Personal / Open source

Agent Airlock™

For when you just don't trust the AI.

Explore repository

The idea

Agent Airlock is a rootless Podman container that holds AI coding agents and their tools. The container sees only the host's ~/git folder and its own home volume, reaches the host's local language model server, and can run VS Code itself over the host's Wayland display. It runs on Linux, inside WSL2 on Windows, and on macOS with podman machine.

What it does

Claude Code and Codex run inside the container as command-line tools and as VS Code extensions, with their MCP servers. Agents can install tools without touching the host system. Test servers inside the container are published to the host's localhost only, so the host browser can open them. One launcher builds the image, starts the container, opens the editor, and runs logins.

Why

The agents get a working development environment, and the rest of the computer stays out of their reach. This website was built inside it.

Source code and documentation