Agent Sandbox: A Kubernetes CRD and controller for AI agent runtimes
github.com
github.com
To me, the interesting part isn't the isolation, RuntimeClass has given us gVisor/Kata pods for years. It makes it easy to deploy this new type of workload where an agent claims a pre-warmed sandbox, gets a prod-like environment with a stable identity, it can hibernate when idle and be thrown away when it has served its purpose.
Replacing CI for the verify step doesn't seem to be the marquee use case, but I'm going to set it up and try it.