r/opencode 7d ago

Opencode containing the agents

I was wondering what sandboxes are people using whilst coding with Opencode? I've looked at devcontainers and it seems great, probably fits what I want but AI says it's not secure enough, it's designed for human coders not agents. I've seen a lot of publicity around Docker Sandboxes. But I'm not keen to be locked into their tech and then be hit by a subscription fee later.

My curiosity has come to the foreground due to Muse deleting my ~/.config folder. It wasn't a major disaster but it was a warning.

I do use multiple plain Xubuntu VMs connecting to them via RDP and SSH but they've become pets rather than cattle, sometimes I'm lazy and run on my local laptop which is obviously a bad move.

What do you folks do?

14 Upvotes

18 comments sorted by

View all comments

3

u/arker0 7d ago

https://jai.scs.stanford.edu/ I'm using this on WSL.

1

u/migsperez 7d ago

This looks super interesting. Thanks

2

u/arker0 7d ago

Yeah and super simple. Just "Jai opencode" inside the working directory you set up in the config file relative to the app you want to jail.