The Containarium blog

Engineering notes from the team building an open-source agent runtime — sandbox design, LXC and Incus internals, container isolation, eBPF network policy, and honest comparisons of the tools in this space. We write up what actually broke, not just what shipped.

Posts

  1. Security Hsin 繁體中文

    You should own everything. You don't have to run it.

    "We're six people, we have nobody to run a cloud account" is a fair objection to yesterday's post, and the answer isn't "go hire an ops team." Owning something and running it are two different jobs. The four things you never hand over, the four tests of a healthy delegation, and how to move out without an IT department.

    Read the post

  2. Security Hsin 繁體中文

    Day two of the breach: custody, not trust

    The official statement says only environment variables were exported; the rumors say far more. You can verify neither — and that verification gap is what you signed up for when you handed over custody. On trust vs. verify vs. custody, and the four rules of real BYOC.

    Read the post

  3. Engineering Hsin

    Agent sandboxes on Kubernetes: gVisor breaks kubectl, not SSH

    Turn on gVisor and kubectl port-forward stops reaching the pod — kubectl exec, it turns out, doesn't. We hit the gap independently, then found our own SSH gateway was ALSO broken, for two unrelated reasons. What broke, what we got wrong the first time, and what's proven end to end now.

    Read the post

  4. Comparison

    The best AI agent sandboxes in 2026 (compared)

    Containarium, E2B, Modal, and Daytona side by side on the things that actually decide the choice: self-hosting, persistence, isolation technology, license, MCP support, and cost. Written by a vendor in the space, so it says plainly where each competitor wins.

    Read the comparison

More posts are on the way — LXC versus microVMs for agent workloads, and what we found taking a debugger to a liblxc deadlock in production. Subscribe by RSS to get them.

Give your agent a real box.

Self-host the open source on your VM, or start free on the hosted cloud.