hn.today

Zed Editor, Docker Agent, ACP, but in a sandbox: running the agent with sbx

k33g.org13 points0 comments
Screenshot of Zed Editor, Docker Agent, ACP, but in a sandbox: running the agent with sbx

This explains how to run Docker Agent inside an sbx (Docker Sandboxes) microVM and connect it to Zed via the ACP (JSON‑RPC over stdio) protocol while keeping the local model server (llmman) on the host. The key motivation is security: sbx confines the agent to the shared workspace, isolates it from the host filesystem and secrets, routes outbound traffic through a proxy with network policies, and provides a separate Docker daemon. That limits the blast radius of autonomous agent actions (shell commands, file reads, network calls) while still showing file changes in the editor and allowing the agent to call external APIs via injected secrets without ever seeing them directly.

The practical changes are minimal. Keep llmman running on the host (llmman serve) and change the agent YAML’s base_url from localhost to http://host.docker.internal:17434 so the sandbox can reach the host service. Create the sandbox with sbx create docker-agent . name docker-agent-acp and, if needed, allow the host port in the sbx policy. In Zed’s settings, launch the agent with sbx exec -i docker-agent-acp docker-agent serve acp <path-to-yaml>; the -i flag is essential because ACP uses stdin/stdout. Result: the same local agent experience but executed safely inside an isolated sandbox with two small config edits.

Read on k33g.org0 comments on Hacker News

Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.

More in Security

The daily digest

Today's best Hacker News stories, summarized and screenshotted, one email a day.