Repository navigation
Replies: 1 comment
|
Yes. The "inject credentials at a proxy so the agent never holds them" pattern is becoming the standard shape for this, so you're in good company. Some prior art to compare your sidecar against:
Gaps worth checking in your setup, since they're where these designs usually leak:
On the bespoke kubectl scripting: a devcontainer.json that declares the sidecar, plus a NetworkPolicy template per workspace, seems like the natural thing for Devsy to generate. It would be a nice feature request if the maintainers are interested. |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
My goal for a while has been to take all the stuff running on my laptop, run it in the cloud, run more than one of them, and make it safe to run with --dangerously-skip-permissions. All the source code and the running applications that talk to each other, and their databases plus the AI agents (Claude Code, Codex) so they can fix things, diagnose problems, click around and take screenshots, reach the issue tracker, etc.
Each container has its own mitmproxy instance configured to inject credentials -- it can't exfiltrate what it never possesses.
I've got it working in K8s with the proxy in a sidecar for now, but it's a lot of bespoke kubectl scripting at the moment, definitely not ready for production.
Is anyone doing anything similar?
(Thanks again for rescuing the abandoned DevPod project and continuing it as Devsy!)
All reactions