cd /news/ai-agents/show-hn-agentnest-self-hosted-sandbo… Β· home β€Ί topics β€Ί ai-agents β€Ί article
[ARTICLE Β· art-69488] src=github.com β†— pub= topic=ai-agents verified=true sentiment=↑ positive

Show HN: AgentNest, self-hosted sandboxes for AI agents

AgentNest, an open-source runtime for secure AI agent execution, provides self-hosted sandboxes with disposable, policy-controlled environments for Python, shell commands, files, packages, browsers, GPUs, and Git work. The tool features secure defaults including non-root execution, read-only root filesystem, denied networking, and egress allowlisting, and supports stateful Python sessions, forkable state, async operations, and audit events.

read4 min views1 publishedJul 23, 2026
Show HN: AgentNest, self-hosted sandboxes for AI agents
Image: source

The open-source runtime for secure AI agent execution.

AgentNest gives AI agents disposable, policy-controlled environments for Python, shell commands, files, packages, browsers, GPUs, and Git work. It is self-hosted, Python-first, and deliberately not another cloud or cluster orchestrator.

from agentnest import Sandbox

with Sandbox("python:3.12-slim", timeout=60) as sandbox:
    sandbox.write_file("main.py", "print('Hello from isolation')")
    result = sandbox.exec_shell("python main.py")
    print(result.stdout)

Secure defaults: non-root, read-only root, no capabilities, denied networking, limits, cleanupEgress allowlisting: let code reachpypi.org

and nothing else, with every connection loggedAgent-native: stateful Python sessions, forkable state, async, streaming, secrets, approvals, audit eventsNon-destructive timeouts: a slow command is killed on its own; the sandbox and its state surviveCrash-safe: every resource is labelled with a deadline, soagentnest prune

reaps orphansProven, not promised: asuite of escape attemptsruns on every commitSelf-hosted & extensible: your Docker or Kubernetes; third-party backends via entry points

Try it in one command (needs Docker):

pip install agentnest
agentnest demo

Warning

Containers share the host kernel. Choose an isolation boundary appropriate for your threat model. Read the security model before running hostile multi-tenant workloads.

pip install agentnest
agentnest doctor

Optional extras:

pip install 'agentnest[kubernetes]'
pip install 'agentnest[server]'
pip install 'agentnest[mcp]'
pip install 'agentnest[all]'
python
from agentnest import NetworkPolicy, Sandbox, Secret, SecurityPolicy

policy = SecurityPolicy(
    network=NetworkPolicy.denied(),
    max_output_bytes=2_000_000,
    require_image_digest=True,
)

with Sandbox(
    "python@sha256:<digest>",
    security_policy=policy,
    environment={"TOKEN": Secret("redacted-in-output")},
    memory="512m",
    cpus=1.0,
) as sandbox:
    for event in sandbox.stream_shell("python main.py"):
        print(event.data, end="")

    checkpoint = sandbox.snapshot("workspace.tar")
    for artifact in sandbox.artifacts("output/**/*"):
        print(artifact.path, artifact.sha256)

Give code the network it needs and nothing more. Denied is still the default; an allowlist routes traffic through a filtering proxy that only lets approved domains through.

from agentnest import NetworkPolicy, Sandbox, SecurityPolicy

policy = SecurityPolicy(network=NetworkPolicy.allowlist(domains=("pypi.org", "files.pythonhosted.org")))
with Sandbox("python:3.12-slim", security_policy=policy) as sandbox:
    sandbox.exec_shell("pip install --user requests").check()   # reaches PyPI
    blocked = sandbox.exec_python("import urllib.request; urllib.request.urlopen('https://evil.example')")
    assert not blocked.ok                                       # everything else is refused

A persistent interpreter keeps variables and imports across calls β€” the code interpreter model, self-hosted.

