FIELD NOTE / X
Where the agent runs is its own category.
The short film, the complete written thought, and the evidence behind it.
The X conversation link will follow its public release.
Where the agent runs is its own category.
Day 106 - 2027-01-11 PT target - X
Video caption
Where the agent runs is its own category. No path back to the host by construction. Inventory before calling DIY equivalent. Treat substrate as a first class row. Narration uses Eric's authorized AI voice clone. #EricFieldNotes
Full written post / accessibility read
A disposable container with network none, a read only root, and dropped capabilities is a solid flag floor. Those flags matter. They are not the same trust boundary as a microVM. That comparison is my read of the isolation split, not a claim that flags are useless.
Docker's Why MicroVMs engineering post puts each sandbox in a dedicated microVM with its own kernel, a private Docker daemon isolated by the VM boundary, and no path back to the host. File access, network policy, and secrets are defined before the agent runs.
OWASP's Docker security cheat sheet still maps residual classes that flags alone leave open on a shared kernel: host kernel CVEs, docker.sock mounts, writable host paths, image supply chain, missing limits, stripped seccomp, container root without user namespaces. Exact CVE inventory for a given DIY shell is untested here; the residual class map is the attributable trail.
Agents API sandbox partner menus and project machines sit in the same category. Shared context and machine choice are substrate and session concerns, not tool schema concerns. Put substrate on its own row.
Narration uses Eric's authorized AI voice clone.
#EricFieldNotes
Four-beat scene transcript
1. Where the agent runs is its own category.
A disposable container with network none, a read only root, and dropped capabilities is a solid flag floor. Those flags matter. They are not the same trust boundary as a microVM. That comparison is my read of the isolation split, not a claim that flags are useless.
Visual: Not a footnote under model choice.
2. MicroVM means own kernel and private daemon.
Docker's Why MicroVMs engineering post puts each sandbox in a dedicated microVM with its own kernel, a private Docker daemon isolated by the VM boundary, and no path back to the host. File access, network policy, and secrets are defined before the agent runs.
Visual: No path back to the host by construction.
3. OWASP still maps shared kernel residuals.
OWASP's Docker security cheat sheet still maps residual classes that flags alone leave open on a shared kernel: host kernel CVEs, docker.sock mounts, writable host paths, image supply chain, missing limits, stripped seccomp, container root without user namespaces. Exact CVE inventory for a given DIY shell is untested here; the residual class map is the attributable trail.
Visual: Inventory before calling DIY equivalent.
4. Treat substrate as a first class row.
Agents API sandbox partner menus and project machines sit in the same category. Shared context and machine choice are substrate and session concerns, not tool schema concerns. Put substrate on its own row.
Visual: Beside model and harness choice.