Hasty Briefsbeta

Bilingual

Zed Editor, Docker Agent, ACP, but in a sandbox: running the agent with sbx

a day ago
  • The article explains how to run Docker Agent inside a Docker sandbox (sbx) for secure code execution, connecting it to Zed Editor via ACP protocol.
  • sbx isolates the agent in a microVM, limiting its access to only the shared workspace, preventing harm to the host filesystem or secrets.
  • The only configuration change needed is updating the LLM agent's `base_url` from `127.0.0.1` to `host.docker.internal:17434` to reach the local model server running on the host.
  • A sandbox is created with `sbx create docker-agent . --name docker-agent-acp`, and the agent is launched inside it via `sbx exec -i` in Zed's settings.
  • The network proxy in sbx filters outgoing traffic and injects secrets (e.g., API keys) without exposing them to the agent, enhancing security.
  • The agent runs locally with llmman serving the model, maintaining a fully local setup while adding sandboxing for safety.