Sign in

Kyle Quest (the DockerSlim guy)

@kcqon.bsky.social
226 followers 305 following 300 posts

Helping contain and control AI agents, so they don't control you :-) * Agent sandboxing * Slim Containers * Good Dockerfiles * AI Native Infra * Created DockerSlim / SlimToolkit / MinToolkit * 50 Shades of Golang

PostsRepliesMedia
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 26/09/2026
Running agents in the cloud is the easy part (so many options for that like Fly.io Sprites or E2B.dev ). Getting those agents to the cloud is the hard part!
fly.io
Fly · Computers for agents
Sandboxes aren't enough. Give your agent a real computer and get back to building.
000
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 17/09/2026
Containers don't contain, but VMs don't contain either 🙂 Latest example, Docker Sandboxes where a vulnerability in virtio-fs host server allows a host breakout / code execution (CVE-2026-77179). There's also CVE-2026-79994, another symlink related bug (with Unix domain sockets).
000
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 12/09/2026
Another example why AI agent harness needs to be sandboxed (a ".git" trick that fools Claude Code). Can't really call it a sandbox escape because the harness itself was not sandboxed :-)
121
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 10/09/2026
Meta's Muse puts its agent harness in a sandbox... Good to see it instead of an essay explaining why you don't need to do it and all you need is just sandboxing your "hands" :-)
100
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 01/09/2026
OpenAI and Anthropic tell you that you only need to sandbox the "hands" (the tool calls), but not the "brain" (the harness) and they imply that it's an either or choice. If you chose to sandbox one thing it should be the tool calls. Why only one option? Why not sandbox the harness?
110
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 29/08/2026
Google's Antigravity agent sandboxing in action on Macs... Uses Seatbelt (not surprising :-)) and blocks access to the home directory (good), but then it pokes holes in it (some are iffy like the one for Docker)
100
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 28/08/2026
Bluesky... every time you log people out you lose tons of users because they likely don't remember the Bluesky password, so they just won't login again :-)
010
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 16/08/2026
The Minimal Containers project hit a big milestone! A 100 minimal container images, and all free! Awesome!
120
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 11/08/2026
TLDR facts about Docker Sandboxes (based on its install): Uses ContainerD compiled natively for Mac OS and uses Nerdbox for the VMs:
110
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 08/08/2026
Your AI agent sandbox is as good as its profile... Guess how good is the sandbox profile you get with Claude Code, Codex, Cursor or any other agent ;-)
010
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 08/08/2026
Totally didn't expect to bump into people at #DEFCON who'd recognize me for my container security talk at #SCaLE :-) Huge conference
010
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 07/08/2026
Swing by the Cloud Village if you're at #DEFCON . And $100 to anyone who can hack this device :-)
010
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 07/08/2026
The #DEFCON badges are pretty cool :-)
010
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 05/08/2026
What if the #DockerSlim magic is applied to agent sandboxing... Catch me at #DEFCON to find out how I do it to protect my Mac from getting hacked by agents (no BlackHat, not selling anything :-))
020
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 23/07/2026
Many AI / agent security tools and products rely on the HTTPS_PROXY environment variable to redirect and inspect network traffic, but many apps don't/won't work with those or will work around those, so you end up either with a security bypass or a broken app (where security blocks direct net access)
000
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 11/07/2026
Funny how OpenAI and Anthropic, with Fable and Sol and their internal uber LLM versions, can't get authentication fully figured out in their products once you get off the happy path :-)
010
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 04/07/2026
Funny how overnight Ralph Loops turned into Loop Engineering... Definitely sounds fancier :-)
000
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 25/06/2026
Speaking of microVMs... rumor has it Apple is building native microVMs. That would be cool. Keeping my fingers crossed :-)
010
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 23/06/2026
Interesting that it took so long AWS to expose its Firecracker MicroVMs (used for Lambda) as a service 🙂 aws.amazon.com/blogs/aws/ru...
aws.amazon.com
Run isolated sandboxes with full lifecycle control: AWS Lambda introduces MicroVMs | Amazon Web Services
AWS launches a new serverless compute primitive, AWS Lambda MicroVMs. VM-level, isolated sandboxes with no shared kernel or resources between sessions. Rapid launch and resume, full lifecycle control,...
130
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 19/06/2026
Looks like the new Docker HQ is in Seattle... Docker 2.0 :) Still mostly empty
120
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 17/06/2026
Crazy how the malware fires in the Node/npm ecosystem are spreading to the OS packages... Now quite a few Arch Linux packages are infected lwn.net/Articles/107...
lwn.net
Hundreds of AUR packages compromised
Hundreds of orphaned packages hosted by the Arch User Repository (AUR) have been compromised by [...]
000
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 04/06/2026
Sad, Docker has more breaking changes now than when it was first created. Will have to stop updating it to lock down the behavior... so it works consistently
000
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 03/06/2026
Sandbox Probe is a great tool to find holes in your coding agent sandboxes. Created by Andrew Martin ( @sublimi.no ) and his team at ControlPlane - github.com/controlplane...
github.com
GitHub - controlplaneio/sandbox-probe: Agentic sandbox enumeration: find security issues, and seed escape automation.
Agentic sandbox enumeration: find security issues, and seed escape automation. - controlplaneio/sandbox-probe
053
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 03/06/2026
KubeCon CFP submissions this year are noticeably better. Very exciting!
000
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 02/06/2026
Cursor coding agent deleting production DB is one of the recent agent horror stories... The OSO team has done a nice job collecting lots of other examples of AI agents going rogue 🙂 www.osohq.com/developers/a...
osohq.com
A registry of AI agent failures, exploits, and defenses | Oso
Track real-world AI agent breaches and exploits. See how and why agents fail and what security teams can do to defend production systems.
030
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 02/06/2026
