AI Engineer

YOLO Mode, Safely: MicroVM Sandboxes for Any Agent — Rowan Christmas, Docker

Published 2026-10-03 · Duration 11:35

Summary

The talk addresses the critical security vulnerability posed by coding agents, which can access sensitive Personally Identifiable Information (PII) and internal data even when running within seemingly safe coding harnesses. The solution presented is Docker Sandboxes (sbx), which utilize microVM technology to provide 'security by design.' By running agents within an isolated virtual machine with its own kernel, sbx enforces strict controls, including default-deny networking, filesystem isolation, and secret placeholders, ensuring that agents cannot access host secrets or perform unauthorized actions.

Download summary

Key takeaways

  1. Coding Agents Pose Significant Security Risks 2:02

    Agents can find and surface sensitive data (e.g., browser history, bank account details) from the host machine, even if the user assumes the coding environment is safe. This risk is not limited to malicious intent, as agents can be prompted to research security topics and reveal PII.

  2. MicroVMs Offer Superior Security Isolation 5:47

    Unlike traditional harness-level guardrails, microVMs provide true isolation by running their own kernel and isolating the filesystem. This prevents agents from accessing host secrets or performing unauthorized network requests.

  3. sbx Provides Comprehensive Governance Controls

    Docker Sandboxes (sbx) offer granular governance, including network allow/deny rules, filesystem rules, and the ability to track agent identity and delegation chains. This allows organizations to enforce policy-based governance.

Technical details

  • Docker Sandboxes (sbx) Architecture 27s

    sbx is a microVM that spins up an isolated VM with its own kernel, filesystem isolation, and secret placeholders. It is designed to be secure by design, not just by policy warnings.

  • Network and Data Leakage Prevention 612s

    The sandbox enforces default-deny networking and blocks unauthorized network egress (e.g., attempts to look up content on the Pirate Bay) and prevents agents from sending excessive telemetry data to external services.

  • Advanced Governance Features

    Future and current controls include agent-level identity tracking, delegation chains, policy enforcement based on Cedar policies, L7 networking controls, and per-GitHub repository file system controls (allowing read/write access only to specified areas).

  • Usage and Compatibility

    The sandbox is easy to use via the `sbx run` command and is compatible with various agents, including Claude Code and Codex. It can run a full VM environment, allowing for shell access, Python jobs, or web servers.

Mentioned resources

Channel & topics

Watch on YouTube · Back to latest

This independent, AI-assisted summary is provided for commentary and informational purposes. It may contain errors or omit important context. Please watch the original video for the creator's complete presentation. Video, thumbnail, and related copyrights belong to their respective owners.