with Sandbox("python:3.12-slim") as sandbox:
    session = sandbox.python_session()
    session.run("import pandas as pd; df = pd.DataFrame({'x': [1, 2, 3]})")
    print(session.run("df['x'].sum()").check().result)   # -> 6

Branch a running sandbox's state, explore several continuations, keep the one that worked β€” parallel A/B attempts and agent tree search without re-running from scratch.

with Sandbox("python:3.12-slim") as base:
    base.write_file("state.json", "{}")
    attempt_a = base.fork()
    attempt_b = base.fork()   # independent copies; neither sees the other's writes

Also included: AsyncSandbox

, deterministic Template

builds, bounded SandboxPool

, Git workspace helpers, browser/GPU presets, MCP tools, YAML profiles, a CLI, and an authenticated remote API.

AgentNest is a self-hosted control layer, not a hosted sandbox service. The distinction that matters: it decides what an agent's code is allowed to do and records what it did, across whatever backend you run.

AgentNest E2B Modal Sandboxes microsandbox llm-sandbox
Self-hosted, no account βœ… βœ… βœ…
Domain egress allowlist βœ… ❌ ❌ ❌ ❌
Stateful REPL sessions βœ… βœ… βœ… βœ…
Forkable state βœ… ❌ ❌ ❌ ❌
Approval hooks + audit events βœ… ❌ ❌ ❌ ❌
Pluggable isolation backend βœ… ❌ ❌ ❌
Auditable in an afternoon (~4k LOC) βœ… ❌ ❌ βœ…

See benchmarks for measured cold-start and round-trip latencies.

Give an existing agent a sandboxed code tool without changing its security story:

from agentnest.integrations.langchain import build_langchain_tool

tool = build_langchain_tool(network_enabled=False)   # a LangChain StructuredTool

There is a smolagents executor and a framework-neutral SandboxRunner

too. Or expose AgentNest over the Model Context Protocol so Claude Code, Cursor, or Claude Desktop can run code safely in one line of config:

{ "mcpServers": { "agentnest": { "command": "agentnest", "args": ["mcp"] } } }

See the integration guide.

flowchart LR
    App["Agent application"] --> API["Sandbox API"]
    API --> Guard["Policy Β· approvals Β· events"]
    Guard --> Contract["RuntimeBackend"]
    Contract --> Docker["Docker / gVisor / Kata"]
    Contract --> K8s["Kubernetes"]
    Contract --> Remote["Remote / Firecracker"]
    Contract --> Plugins["Third-party plugins"]

Read the quickstart, architecture, deployment guide, and complete documentation.

Planned: an optional service for teams that need to run many sandboxes at once. Applications will send it a sandbox request, and the manager will create, track, and delete the temporary environments on the team's existing Kubernetes cluster.

The manager will provide:

  • Queues and per-user limits so one application cannot consume every available resource
  • Automatic cleanup if an application disconnects or crashes
  • A dedicated Kubernetes namespace for sandbox workloads
  • gVisor-backed sandboxes for stronger isolation
  • Central logs, audit history, usage metrics, and health checks
  • Warm sandbox pools for faster startup

This will remain optional. Developers will still be able to use the current Sandbox

API directly with Docker or Kubernetes. AgentNest will use existing infrastructure rather than replace Docker or Kubernetes.

pip install -e '.[dev,docs]'
ruff check .
ruff format --check .
mypy agentnest
pytest --cov=agentnest --cov-report=term-missing
mkdocs build --strict

Docker integration tests are opt-in:

AGENTNEST_DOCKER_TESTS=1 pytest -m integration

Apache License 2.0. See LICENSE.

── more in #ai-agents 4 stories Β· sorted by recency
── more on @agentnest 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain β€” perfect for shipping the agent you just read about.

$git push zahid main
β†’ Live at https://your-agent.zahid.host βœ“
Get free account β†’ Pricing
from €0/mo Β· no card required
LIVE [news/show-hn-agentnest-se…] indexed:0 read:4min 2026-07-23 Β· β€”