kodebeat / papers / ai
Containing what a coding agent can reach
Azkaban and offline, two Linux sandboxes with one axis each.
A coding agent runs with the full privileges of whoever started it and needs almost none of them. azkaban empties $HOME to a tmpfs and binds back only what you allow, leaving the network connected; offline severs the network in three kernel layers and leaves the filesystem alone. Both state their threat model, and neither claims to stop a determined attacker.
What is in it
- The problem — what goes unanswered without it, and who notices first.
- Why the obvious alternative falls short — stated plainly, including where it is the better choice.
- How it works — the method, not a feature list.
- Concrete use cases — with console output quoted from the repository, never reconstructed.
- The methodology behind any number it emits — every term shown, so the figure survives a question.
- What it deliberately does not do — the section most papers leave out.
Part of the AI infrastructure theme.
Get the PDF
One email with the download link, and this paper already selected. No follow-up sequence.