cd /news/ai-tools/show-hn-cordium-foss-sandbox-platfor… · home topics ai-tools article
[ARTICLE · art-19127] src=github.com pub= topic=ai-tools verified=true sentiment=↑ positive

Show HN: Cordium: FOSS sandbox platform that eliminates credential injection

Cordium, a new open-source sandbox platform built on Kubernetes and Octelium, eliminates credential injection by providing identity-based, secretless remote access to infrastructure for developers and automated workloads. The platform, which serves as a self-hosted alternative to GitHub Codespaces and AI sandbox products like E2B, uses an identity-aware proxy to hold credentials outside the sandbox environment. Cordium is released under Apache 2.0 for self-hosting with no plans for a commercial version.

read1 min publishedMay 31, 2026

Hello HN, Cordium is a general-purpose sandbox platform built on Kubernetes and Octelium, may main work https://github.com/octelium/octelium, that can be used for various use cases, including coding for developers with VSCode, Zed, etc. (i.e. self-hosted GitHub Codespaces alternative), AI agent tasks (i.e. FOSS alternative to AI sandbox products such as E2B, Daytona, etc.), CI/CD workloads (e.g. building and publishing Docker images etc.), and more importantly for secretless remote access to infrastructure for devs and automated workloads.

The main differentiator here, compared to other dev environments and sandbox platforms, is that Cordium automatically provides identity-based, secretless secure access to resources/infrastructure (e.g. APIs, SSH, databases, k8s, etc.) without having to inject credentials (e.g. API keys, SSH private keys, database passwords, etc.) into the sandbox where the upstream credential is held by the identity-aware proxy of the Octelium-protected resource outside the reach of the sandbox. You can simply think of it as a sandbox + ZTNA/remote-access-VPN baked-in where access to infrastructure is based on identity and policy-as-code rather than credentials.

Cordium is a purely FOSS project under Apache 2.0 that's meant for self-hosting and there are no plans for a pro/SaaS/cloud version. The development of the project started back in 2022 and it is already being used by a few organizations that use Octelium since last year. Happy to answer any questions.

Comments URL: [https://news.ycombinator.com/item?id=48344623](https://news.ycombinator.com/item?id=48344623)

Points: 2

── more in #ai-tools 4 stories · sorted by recency
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/show-hn-cordium-foss…] indexed:0 read:1min 2026-05-31 ·