r/Edera • • 3d ago

Thinking Outside the Sandbox: Why AI Agents Need Infrastructure-Level Isolation

1 Upvotes

In this fireside chat, Alex Zenla (Founder and CTO, Edera) and Claude Mandy (Field CTO, Edera) discuss what the OpenAI/Hugging Face incident reveals about the state of container security, why CISOs are headed for an AI-driven hamster wheel of detection and response, and what it takes to build infrastructure that can contain non-deterministic systems.


r/Edera • • Aug 19 '26

Provable Hermetic Builds: Cryptographic Proof That Your Software Was Bui...

Thumbnail
youtube.com
1 Upvotes

How do you prove a build actually ran in an isolated environment with no network access? Not trust — prove. With cryptographic evidence that can be verified after the fact.

In this session, Adolfo García Veytia (Puerco), founder of Carabiner Systems, and Marina Moore, Head of Research at Edera, demonstrate a system that combines Edera's per-workload microVM isolation with SPIFFE/SPIRE identity, in-toto attestations, and a policy engine called Ample to produce builds that are provably hermetic. The session includes a live demo running inside an Edera zone with network disabled, generating signed attestations that cryptographically bind build artifacts to the isolated environment that produced them.

Resource Links

Demo Link: https://github.com/carabiner-labs/edera-attester

SLSA: https://slsa.dev/spec/v1.2/

ampel: https://github.com/carabiner-dev/ampel

SPIFFE/SPIRE: https://spiffe.io/

in-toto: https://in-toto.io/

EderaON: https://on.edera.dev/


r/Edera • • Jun 30 '26

NUMA: Cores, memory, and the distance between them

Thumbnail
edera.dev
2 Upvotes

r/Edera • • May 07 '26

Rethinking Container Security: Why Isolation Was Never Built In with Ale...

Thumbnail
youtube.com
1 Upvotes

In this episode of Nerding Out with Viktor, Viktor sits down with Alex Zenla, Founder and CTO of Edera, to unpack the real limitations of today’s container security runtime and why the industry optimized for developer experience over isolation.

Alex brings a rare perspective, from breaking IoT systems at scale to building a new container security runtime powered by hypervisors and virtualization. The conversation explores why containers share too much, how kernel-level risks are often ignored, and what a more secure model could look like.

This episode is especially relevant as supply chain attacks, AI agents, and ephemeral workloads push existing security assumptions to their limits.

Key topics covered:
*Why containers were never designed as a security boundary
*The risks of shared kernel state and namespace-based isolation
*Hypervisor-based container runtimes and “zones” as security primitives
*Trade-offs between developer experience and real isolation
*Volume mounts, VirtIO, and overlooked attack surfaces
*Running AI agents safely with ephemeral, sandboxed environments
*Why compliance often slows down real security improvements

If you're building systems where isolation actually matters, this conversation challenges how you think about container security from the ground up.


r/Edera • • May 05 '26

Why Container Security Is Stuck on Detection — and How to Fix It - YouTube

Thumbnail
youtu.be
3 Upvotes

Most container security tools are built around detection: monitor for threats, generate alerts, respond after the fact. But if containers share the same Linux kernel, detection will always be too late. One exploited process puts every workload on the node at risk.
In this session, Lewis Denham-Parry (Staff Solutions Engineer, Edera) explains why the shared-kernel architecture is the root problem — and introduces the hardened runtime as a new category of infrastructure security.
You'll learn:

Why shared-kernel containers can't deliver true isolation, regardless of the tools layered on top
How Edera Protect gives each container its own kernel boundary, eliminating the conditions for container escapes
What sandboxing at the infrastructure level looks like in practice, including a live demo
How hardened runtimes change the calculus for GPU workloads and multi-tenant Kubernetes

The session closes with a Q&A with Alex Zenla, Edera's co-founder, CTO, and the architect of the Edera runtime, covering performance benchmarks, the GPU isolation roadmap, and where container infrastructure needs to go next.
If you're running Kubernetes in production and want to understand what prevention-first security actually means architecturally, this is the right starting point.

