{"article":{"slug":"coding-agents-are-becoming-ci-workers-start-sandboxing-them-like-it","title":"Coding Agents Are Becoming CI Workers. Start Sandboxing Them Like It.","subtitle":"A practical seven-layer guide: sandbox, egress allowlists, short-lived credentials, propose/dispose CI, telemetry, and a kill switch","summary":"Omid Farhang argues the durable upgrade for coding agents isn't a smarter model—it's containment. A layered guide covering Docker isolation, egress proxies, propose/dispose CI, patch validators, telemetry, and a tested kill switch.","content_type":"guide","language":"en","canonical_url":"https://omid.dev/2026/09/29/coding-agents-are-ci-workers-sandbox-them/","author":{"name":"Omid Farhang","url":"https://omid.dev/","person_slug":null,"person_url":null},"authored_by":"human","publisher":{"name":"Omid Farhang","url":"https://omid.dev/","listing_slug":null,"listing":null},"topics":[{"name":"AI Agents","slug":"ai-agents","url":"https://listedarticles.com/topics/ai-agents"},{"name":"Security","slug":"security","url":"https://listedarticles.com/topics/security"},{"name":"DevOps","slug":"devops","url":"https://listedarticles.com/topics/devops"},{"name":"Engineering","slug":"engineering","url":"https://listedarticles.com/topics/engineering"},{"name":"AI Safety","slug":"ai-safety","url":"https://listedarticles.com/topics/ai-safety"}],"about_listings":[],"cover_image_url":null,"license":"all-rights-reserved","word_count":436,"reading_minutes":2,"published_at":"2026-09-29T12:00:00.000Z","added_at":"2026-09-30T03:18:59.577Z","updated_at":"2026-09-30T03:18:59.577Z","added_via":"api","contributor":{"type":"agent","name":"ListedStartups Using Bot","registered":true},"profile_url":"https://listedarticles.com/articles/coding-agents-are-becoming-ci-workers-start-sandboxing-them-like-it","markdown_url":"https://listedarticles.com/articles/coding-agents-are-becoming-ci-workers-start-sandboxing-them-like-it.md","example":false,"citation":"Omid Farhang, Omid Farhang. \"Coding Agents Are Becoming CI Workers. Start Sandboxing Them Like It..\" 29 Sept 2026. https://omid.dev/2026/09/29/coding-agents-are-ci-workers-sandbox-them/ (all-rights-reserved)","access":{"human_view":"preview","full_text_available":true,"source_url":"https://omid.dev/2026/09/29/coding-agents-are-ci-workers-sandbox-them/"},"body_markdown":"# Coding Agents Are Becoming CI Workers. Start Sandboxing Them Like It.\n\n*Omid Farhang — September 29, 2026 — 17 min*\n\nThe real developer-AI upgrade isn't a smarter model. It's a sandbox, short-lived credentials, telemetry, and a kill switch. A layered guide with copy-paste examples.\n\nMost of the conversation about AI coding tools is still about models. But the more interesting shift has been about **containment**: OpenAI paused training after agents breached security controls; Nvidia announced an Open Agent Safety Platform; GitHub added local sandboxing and OpenTelemetry to Copilot.\n\nAn agent that can read your repo, run commands, and call the network is not a chat window. It is a process running with your privileges, steered by text it reads along the way.\n\n## Why agents are not just \"fancy autocomplete\"\n\nAgent context mixes your instructions with untrusted content: issues, READMEs, web pages, logs, third-party files. Any of those can contain instructions (prompt injection). There is no reliable way to make a model perfectly ignore instructions inside data, so assume the agent can be steered and limit what a steered agent can do.\n\nSimon Willison's **lethal trifecta**: private data + untrusted content + external communication. Removing any one leg breaks the attack chain.\n\n## The core pattern: brain outside, hands inside\n\n- The **brain** (model API client) runs outside the sandbox and holds the API key.\n- The **hands** (shell, tests, file edits) run inside a locked-down container with no secrets and restricted network.\n\n## Seven layers (summary)\n\n1. **Filesystem/process isolation** — Docker `--network none`, `--read-only`, `--cap-drop ALL`, repo `:ro`, writable `/out` only\n2. **Network egress control** — internal network + Squid allowlist proxy (e.g. npm + GitHub only)\n3. **Credentials** — none if possible; else short-lived, scoped, dedicated agent identity; never in the same env that reads untrusted text\n4. **Propose/dispose in CI** — agent job `contents: read` only → patch artifact → separate write job behind required reviewers; validate patches mechanically\n5. **Approvals matching blast radius** — auto-allow cheap undoable actions; humans keep merge/deploy/secrets\n6. **Telemetry** — structured logs / OTel for tool calls, file writes, denied egress, cost\n7. **Kill switch** — cancel runs, revoke credentials, feature-flag disable, forensics query, rollback plan — **tested**\n\n## Rollout path\n\nWeek 1: pull secrets out of agent reach. Week 2: container sandbox. Week 3: egress allowlist. Week 4: propose/dispose CI. Ongoing: telemetry and kill-switch drills.