HN user

pploug

120 karma

co-founder of Umbraco, stints at Zalando, Spotify etc etc

Posts24
Comments49
View on HN
docs.docker.com 8d ago

MicroVM sandbox on Win, Mac, Linux, with policy engine

pploug
12pts7
www.docker.com 3mo ago

SBX: MicroVM Sandboxes for Agents

pploug
5pts1
www.rivet.dev 5mo ago

We Reverse-Engineered Docker Sandbox's Undocumented MicroVM API

pploug
1pts0
www.docker.com 5mo ago

Docker AI agent sandboxes with HyperVisor isolation

pploug
5pts2
csef.it 6mo ago

Study: Managers with first-born daughters, hire more women and pay more equal [pdf]

pploug
14pts4
thenewstack.io 7mo ago

Docker open sources hardened images catalog, free for all to use

pploug
12pts0
docs.docker.com 8mo ago

Debugging containers that have no shell

pploug
31pts7
gordonbeeming.com 8mo ago

The Paranoid Guide to Running Copilot CLI in a Secure Docker Sandbox

pploug
59pts14
www.docker.com 9mo ago

Docker model runner adds Vulkan GPU support

pploug
1pts0
github.com 10mo ago

Orchestrate multi agents in a single YAML file

pploug
1pts0
www.solarpunks.club 11mo ago

Burning Man camp builds 2MWH solar power plant

pploug
4pts0
www.techemails.com 1y ago

Facebooks Strategy Tax

pploug
1pts0
cloud.google.com 1y ago

Gcloud run compose up – cloud run straight from compose.yaml

pploug
1pts0
github.com 1y ago

Mcp-gateway, central auth and config manager for mcp servers

pploug
3pts2
github.com 1y ago

Compose Spec Updated with <models> for AI Workloads

pploug
16pts10
github.com 1y ago

Generative AI Applications with Go and Testcontainers

pploug
2pts1
www.reuters.com 1y ago

Following fraud allegations, payments provider worldline shares drops 41%

pploug
4pts0
plo.ug 1y ago

Using LLMs in CI/CD for semantic testing of web content

pploug
6pts1
github.com 1y ago

Docker go SDK open sourced

pploug
1pts0
www.ajeetraina.com 1y ago

N8N, Local LLM, MCP proxy in 1 compose file

pploug
3pts0
www.youtube.com 1y ago

Chainguard on the challenges of solving OSS security issues

pploug
2pts1
engineering.atspotify.com 4y ago

Basic Pitch: ML model to turn audio into MIDI

pploug
12pts1
opensource.zalando.com 7y ago

Supporting employees engaged in open source

pploug
32pts7
github.com 7y ago

Show HN: Flair – State of the art NLP framework on top of pytorch

pploug
11pts0

Sandboxes are free, distributed outside of Docker Desktop, no license fee required - money is made on enterprise governance and cloud offerings.

You can call containers a commodity, or an industry standard? Feels like that is more an emotional argument than anything else.

2 different platforms, 2 separate sources of truths for policies, 2 different level of compatibility (apple containers don't support compose, MS uses a custom moby implementation, neither are particular mature), none has linux compatibilty?

Company sells product for profit - they are liable for the product and all its subcomponents - there is nothing unfair about this - it doesn't matter if you found the components in a hole in the ground or on github - if you are selling a product based off it, you are liable.

For freelancers / oss companies - you can still sell services such as consulting or support - without selling your oss project - then its a service - not a product.

Uh, this looks very nice - reminds me of a TUI version of Canopy, if you are interested, We've (docker) been working on a separate agent sandbox runtime called SBX built around a MicroVM with a private docker daemon inside, maybe there's potential for a collaboration to add support for this runtime - feel free to ping me: per(dot)krogslund(at)docker .com

- Each agent runs in a dedicated microVM - agents can build and run Docker containers inside the MicroVM - no access to the host Docker daemon - network isolation with allow and deny lists - available for macOs and windows (linux support coming)

Remember interviewing for a security role at Phillip Morris who owns the IQOS e-cigaret brand. They bragged about how the device phoned home every time it could get a bluetooth or wifi connection, to inform of consumption amount and patterns - so they could proactively send users more nicotine.

He dramatically revealed that they were no longer selling tobacco, but rather "Nicotine as a service"

Needless to say, I decided not to work for a merchant of death

the prevailing trends in locker-room design is privacy, a way to make “a diverse user base” feel comfortable.

One thing that annoys me about this article is the subtle stab at woke / gender identity as a reason for this change. Both Germany and Sweden has a much higher percentage of transgender people compared to the US, and neither have these kinds of locker rooms.

Living in Germany where all-gender nude changing rooms, nude all-gender saunas and nude beaches are very normal and very much not sexualised, it is striking how different the underlying culture is here - Germans find nudity practical and sanitary, and at the same time they very much insist that you wear special bathing shoes.

Only norway has significant oil revenue - sweden and denmark specifically are primarily economies driven by a highly educated workforce and well regulated job markets - Lego, Novo, Maersk are all exemples of this kinds of companies depending on those socalled big government programmes to produce highly educated and specialised workers.

While I generally agree with the author on code over tools, the article could have benefitted from some concrete ways that this could have potentially been done somewhat securely by sandboxing, enforcing zero trust, network segmentation, and all the other known controls we've developed over the last decade.

I love the optimism of this space, but fear that the "security is a sham" attitude will bite us all in the ass down the line.