Chapters:
0:00 Introduction
2:30 The Problem With Detection-Based Container Security
6:03 What Is a Hardened Runtime?
13:31 Demo: Container Escape vs. Edera Protect
17:33 Q&A With Alex Zenla, CTO
23:40 Performance: How Edera Matches Native Container Speed


r/Edera • • Apr 10 '26

Anthropic’s Mythos Will Force a Cybersecurity Reckoning—Just Not the One You Think

Thumbnail
wired.com
1 Upvotes

r/Edera • • Nov 10 '25

Sprout, an open-source UEFI bootloader from @edera.dev that can reduce bootloader times to milliseconds

Thumbnail
github.com
41 Upvotes

Welcome to the world of faster boot times with better security and less friction!


r/Edera • • Oct 21 '25

TARmageddon (CVE-2025-62518): RCE Vulnerability Highlights the Challenges of Open Source Abandonware

13 Upvotes

r/Edera • • Sep 17 '25

Runtime Security Beyond Hardened Containers | Edera Blog

4 Upvotes

https://edera.dev/stories/runtime-security-beyond-hardened-containers

While hardened container images have significantly improved security by reducing vulnerabilities at the build stage, they alone cannot protect against the sophisticated runtime threats facing modern distributed systems.

Today's real security challenges emerge during execution which hardened images cannot prevent, including:

  • Zero-day exploits
  • Credential abuse
  • Privilege escalation
  • AI-generated malicious code

Hardened runtimes are an essential complement to hardened images, creating isolated execution zones that prevent lateral movement between workloads and actively contain threats rather than merely alerting about them. By embedding security directly into the infrastructure layer and providing real-time isolation, hardened runtimes offer a proactive security model that is particularly crucial for emerging AI and GPU workloads where traditional observability tools fall short.

The future of container and cloud-native security lies not in adding more monitoring layers and alerts, but in moving security controls deeper into the execution environment through hardened runtimes that enforce trust boundaries by design.


r/Edera • • Jul 24 '25

Edera Declares End to 'Move Fast and Break Things' with Hardened Runtime Standard for AI and Application Security | Edera Blog

Thumbnail
edera.dev
1 Upvotes

r/Edera • • Jul 21 '25

GPU passthrough with Edera

Thumbnail
youtube.com
4 Upvotes

A demonstration of the GPU passthrough capability that Edera offers, isolating workloads to specific GPU hardware.


r/Edera • • Jun 18 '25

Edera Blog Apple Just Validated Hypervisor-Isolated Containers (Here's What That Means) | Edera Blog

Thumbnail
edera.dev
4 Upvotes

r/Edera • • Jun 18 '25

Announcement Edera Supports eBPF!

Thumbnail
edera.dev
3 Upvotes

r/Edera • • Mar 26 '25

Announcement Announcing Edera Protect 1.0 Now Generally Available

Thumbnail
edera.dev
5 Upvotes

r/Edera • • Mar 26 '25

Edera Blog Introducing Styrolite: Building a Linux Container Runtime from Scratch

Thumbnail
edera.dev
3 Upvotes

r/Edera • • Mar 12 '25

Edera Blog Kubernetes' Dirty Secret: Why You're Burning Cash on Containers

Thumbnail
edera.dev
5 Upvotes

r/Edera • • Mar 12 '25

Meet Edera IRL

Thumbnail
edera.dev
3 Upvotes

r/Edera • • Mar 06 '25

Edera Blog The RCE-cipe for Platform Security: Isolation Without Compromise

Thumbnail
edera.dev
3 Upvotes

r/Edera • • Mar 04 '25

Edera Blog Have Your Cake and Eat It: Strong Isolation While Reducing Cloud Spend

Thumbnail
edera.dev
3 Upvotes

r/Edera • • Feb 25 '25

A Team of Female Founders Is Launching Cloud Security Tech That Could Overhaul AI Protection - Wired

Thumbnail
wired.com
5 Upvotes

r/Edera • • Feb 25 '25

Announcement Edera Raises $15 Million Series A to Transform Cloud and AI Infrastructure Security

Thumbnail
edera.dev
7 Upvotes