HNHacker News
TopNewBestAskShowJobs

ushakov

8,062 karma · joined March 24, 2017

https://mish.co
submissionscomments
ushakov··on The VMs Powering Mobile Agents (Instinct, Claude Code)
my thoughts is that Firecracker might be not the best runtime for that, as it’s very minimal on devices it wants to support (famously no PCI out of the box)
ushakov··on The VMs Powering Mobile Agents (Instinct, Claude Code)
Amp’s Orbs run on E2B.

E2B is fully open-source under Apache 2.0 and runs on GCP, AWS, Azure (preview) and locally on any Linux box that has /dev/kvm (Mac works via Colima, too).

source: https://github.com/e2b-dev/infra

ushakov··on The VMs Powering Mobile Agents (Instinct, Claude Code)
hey, i work at E2B, happy to answer any questions!
ushakov··on Migrating to HTTPX2
because pyqwest is what official connect Python library uses and we wanted to follow that
ushakov··on Migrating to HTTPX2
we have recently switched from httpx for the same reason but instead went with the Rust-based pyqwest (runs on Hyper) it has also a drop-in httpx-compatible transport so migration was easy and also it supports http2 trailers

https://pyqwest.dev

ushakov··on MicroVMs: Run isolated sandboxes with full lifecycle control
i’d say what AWS released looks closer to a bare compute primitive. E2B is up the stack and ships everything around VM like snapshots, networking, integrations.

also, there’s no lock-in, E2B is open-source and can be hosted on any cloud (AWS included).

plus supports bigger boxes, higher concurrency, longer timeouts (24hr).

disclaimer: i work at E2B

ushakov··on Ggml.ai joins Hugging Face to ensure the long-term progress of Local AI
the code is not public, so we can't know. i think it's much more nuanced and certain users' comments might get a preferential treatment, based on factors other than the upvote count - which itself is hidden from us.
ushakov··on Ggml.ai joins Hugging Face to ensure the long-term progress of Local AI
of course your comment attracts more upvotes - it's at the top.
ushakov··on Ggml.ai joins Hugging Face to ensure the long-term progress of Local AI
i don't doubt this. i just find it questionable that one particular poster always gets in the spotlight when AI is the topic - while other conversations in my opinion offer more interesting angles.
ushakov··on Ggml.ai joins Hugging Face to ensure the long-term progress of Local AI
i am curious, why are your comments always pinned to the top?
ushakov··on AWS Adds support for nested virtualization
We are running Sandboxes for AI Agents using Firecracker microVMS @ E2B
ushakov··on Ex-GitHub CEO launches a new developer platform for AI agents
$1.5M seed bets, maybe. not $60M though
ushakov··on Matchlock – Secures AI agent workloads with a Linux-based sandbox
just from looking at it

on Linux it runs Firecracker: https://github.com/jingkaihe/matchlock/blob/main/pkg/vm/linu...

on macOS uses the Apple's Virtualization.Framework Go wrapper: https://github.com/jingkaihe/matchlock/blob/main/pkg/vm/darw...

ushakov··on Matchlock – Secures AI agent workloads with a Linux-based sandbox
very cool, if you want cross-platform microvms, there's an interesting project called libkrun that powers projects like Podman and Colima.

here's a Go binding: https://github.com/mishushakov/libkrun-go

demo (on Mac): https://x.com/mishushakov/status/2020236380572643720

ushakov··on Monty: A minimal, secure Python interpreter written in Rust for use by AI
i think there’s a confusion around what use-case Monty is solving (i was confused as well). this seems to isolate in a scope of execution like function calls, not entire Python applications
ushakov··on Monty: A minimal, secure Python interpreter written in Rust for use by AI
we’re not disagreeing here - i meant for general use-case VMs are better, for some application-specific calls Monty this might suffice.

although you’d still need another boundary to run your app in to prevent breaking out to other tenants.

ushakov··on Monty: A minimal, secure Python interpreter written in Rust for use by AI
agree. you still need a secure boundary like VM to isolate the tenants in case the model breaks out of the sandbox.

everything that you don’t want your agent to access should live outside of the sandbox.

ushakov··on Monty: A minimal, secure Python interpreter written in Rust for use by AI
best answer is probably to have a layered approach - use this to limit what the generated code can do, wrap it in a secure VM to prevent leaking out to other tenants.
ushakov··on Monty: A minimal, secure Python interpreter written in Rust for use by AI
there’s no way around VMs for secure, untrusted workloads. everything else, like Monty has too many tradeoffs that makes it non-viable for any real workloads

disclaimer: i work at E2B, opinions my own

ushakov··on Deno Sandbox
Factory, Nvidia, Perplexity and Manus are using E2B in production - we ran more than 200 million Sandboxes for our customers
ushakov··on Sandboxing AI Agents in Linux
for personal use, many ways: Vargant, Docker Sandbox, NixOS VMs, Lima, OrbStack.

if you want multi-tenant: E2B (open-source, self-hosted)

ushakov··on Deno Sandbox
we aren’t worried about that.

when we were starting out we figured there was no solution that would satisfy our requirements for running untrusted code. so we had to build our own.

the reason we open-sourced this is because we want everyone to be able to run our Sandboxes - in contrast to the majority of our competitors who’s goal is to lock you in to their offering.

with open-source you have the choice, and luckily Manus, Perplexity, Nvidia choose us for their workloads.

(opinions my own)

ushakov··on Deno Sandbox
we offer secure cloud VMs that scale up to 100k concurrent instances or more.

the value we sell with our cloud is scale, while our Sandboxes are a commodity that we have proudly open-sourced

ushakov··on Sandboxing AI Agents in Linux
both Docker and bubblewrap are not secure sandboxes. the only way to have actually isolated sandboxes is by using VMs

disclaimer: i work on secure sandboxes at E2B

ushakov··on Deno Sandbox
10 seconds is actually not that impressive. we spin up Sandboxes around 50-200ms at E2B
ushakov··on Deno Sandbox
why? because there’s a huge market demand for Sandboxes. no one would be building this if no one would be buying.

disclaimer: i work at E2B

ushakov··on Deno Sandbox
we have 100% open-source Sandboxes at E2B

git: https://github.com/e2b-dev/infra

wiki: https://deepwiki.com/e2b-dev/infra

ushakov··on We asked 15k European devs about jobs, salaries, and AI [pdf]
i wonder what the stats look like with U.S companies in Germany. probably much higher, especially in areas like Berlin/Munich
ushakov··on Vm0
E2B https://github.com/vm0-ai/vm0/blob/main/turbo/package.json#L...
ushakov··on ClickHouse acquires Langfuse
they want to enter the llm observability market and langfuse has already built a convenient wrapper around clickhouse that companies have adopted

https://clickhouse.com/blog/clickhouse-raises-400-million-se...

Page 1 of 34Next →