| ▲ | s_ting765 21 hours ago | |
The solution is not to use docker to sandbox Opencode. It is to use flatpak/bubblewrap/flatseal. I have vscode running in flatpak with directory permissions handled by flatseal. Vscode only has access to my dev folders and nothing else. Even the git bundled by vscode cannot call git push because of this (vscode doesn't have permission to read ~/.ssh!). It's an easy sandbox that's provided free of charge courtesy of bubblewrap/flatpak. As someone who uses opencode regularly, the quip about it asking for permission to read logs in /tmp after already writing to the directory is pretty funny. | ||
| ▲ | alanwreath 20 hours ago | parent [-] | |
I’m running my development from a Mac which I think precludes flatpack usage. Pity because I love the control you have over git | ||