blog

Blog — page 6 of 38

·10 min read

How to Sandbox OpenHands Agent Execution in a microVM

OpenHands is a software engineer that runs bash, edits files, and browses the web on your behalf. By default it does all of that in a container sharing your host kernel.

how-toopenhandsai-agents
Ajay Kumar
·9 min read

How to Sandbox Aider's Command Execution

Aider is local-first on purpose, and that is exactly why the auto-test loop is the sharp edge: model-chosen commands, repeatedly, unattended, next to your SSH keys.

how-toaidercoding-agents
Ajay Kumar
·9 min read

How to give Goose a code execution sandbox

Goose's premise is that it lives on your machine with your tools. That is genuinely the point — and it is also a very large default trust grant. Here is where to draw the line.

how-togooseai-agents
Ajay Kumar
·11 min read

Running a SWE-bench Evaluation Harness on microVMs

Every SWE-bench instance needs an exact repo at an exact commit with an often-ancient dependency set, then runs a patch the model wrote and a test suite it wants to beat. That is an infrastructure problem, not a benchmark.

swe-benchevalsai-agents
Ajay Kumar
·10 min read

The best ways to host OpenHands in 2026

OpenHands is two workloads sharing a hostname: a cheap, mostly-idle control app, and a runtime that executes whatever the model just decided to type. Most hosting advice answers the first question and quietly gets the second one wrong.

openhandsai-agentscomparison
Ajay Kumar
·10 min read

Agent runtimes: containers vs microVMs

Nearly every open-source coding agent converged on the same runtime: a long-lived container holding a workspace, a shell, and an action server. That design is right about the shape and optimistic about the boundary.

ai-agentsagent-runtimecontainers
Ajay Kumar
·9 min read

Tracing agent runs when the code runs in a sandbox

You did the right thing and moved code execution out of your process. Now your beautifully instrumented trace has one span in the middle that says 'ran code, 4.2s, 900 bytes' and nothing else.

observabilityopentelemetrylangsmith
Ajay Kumar
·10 min read

Sandboxing IDE Agent Extensions

Your Approve button is doing more security work than any control you actually designed. Here is how to move the agent's shell off every developer's laptop without giving up the part that made it good.

ide-agentsdeveloper-toolssecurity
Ajay Kumar
·10 min read

How to Sandbox a browser-use Agent

Every page a browser agent visits can address it directly. That is not an edge case in the threat model — it is the product. Here's how to run one session per microVM.

how-tobrowser-useplaywright
Ajay Kumar
·11 min read

What Coding Agents Actually Need From a Sandbox

Most sandbox comparisons start from the sandbox's feature list. Start from what the agent actually does all day and you end up with a different, shorter, more annoying list.

ai-agentscoding-agentssandbox
Ajay Kumar
·13 min read

The Best Sandbox APIs for Ruby and Rails AI Agents in 2026

You are building an agent in Ruby, and every sandbox vendor's quickstart opens with Python. The honest first finding: essentially nobody ships a Ruby SDK, so the real question is how good the REST API is and how much of a client you are about to write.

comparisonrubyrails
Ajay Kumar
·14 min read

The Best Open-Source Coding Agents in 2026 — and What Each One Needs From the Machine It Runs On

Every open-source coding agent is a shell with a language model attached. The interesting differences aren't in the model — they're in what the shell can reach.

ai-agentscoding-agentsopen-source
Ajay Kumar
·14 min read

The best web scraping and crawling platforms in 2026

Scraping platform names four different products that people compare as if they were one. Sort the field into layers and most of the comparison questions answer themselves.

comparisonweb-scrapingcrawling
Ajay Kumar
·18 min read

The Best Open-Source Browser-Agent Frameworks in 2026

Five ways to let a model drive Chrome — and the unfashionable truth that plain Playwright behind typed tools beats all of them more often than the category admits.

ai-agentsbrowser-automationcomparison
Ajay Kumar
·14 min read

The best AI agent observability and tracing platforms in 2026

Agent observability is three different products sold under one word. Pick by which of the three jobs is your bottleneck — and check whether your traces cover the part where agents actually fail.

comparisonobservabilityai-agents
Ajay Kumar
·14 min read

The best StackBlitz alternatives in 2026

StackBlitz is not a slightly different CodeSandbox. There is no server at all -- your code runs in the tab. Picking a replacement means knowing which wall you hit.

stackblitzwebcontainersalternatives
Ajay Kumar
·14 min read

What is the Model Context Protocol (MCP)?

Tool calling already existed. MCP's contribution is turning M applications times N integrations into M plus N. Here is what that buys you, what it does not, and why an MCP server is a program you are running with your credentials.

mcpai-agentsexplainer
Ajay Kumar
·12 min read

What Is a Headless Browser? How It Works and What It Costs to Run

It is not a different browser — it is the same engine with the window removed. The surprise is never the definition; it is that the process you thought was free costs hundreds of megabytes, needs kernel features your container blocks, and leaks until the box dies.

headless-browserbrowser-automationplaywright
Ajay Kumar
·19 min read

The anatomy of an AI agent's bill: tokens vs compute vs egress

Three invoices, no shared key, and the biggest line grows with the square of your turn count. Here is one agent run taken apart, with a lever for each cost line.

cost-optimizationagentsllm
Ajay Kumar
·16 min read

How to give a Strands agent a code execution tool

Strands ships a sandbox interface and names its default NotASandboxLocalEnvironment. Here is how to implement that interface against a real microVM, and every decision that follows.

strands-agentsawspython
Ajay Kumar
·11 min read

Tekton Steps, MicroVM Bodies: Isolating Untrusted Tasks

A TaskRun is a Pod. That is Tekton's best feature and its sharpest constraint — because everything inside a Pod is inside one trust boundary, including the step running a stranger's build script.

tektonkubernetesci-cd
Ajay Kumar
·11 min read

Cross-Compilation Build Farms: One MicroVM Per Target

One binary becomes a matrix the moment somebody asks for arm64. Emulation lies about the parts you care about, cross-compiling breaks on the sysroot — here is the third answer.

cross-compilationbuild-systemsmicrovm
Ajay Kumar
·11 min read

OSS License Compliance Scanning, One MicroVM Per Scan

You cannot produce a defensible license report from a lockfile — the evidence lives inside the tarballs. Which means something of yours has to expand a few thousand strangers' archives.

license-complianceopen-sourcespdx
Ajay Kumar
·11 min read

The Best Prefect Hosting Platforms in 2026

Almost every 'how do I host Prefect' thread is two questions wearing one coat: where does the server live, and where do flow runs actually execute? They have different answers, and the second one is the one that costs money.

comparisonprefectorchestration
Ajay Kumar