code-on-incus
Provides each AI agent with an isolated machine featuring root access, Docker, and systemd, along with automatic active defense — helping developers safely test AI-generated code.
Tool overview
The project has attracted 578 GitHub stars, indicating notable attention, but the evidence is confined to a single repository without tutorials, detailed reviews, or production case studies. Its real-world adoption remains uncertain, placing it at an early visibility stage.
It uses Incus containers to provision a complete isolated environment for every AI agent, including root privileges, a Docker daemon, and systemd. An active defense component continuously monitors process behavior, automatically identifying and stopping suspicious activity to protect the host from malicious AI-generated actions. This setup allows developers to execute untrusted scripts or commands in a realistic yet disposable machine-like setting.
No pricing is disclosed; based on its open-source nature, it is likely free to deploy locally. Users must manage their own Incus infrastructure and have solid Linux administration skills. It is well-suited for AI-tooling developers who need strong isolation, but less suitable for teams seeking zero-ops cloud sandboxes or lightweight file-system-only restrictions.
This tool does not have related social references to display yet.