Containarium
View on GitHubOpen-source agent runtime — SSH-native isolation, eBPF egress policy, Kubernetes + LXC backends, GPU passthrough, MCP-native CLI
Self-hosted agent runtime that gives each AI agent a persistent, SSH-reachable isolated box on LXC or Kubernetes, with eBPF egress policy, GPU passthrough, and MCP-native CLI plus in-box shell/file tools for Cursor, Claude Code, and other MCP clients.
Use Cases
Give AI coding agents a persistent, isolated Linux boxRun untrusted agent-generated code with egress policy controlWire Cursor/Claude Code to a remote sandbox over MCP+SSHSelf-host a multi-tenant agent runtime on LXC or KubernetesExpose agent-built apps on public HTTPS hostnamesProvide shell/file MCP tools inside the agent containerAttach GPU nodes for agent AI workloadsSpin up ephemeral CI-debug boxes for failing test runs
Built With
- Language
- Go
- Frameworks
- MCP (mcp-go) · Kubernetes · controller-runtime · Incus/LXC · gRPC · OpenTelemetry · Caddy · sshpiper · Agent Sandbox (sigs.k8s.io) · Protobuf
Tags
agent-runtime · agent-sandbox · isolation · mcp · ebpf · kubernetes · lxc · ssh · self-hosted · multi-tenant · gpu-passthrough · sandboxing · coding-agents · go · code-execution · egress-policy