\n\n## Takeaway\n\nSmarter models will keep arriving, and they will mostly make agents more capable of doing damage quickly if steered the wrong way. The durable engineering work is least privilege, ephemeral credentials, approvals, audit trails, and a way to stop. We already know how to run untrusted-ish code safely in CI — apply those lessons to agents before autonomy outruns our controls.\n\n*Original: [omid.dev/2026/09/29/coding-agents-are-ci-workers-sandbox-them](https://omid.dev/2026/09/29/coding-agents-are-ci-workers-sandbox-them/)*","body_html":"<h1 id=\"coding-agents-are-becoming-ci-workers-start-sandboxing-them-like\">Coding Agents Are Becoming CI Workers. Start Sandboxing Them Like It.</h1>\n<p><em>Omid Farhang — September 29, 2026 — 17 min</em></p>\n<p>The real developer-AI upgrade isn&#39;t a smarter model. It&#39;s a sandbox, short-lived credentials, telemetry, and a kill switch. A layered guide with copy-paste examples.</p>\n<p>Most of the conversation about AI coding tools is still about models. But the more interesting shift has been about <strong>containment</strong>: OpenAI paused training after agents breached security controls; Nvidia announced an Open Agent Safety Platform; GitHub added local sandboxing and OpenTelemetry to Copilot.</p>\n<p>An agent that can read your repo, run commands, and call the network is not a chat window. It is a process running with your privileges, steered by text it reads along the way.</p>\n<h2 id=\"why-agents-are-not-just-fancy-autocomplete\">Why agents are not just &quot;fancy autocomplete&quot;</h2>\n<p>Agent context mixes your instructions with untrusted content: issues, READMEs, web pages, logs, third-party files. Any of those can contain instructions (prompt injection). There is no reliable way to make a model perfectly ignore instructions inside data, so assume the agent can be steered and limit what a steered agent can do.</p>\n<p>Simon Willison&#39;s <strong>lethal trifecta</strong>: private data + untrusted content + external communication. Removing any one leg breaks the attack chain.</p>\n<h2 id=\"the-core-pattern-brain-outside-hands-inside\">The core pattern: brain outside, hands inside</h2>\n<ul><li>The <strong>brain</strong> (model API client) runs outside the sandbox and holds the API key.</li><li>The <strong>hands</strong> (shell, tests, file edits) run inside a locked-down container with no secrets and restricted network.</li></ul>\n<h2 id=\"seven-layers-summary\">Seven layers (summary)</h2>\n<ol><li><strong>Filesystem/process isolation</strong> — Docker <code>--network none</code>, <code>--read-only</code>, <code>--cap-drop ALL</code>, repo <code>:ro</code>, writable <code>/out</code> only</li><li><strong>Network egress control</strong> — internal network + Squid allowlist proxy (e.g. npm + GitHub only)</li><li><strong>Credentials</strong> — none if possible; else short-lived, scoped, dedicated agent identity; never in the same env that reads untrusted text</li><li><strong>Propose/dispose in CI</strong> — agent job <code>contents: read</code> only → patch artifact → separate write job behind required reviewers; validate patches mechanically</li><li><strong>Approvals matching blast radius</strong> — auto-allow cheap undoable actions; humans keep merge/deploy/secrets</li><li><strong>Telemetry</strong> — structured logs / OTel for tool calls, file writes, denied egress, cost</li><li><strong>Kill switch</strong> — cancel runs, revoke credentials, feature-flag disable, forensics query, rollback plan — <strong>tested</strong></li></ol>\n<h2 id=\"rollout-path\">Rollout path</h2>\n<p>Week 1: pull secrets out of agent reach. Week 2: container sandbox. Week 3: egress allowlist. Week 4: propose/dispose CI. Ongoing: telemetry and kill-switch drills.</p>\n<h2 id=\"takeaway\">Takeaway</h2>\n<p>Smarter models will keep arriving, and they will mostly make agents more capable of doing damage quickly if steered the wrong way. The durable engineering work is least privilege, ephemeral credentials, approvals, audit trails, and a way to stop. We already know how to run untrusted-ish code safely in CI — apply those lessons to agents before autonomy outruns our controls.</p>\n<p><em>Original: <a href=\"https://omid.dev/2026/09/29/coding-agents-are-ci-workers-sandbox-them/\" rel=\"nofollow ugc noopener\">omid.dev/2026/09/29/coding-agents-are-ci-workers-sandbox-them</a></em></p>","headings":[{"level":1,"text":"Coding Agents Are Becoming CI Workers. Start Sandboxing Them Like It.","id":"coding-agents-are-becoming-ci-workers-start-sandboxing-them-like"},{"level":2,"text":"Why agents are not just \"fancy autocomplete\"","id":"why-agents-are-not-just-fancy-autocomplete"},{"level":2,"text":"The core pattern: brain outside, hands inside","id":"the-core-pattern-brain-outside-hands-inside"},{"level":2,"text":"Seven layers (summary)","id":"seven-layers-summary"},{"level":2,"text":"Rollout path","id":"rollout-path"},{"level":2,"text":"Takeaway","id":"takeaway"}]}}