Replies: 1 comment
|
Instead of relying on heavy Docker daemons (ContainerCodeExecutor) or completely un-isolated UnsafeLocalCodeExecutor, veltra-agent (v0.4.0) provides sub-60ms OS-edge sandboxing. It uses Linux Landlock LSM & macOS Seatbelt (PR_SET_NO_NEW_PRIVS) to restrict filesystem, socket writes, and subshells at the process boundary without container setup. Check out pip install veltra-agent or [github.com/Jayanthpulisheri/veltra-ai-engine] |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Problem
ADK doesn't have many sandboxed local alternatives for code execution. The only option is
ContainerCodeExecutorwhich relies on Docker. Beyond requiring a Docker daemon to be available, it can also add complexity in production, especially when the app or agent is already running inside a container. Nested containers (DinD) require elevated privileges, which can compromise the isolation and defeat the very purpose of sandboxing.Proposed solution
The solution I'm proposing is based on Vpod, an open-source project I maintain. A
vpodis a tiny Linux sandbox that runs inside WebAssembly for untrusted processes. It uses snapshots with preinstalled libraries to start fast and avoid setup complexity.Here's an example of what the code execution inside a
VpodCodeExecutorcould look like:Under the hood, it's a thin wrapper over Vpod's Python SDK:
Sandboxes are highly portable and work on any OS or environment. They also can be suspended and resumed on disk without any background process or daemon.
Trade-offs, up front
Vpodis based on RISC‑V emulated in WASM and doesn't benefit from hardware acceleration, so CPU‑heavy workloads might run slower than native. It's mainly aimed at safely running typical agent-generated code, not at max-throughput compute.I'm curious whether anyone here has run into this with Docker and
ContainerCodeExecutorin production. If so, I'd love to hear how you worked around it.Here's more information about Vpod:
pip install vpodAll reactions