at main · NVIDIA/nvidia-container-toolkit Build and run containers leveraging NVIDIA GPUs. Contribute to NVIDIA/nvidia-container-toolkit development by creating an account on GitHub.

Hot bugfix #distrobox #release!

improve nvidia file integration, adopt a more solid approach from: github.com/NVIDIA/nvidi...
solve a problem with distrobox-export

github.com/89luca89/dis...

23.01.2025 08:09 👍 0 🔁 0 💬 0 📌 0
Preview
Release 1.8.1 · 89luca89/distrobox Another bugfix release! 🎉 Improvements and refinements all over the place, in pkg manager handling, in nvidia integration and in performance department! 💪 What's Changed assemble: add clone in dis...

Hi All!
New release of #distrobox is on the way!

1.8.1 brings lots of improvements and refinements all over the place, in pkg manager handling, nvidia integration and in performance department! 💪

Also many many new contributors! 🎉

Check it out! github.com/89luca89/dis...

19.01.2025 16:16 👍 2 🔁 1 💬 0 📌 0

And for the ones using #Distrobox on #Aeondesktop or #Bluefin (or anywhere else), here's a small new year gift:
github.com/nunix/config...

@89luca89.bsky.social @castrojo.bsky.social assemble 😇

The appsvenger Corsair 🏴‍☠️

06.01.2025 08:18 👍 3 🔁 2 💬 1 📌 0
openSUSE Conference 2024 - Developing on Aeon with Distrobox
openSUSE Conference 2024 - Developing on Aeon with Distrobox YouTube video by openSUSE

Adapting to Atomic systems like Aeon? Explore how #Distrobox can transform your development workflow. #openSUSE #DevOps #Containers youtu.be/24F3uFMrDtE?...

18.12.2024 07:48 👍 11 🔁 2 💬 0 📌 0