This is promising, but there's one feature that's missing that I really care about: fine-grained networking.
They have this for Windows and Linux, but it's sadly missing for macOS - see the support table here: https://github.com/microsoft/mxc/blob/main/docs/backends/sea...
Things macOS is missing include "Allow/deny by hostname" and "Allow/deny by IP, CIDR, port, or protocol".
The rest all looks great, and if you are on Linux or Windows those restrictions don't apply.
I guess this is the universal challenge of building an abstraction layer over multiple different technologies.
hey simon,
smol machines actually support exactly those things across macs,linux, windows btw: https://github.com/smol-machines/smolvm/blob/main/AGENTS.md#...
here's a snippet of how it looks like to configure that:
+1 on smolvm! I provision a smolvm per job in preloop, a local/self-hosted github actions( https://github.com/preloopdev/preloop). iirc there was also some work to add a deny-cidr option as well which would give you more flexibility. But the egress filter captures most of what you need so it works great nonetheless.
love seeing preloop's work :)
how does it do it?
proxy in the middle (but cert pinning problems)
or DNS filtering? (but agent could have "memorized" stable IP)
Cert pinning: not a problem. we don't decrypt traffic, we just pass it through. The only exception is hosts you give a credential to, since we have to insert the key.
Memorized IP: doesn't work, the vm can only connect to an IP if it came from a DNS lookup of an allowed name. Any other IP is blocked.
A bit of "shared responsibility" philosophy kicking through but I try to have good defaults
Fine grained network policies is supported by microsandbox- a project that has already been working hard at building an abstraction layer over multiple different technologies. Microsandbox (on unix) builds on top of libkrun (a VM abstraction layer for unix). I am building a convenient runner on top of microsandbox: https://github.com/runcontain/runcontain (undergoing a rename right now). The best thing Microsoft could contribute right now would be great technology for light-weight containment on Windows.
They could bundle in a HTTP proxy (enforcing similar rules) perhaps. It takes a bit of reading to dig-through the Claude speak, but "Egress confinement is enforced; using the proxy is cooperative" simply means that there's no network egress, except through the proxy.
Of course, that only limits HTTP; and not other forms of network requests.
... interestingly, Anthropic's SRT is built on the same macOS primitives and DOES support the network configuration I'm looking for:
https://github.com/anthropics/sandbox-runtime/tree/main#as-a...
Yes, I wrap seatbelt myself, and it definitely supports this.