Hardening¶
Tighten progressively, from low to high risk. Verify the controls actually installed at each level with pvisor status --review.
Level 1: Protect the workspace¶
- Workspace changes go to the staging area and reach the project only after review and apply; conflicts refuse to overwrite your edits.
.ssh,.gnupg, and private-key files inside the view are rejected, and access to.env,*.pem, and similar files raises a warning.- HOME uses an isolated view, and credentials are not passed through by default.
Level 2: Use mandatory network boundaries¶
A cooperative proxy constrains only clients that respect proxy settings. When you need a mandatory boundary:
# 只允许必要的目标(VM 上不可绕过)
pvisor run --safe --vm --rootfs image=my-agent-image:latest \
--overlaynet-allow api.openai.com:443 -- codex
# 或者在 host 上拒绝所有普通出口
pvisor run --safe --overlaynet-deny-all -- ./agent.sh
macOS host --safe already blocks direct external connections; selective rules on Linux host remain cooperative. See network boundaries for how the paths differ.
Level 3: Tighten credentials¶
- Do not hand long-lived credentials to the agent through
--pass-env; prefer a configured Gateway where the trusted side holds the upstream key. See credentials and environment variables. - Add rules for secret files with custom names in your project, for example
--access 'config/secrets/**:deny'; presets recognize only common filenames and do not detect renamed copies or keys in source. - Do not share credential directories with
--mount SOURCE:write; explicit shares do not pass through the workspace file rules.
Level 4: Reduce visibility¶
- On Linux, confine reads to the projected root with
--filesystem sandbox. - On VM, use an OCI image instead of
--rootfs host, and expose only the paths you need with--mount. - Pin the image digest, agent version, and model version, and keep the Run Bundle for later verification.
Verify fail-closed¶
--strict requires non-bypassable enforcement evidence for every requested capability dimension, and refuses to start the agent when any is missing. No executor currently claims complete subprocess enforcement, so it refuses to run; use it to confirm that your pipeline stops when a boundary is too weak, not as a stronger sandbox.