Another reason why Claude Code or any other agent harness shouldn't run outside a (properly configured) sandbox... CC nukes session data that it considers old whether you like it or not... no warning, no prompt 🙂
000
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 01/06/2026
For the next Good Dockerfiles session, Ivan & I will be learning how 2 build our own Docker Hardened Images 2 see how they stack up to the regular images, the Wolfi images we built & the official Chainguard images. I'll be cool if someone who knows DHIs wants to join us (maybe even from #Docker :-))
010
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 28/05/2026
Interesting sandboxing post from Anthropic engineering. The harness / agent loop approach outside sandbox is flawed though (when it comes to security, but it's a UX/ops trade off for them). www.anthropic.com/engineering/...
anthropic.com
How we contain Claude across products
Anthropic is an AI safety and research company that's working to build reliable, interpretable, and steerable AI systems.
210
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 27/05/2026
Of course, the built-in sandboxing capabilities in agents have vulnerabilities in the areas where they are actually meant to protect. This null byte network bypass vulnerability in Claude Code's sandbox reminds me of the old network vulnerabilities from way back 🙂 oddguan.com/blog/second-...
oddguan.com
Second Time, Same Sandbox: Another Anthropic Claude Code Network Sandbox Bypass Enables Data Exfiltration
For the second time in five months, Anthropic Claude Code's network sandbox lets a process inside reach hosts the user's policy says to block, and exfiltrate any data the process touches. Every Claude...
000
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 26/05/2026
With this Claude Code sandbox config will access to the AWS credentials file be blocked? Not really 😉
110
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 26/05/2026
Follow up 2 how u can build your own minimal Wolfi-based container images with the OSS Chainguard tools & the "minimal" project Ritvik Arya created. This PoC agent uses various tools including BrowserBase & BrowserUse to reverse the Apko config from the official Chainguard Bun.js image catalog info
110
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 21/05/2026
Crazy how brittle (and barely usable) local AI agent sandboxing is... You are pretty much on your own to keep them on a leash and to keep them from biting your ass :)
030
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 13/05/2026
So now that Gitlab gave up on code hosting and collaboration are all the cool kids moving from GitHub straight to Codeberg :-)
020
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 12/05/2026
Bummer that Bun.js is being rewritten in Rust :-(
000
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 10/05/2026
The first batch of the follow up material for the "Assemble Your Own Chainguard Base Container Images" stream: An enhanced version of the "wolfictl" CLI ( github.com/GoodDockerfi... ) with new commands, extra flags and fixes.
github.com
GitHub - GoodDockerfiles/wolfictl: An enhanced version of the Chainguard wolfictl CLI used to work with the Wolfi OSS project
An enhanced version of the Chainguard wolfictl CLI used to work with the Wolfi OSS project - GoodDockerfiles/wolfictl
310
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 08/05/2026
May 9 is THE day! Join us this Saturday at 9:30am Pacific time if you are awake. We'll create minimal container images with Ritvik Arya using his "minimal" project and the open source Chainguard tools... and maybe we'll make some pancakes too 🙂 youtube.com/live/V-5ju2x...
youtube.com
Assemble Your Own Chainguard Base Container Images
YouTube video by Cloud Native Container Craft with Ivan and Kyle
000
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 30/04/2026
When you hear QEMU you probably think slow CPU emulation 🙂 But did you know that you can have MicroVMs with QEMU too? Firecracker and Cloud Hypervisor are not the only options if you are building your own sandboxing!
010
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 28/04/2026
With the Warp Terminal going open source I can finally make those terminal blocks deletable... It was so annoying to have noisy command blocks that you can share, save as workflow, filter and do many other things, but NOT delete 🙂
210
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 17/04/2026
If you don't control your AI agents, your agents control you :-)
000
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 12/04/2026
Anthropic Mythos and its ability to find new vulnerabilities got a lot of buzz... A great way to counter it is to reduce the attack surface removing the software components you don't need, so Mythos can't find zero day vulnerabilities in them. Can't exploit what's not there 🙂
000
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 01/04/2026
Nice to be able to compare the reverse engineered version of Claude Code with the original source code version 🙂
000
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 23/03/2026
If you are in Amsterdam for KubeCon this session on Tuesday will be great to see AND it's powered by Ivan's Iximiuz Labs!
230
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 21/03/2026
This week was a pretty cool Chainguard Assemble event and it was a great reminder that you can't have good Dockerfiles without good base images! But can you "assemble" your own Wolfi-based base container images?
220
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 18/03/2026
120
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 18/03/2026
Adding a bit more context to the last post... Full stack reachability isn't just a collection of data from different tools dumped into one place (looking at you ASPM :-))
100
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 15/03/2026
The AI code tsunami is already here... The software iceberg you are shipping to prod is becoming 10x bigger. And like with regular icebergs you don't see and don't know the biggest and the most dangerous part of it.
143
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 14/03/2026
The best tutorial out there (and i've seen all of them :-)) if you are interested in understanding the container image internals (and with awesome diagrams, as usual, that makes the tutorial 10x better): "How Container Images Actually Work: Layers, Configs, Manifests, Indexes, and More"
110
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 11/03/2026
Having a good vulnerability scanner / SBOM generator that produces complete and accurate results AND that's not brittle when it comes to obfuscation and evasion is significantly harder than what the vendors are doing now (but still doable).
220
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 10/03/2026
Good news... AWS EC2 VMs finally support nested virtualization, which is great for AI sandboxing that uses microVMs like Firecracker (no need for super expensive bare metal instances). Bad news... It's only for the C8i, M8i and R8i EC2 instance types.
000
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 10/03/2026
So many SomethingSomethingClaw projects and products everywhere 🙂
000