Hacker News

Coop – Isolated VM Environments for Running Claude Code and Codex

27 points by aggrrrh ago | 9 comments

compiotr |next [-]

How is this different from docker sbx or microsandbox.dev? Not saying we don't need more alternatives, just asking to see if there is a reason to switch.

mkesper |root |parent |next [-]

Docker sandbox is proprietary.

darkamaul |root |parent |previous [-]

I _think_ (disclaimer: I have only read the documention of the two tools) they overlap quite a bit. The main idea is to get VM isolation for your agents env.

3stacks |next |previous [-]

Oh awesome, I just started building something like this but nice to use something off the shelf for once.

I used a project called toolgate to autoapprove "safe" tool calls but request permission on riskier calls declaratively. But there's so many unnecessary tool permission requests

darkamaul |next |previous [-]

I use coop daily and found it super convenient for my use case (ie letting agents go on with no access to my other projects or personal files)

I would recommend anyone that has desire to provide stricter boundaries to agents to give it a try - while remembering that a motivated agent would probably be able to escape it :)

SegmentTree |next |previous [-]

Personally I am using Eclipse Enclave to sandbox my agents. Good to see another fully open source solution in Coop.

vladde |next |previous [-]

sidenote: coop is also a large swedish grocery chain, pronounced the same way :)

https://www.coop.se/

wolfi1 |root |parent [-]

not only in Sweden, in Germany and Switzerland as well. I guess it has the same origins in the trade unionist purchasing cooperatives at the turn of the century from the 19th to the 20th

mkesper |root |parent [-]

At least in Germany, it's pronounced co-op, though. The stores got rebranded meanwhile. https://www.coop.de/coop/historie/

sid_ships |next |previous [-]

[dead]

nirmeet011011 |next |previous [-]

[flagged]

DarmokTanagra |previous [-]

[dead]