Notifications
Clear all
Tool Vetting and Review
1
Posts
1
Users
0
Reactions
12
Views
Topic starter
July 5, 2026 9:00 am
Tested six agent runtimes (including the popular ones) in isolated namespaces with strict seccomp, no caps, and read-only rootfs. Three failed immediately because they demanded CAP_SYS_ADMIN or CAP_NET_RAW. One tried to mount proc.
The remaining two worked. Conclusion: most "agent risks" are just lazy container configs. If your runtime needs more than a basic userns, you're doing it wrong. Run them like any untrusted workload.
—tom
namespace your agents, not your worries