Remix.run Logo
▲ simonw an hour ago

This is promising, but there's one feature that's missing that I really care about: fine-grained networking.

They have this for Windows and Linux, but it's sadly missing for macOS - see the support table here: https://github.com/microsoft/mxc/blob/main/docs/backends/sea...

Things macOS is missing include "Allow/deny by hostname" and "Allow/deny by IP, CIDR, port, or protocol".

The rest all looks great, and if you are on Linux or Windows those restrictions don't apply.

I guess this is the universal challenge of building an abstraction layer over multiple different technologies.

▲gregwebs 27 minutes ago | parent | next [-]

This is supported by microsandbox- a project that has already been working hard at building an abstraction layer over multiple different technologies. Microsandbox (on unix) builds on top of libkrun (a VM abstraction layer for unix). I am building a convenient runner on top of microsandbox: https://github.com/runcontain/runcontain (undergoing a rename right now). The best thing Microsoft could contribute right now would be great technology for light-weight containment on Windows.

▲dannyw an hour ago | parent | prev | next [-]

They could bundle in a HTTP proxy (enforcing similar rules) perhaps. It takes a bit of reading to dig-through the Claude speak, but "Egress confinement is enforced; using the proxy is cooperative" simply means that there's no network egress, except through the proxy.

Of course, that only limits HTTP; and not other forms of network requests.

▲simonw an hour ago | parent | prev [-]

... interestingly, Anthropic's SRT is built on the same macOS primitives and DOES support the network configuration I'm looking for:

https://github.com/anthropics/sandbox-runtime/tree/main#as-a...

  const config: SandboxRuntimeConfig = {
    network: {
      allowedDomains: ['example.com', 'api.github.com'],
      deniedDomains: [],
    },
    filesystem: {
      denyRead: ['~/.ssh'],
      allowWrite: ['.', '/tmp'],
      denyWrite: ['.env'],
    },
  }