▲ | netcoyote 11 hours ago | |||||||||||||||||||
I'm playing around with sandboxing techniques on Mac so I can isolate AI tools and prevent them from interacting with files they shouldn't have access to -- like all my dotfiles, AWS credentials, and such. I've created two open-source solutions, one which uses a VM (https://github.com/webcoyote/clodpod) and another which creates a limited-user account with access to a shared directory (https://github.com/webcoyote/sandvault). Along the way I rolled my own git-multi-hook solution (https://github.com/webcoyote/git-multi-hook) to use git hooks for shellcheck-ing, ending files with blank lines, and avoid committing things that shouldn't be in source control. | ||||||||||||||||||||
▲ | LaFolle 10 hours ago | parent | next [-] | |||||||||||||||||||
Have you seen tart https://tart.run/ ? | ||||||||||||||||||||
| ||||||||||||||||||||
▲ | thethimble 11 hours ago | parent | prev [-] | |||||||||||||||||||
Have you considered using docker? Seems possibly more lightweight than a VM with more isolation than a user account based method. | ||||||||||||||||||||
|