Hacker News

Favorites Setup
Comment by tomrod | original | Mxc: Microsoft Execution Containers version 1.0.0
[−]tomrod · 2026-10-10 Sat 17:43 UTC · link
FANTASTIC question here. I've been locking down agents by running them as untrusted users (mostly linux here) as even docker boundaries aren't really great. Firecracker is a step in the right direction (older tech, sure, but useful). I really want a local hashicorp-like vault that I can give agents specific access permissions and it can take forever to review and manage those access boundaries.
[−]trollbridge · 2026-10-11 Sun 08:07 UTC · link
Indeed, Linux users pretty much provide enough protection and if you are willing to fiddle with SELinux you can get whatever you need.