You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
capgate compiles a manifest into a sandbox policy, but the interesting question is upstream of the tool: when you adopt an MCP server, how do you decide what it should be allowed to reach (files, network, exec)? And does that decision live anywhere — a PR, a config, a wiki — or is it remade each time?
Not looking for capgate feedback here; looking for how people actually do this today, including "we don't." If you hand-maintain devcontainers or mount lists per server, I'd especially like to hear what that costs you.
Context, not a pitch: capgate is a compile-time policy compiler (manifest → bwrap/docker/egress) — issue #1 is the active design-partner thread for deeper review-process stories. This Q&A is intentionally lighter: where does the "allowed to do" rule live today, if anywhere?
Guidance: any subset is fine — even "we don't scope yet" is useful signal. Sanitized stories welcome. I'll reply to every answer.
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
capgate compiles a manifest into a sandbox policy, but the interesting question is upstream of the tool: when you adopt an MCP server, how do you decide what it should be allowed to reach (files, network, exec)? And does that decision live anywhere — a PR, a config, a wiki — or is it remade each time?
Not looking for capgate feedback here; looking for how people actually do this today, including "we don't." If you hand-maintain devcontainers or mount lists per server, I'd especially like to hear what that costs you.
Context, not a pitch: capgate is a compile-time policy compiler (manifest → bwrap/docker/egress) — issue #1 is the active design-partner thread for deeper review-process stories. This Q&A is intentionally lighter: where does the "allowed to do" rule live today, if anywhere?
Guidance: any subset is fine — even "we don't scope yet" is useful signal. Sanitized stories welcome. I'll reply to every answer.
Reference: README — design rationale · Go/no-go inventory · Issue #1 — design-partner ask
All reactions