textlog
Really glad to be using Haskell for work - especially in today's climate with agentic coding. Our team uses containers to keep our development environment consistent across team members, though, and most agent sandbox approaches want to either offload your work fully to the cloud or they want to sandbox the agent harness process itself. We're not ready for full cloud based development (yet?) and sandboxing just the agent doesn't work for us when the agent needs to run docker. #haskellnotesfollow #ainotesfollow

share with friends

@zen wrote on textlog https://textlog.cc/post/2448
500 chars / 20 lines max · use #hashtags, @mentions and more
😀😃😄😁😆😅😂🤣😊😇🙂🙃😉😌😍🥰😘😋😛😜🤪🤨🧐🤓😎🤩🥳😏😒😞😔😟😕🙁☹️😣😖😫😩🥺😢😭😤😠😡🤬🤯😳🥵🥶😱😨😰😥😓🤗🤔🫣🤭🫢🤫🤥😶😐😑😬🙄😯😦😧😮😲🥱😴🤤😪😵🤐🥴🤢🤮🤧😷🤒🤕🤑🤠😈👿👻💀☠️👽🤖🎃😺😸😹😻😼😽🙀😿😾❤️🧡💛💚💙💜🖤🤍🤎💔❣️💕💞💓💗💖💘💝💟👍👎👌🤌✌️🤞🤟🤘🤙👈👉👆👇☝️✋🤚🖐️🖖👋🤝👏🙌🫶👐🤲🙏✍️💪👀👁️🧠🫀🫁🌱🌿☘️🍀🌸🌺🌻🌞🌙⭐✨⚡🔥🌈☀️☁️❄️☕🍕🍎🎉🎊🎈🎁🎵🎶🎨📚💡✅❌⚠️🚀🌍💻📱🔒🔑
example.com or
https://example.com
Regular links
[title](example.com) or
[title](https://example.com)
Markdown links
~text~ or ~~text~~
Strikethrough
*text* or **text**
Bold
_text_ or __text__
Underline
/text/
Italics
> text
Quote
:smile
Emoji autocomplete
1. first
2. second
3. third
Numbered lists
- first
- second
- third
Bulleted lists
Name  | Status | Count
----- | :----- | ----:
notes | ready  |     3
Tables
|redacted|
Redacted
`code`
Inline code
```…```
Code fences
$inline$
Inline LaTeX
$$block$$
Block LaTeX
Which one? #poll
First option
Second option
PollsUse 2–8 unique options.
Which one? #quiz
Wrong answer
> Correct answer

Explanation revealed after answering
QuizzesMark exactly one of 2–8 unique answers with >. Text after a blank line is revealed after answering.
Visible text #spoiler
Hidden text
SpoilersText after #spoiler is hidden until revealed. Aliases: #tldr, #sensitive, #contentwarning, #cw, and #triggerwarning.
Going hiking #map
Kallikratis, Crete
MapsShows a map preview for the first location line. Alias: #location.
#flying Heraklion to Berlin
FlightsHover over the itinerary to see a map connecting the airports. The next three words form the itinerary: airport, to (or → or ->), airport. Use single-word airport names or IATA/ICAO codes.
Today #todo
[ ] First task
[x] Finished task
TodosOnly [ ] and [x] lines become items. Click your items to toggle them.
Run this #exec
```js
console.log(6 * 7)
```
Executable codeRuns the next language-tagged code fence and shows its output beneath the note.
Keep this visible #pin
Pinned notesYour latest #pin is shown first on your profile, independently for notes and replies.
No more replies #lock
Locked conversationsPrevents new replies to this note and every reply beneath it.
About textlog #meta
Meta conversationsKeeps this note and its replies out of public discovery feeds. Aliases: #tlog and #textlog.
Continue quietly #whisper
Whisper conversationsKeeps the branch out of all and hot. Participants, mentions, and tag followers can receive it in my feed. It remains public elsewhere.
For @someone and @another #private
Private conversationsOnly the author and mentioned users can read this branch.
Answer before reading #HiddenReplies
Hidden repliesHides all replies until you reply.
... because letting the agent run docker gives them a too-easy escape hatch from their sandbox. So we're currently stuck with using VMs. This turns out to be tricky but seems do-able. My current approach is to provision a VM image and use Incus for the execution. My main goal is to keep my current workflow of local/non-agent dev working seamlessly and share the source with the VM/agent.
This means sharing my working dirs with the agent VM but overlaying artifact dirs from VM-owned block devices so we don't take too big of an IO perf hit. I also don't want the agent to be able to git push so that means we need some quirky git config to rewrite origin paths and thread through some agent specific PATs ("thanks" GitHub) for read-only repo access. These ALSO need to be threaded through to the development containers - they need to clone private repos.
... in the end, this seems to work but I haven't lived with it for long. There are still some quality of life issues to work out, but I think it'll work out. At this point, I've removed all coding agents from my host - and that's nice.
It's tangential to the sandboxing topic, really. I started the first post with a broader intent in mind and then elaborated on the sandboxing setup I'm working on. For AI-assisted coding, though, it's nice because Haskell provides a lot of feedback earlier in the development process compared to lots of other languages. It tends to work once it compiles (obviously not all the time).
join the communityorbrowse more notes