Whilst it is safer to run inside a Vm/container, it doesn't make it safe.
Yes, having your entire filesystem deleted is much less likely now (bonus points for zfs snapshots of the image for each operation) Your context is still vulnerable, as anything the VM has access too.
metachris 10 hours ago [-]
Good point! Running in isolation does reduce the amount of sensitive things an LLM has access to though, which typically can be quite a lot (SSH keys, Cloud credentials, communication tools, etc.)
dk8996 1 days ago [-]
Interesting. Im looking for solution to run multiple OpenClaw bots in the cloud, with security and isolation in mind.
ews 1 days ago [-]
I ended up using guix shells (container mode) for my agents and sharing just the directories they need
nkko 13 hours ago [-]
For no special reason, beside I could, I’ve slop coded this AI agents ephemeral VM orchestrator which I use inside any agent to manipulate and maintain my coding VMs on Proxmox. Probably it could make sense to simplify it further and move from Proxmox to something like this. Link: https://github.com/nibzard/agentlab
xyzsparetimexyz 13 hours ago [-]
Oh my GOD just STOP with the awful kitschy sepia toned slop images for blog posts like these. I can't take it any more!!!
10 hours ago [-]
metachris 9 hours ago [-]
Gave your comment a bit more thought and I kind of agree, and removed the image! Thanks for your feedback.
nsonha 10 hours ago [-]
The comparison between these and lima makes me think that it's AI generated
metachris 10 hours ago [-]
I've had LLMs assist me in putting together the comparison. I did edit it, and found the comparison good and wanted to keep it. The rest of the post is all hand written and thoroughly manually tested.
Rendered at 22:02:24 GMT+0000 (Coordinated Universal Time) with Vercel.
Yes, having your entire filesystem deleted is much less likely now (bonus points for zfs snapshots of the image for each operation) Your context is still vulnerable, as anything the VM has access too.