<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: dbmikus</title><link>https://news.ycombinator.com/user?id=dbmikus</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Mon, 10 Aug 2026 13:39:43 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=dbmikus" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by dbmikus in "Ask HN: What are you working on? (August 2026)"]]></title><description><![CDATA[
<p>I'm working on <a href="https://www.amika.dev/">https://www.amika.dev/</a>, which lets you put sandboxed agents on cloud VMs and then message them over the internet.<p>It's for agent + human devboxes, for chatting with coding agents from the web, or automating them with an API. Thing like Claude Code web, but any agent and you directly control the VM, too.<p>We're working to make amika.dev work on any computer, homelab, or K8S cluster. For tech folks, I describe it kinda like if Tailscale and Firecracker had a baby.</p>
]]></description><pubDate>Sun, 09 Aug 2026 17:49:21 +0000</pubDate><link>https://news.ycombinator.com/item?id=49233657</link><dc:creator>dbmikus</dc:creator><comments>https://news.ycombinator.com/item?id=49233657</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49233657</guid></item><item><title><![CDATA[Axioms for a new operating system for AI agents]]></title><description><![CDATA[
<p>Article URL: <a href="https://fixpoint.co/axioms">https://fixpoint.co/axioms</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=49199885">https://news.ycombinator.com/item?id=49199885</a></p>
<p>Points: 3</p>
<p># Comments: 0</p>
]]></description><pubDate>Thu, 06 Aug 2026 17:43:04 +0000</pubDate><link>https://fixpoint.co/axioms</link><dc:creator>dbmikus</dc:creator><comments>https://news.ycombinator.com/item?id=49199885</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49199885</guid></item><item><title><![CDATA[New comment by dbmikus in "Celld: Self-hosted, distributed Durable Objects"]]></title><description><![CDATA[
<p>time to bring back the dev email distribution list</p>
]]></description><pubDate>Thu, 06 Aug 2026 01:39:52 +0000</pubDate><link>https://news.ycombinator.com/item?id=49191372</link><dc:creator>dbmikus</dc:creator><comments>https://news.ycombinator.com/item?id=49191372</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49191372</guid></item><item><title><![CDATA[New comment by dbmikus in "Codeberg Bans Cryptocurrency Projects"]]></title><description><![CDATA[
<p>Nope, but I thought about moving hosting (or to Forgejo) because of (a) GitHub's issues, and (b) I like the idea of using an OSS code forge<p>I suppose since Codeberg is a totally free non-profit for OSS projects, it makes it more reasonable for them to ban code for idealogical differences (as opposed to legal).<p>But if it were a paid service, this would not inspire confidence that it's a place to host my company's code.</p>
]]></description><pubDate>Sat, 01 Aug 2026 14:41:07 +0000</pubDate><link>https://news.ycombinator.com/item?id=49134869</link><dc:creator>dbmikus</dc:creator><comments>https://news.ycombinator.com/item?id=49134869</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49134869</guid></item><item><title><![CDATA[New comment by dbmikus in "Codeberg Bans Cryptocurrency Projects"]]></title><description><![CDATA[
<p>Identity is more than a name. It is also proving that you own that identity (aka authentication)</p>
]]></description><pubDate>Fri, 24 Jul 2026 14:59:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=49036663</link><dc:creator>dbmikus</dc:creator><comments>https://news.ycombinator.com/item?id=49036663</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49036663</guid></item><item><title><![CDATA[New comment by dbmikus in "Codeberg Bans Cryptocurrency Projects"]]></title><description><![CDATA[
<p>But the identity part of git is not (unless you count pgp signing of each commit, which never took off at a large scale)<p>and the git tools don't automatically propagate repo changes by default across a network</p>
]]></description><pubDate>Thu, 23 Jul 2026 02:33:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=49016148</link><dc:creator>dbmikus</dc:creator><comments>https://news.ycombinator.com/item?id=49016148</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49016148</guid></item><item><title><![CDATA[New comment by dbmikus in "Codeberg Bans Cryptocurrency Projects"]]></title><description><![CDATA[
<p>Well, definitely makes me inclined to never use Codeberg for source hosting if they can just get together and decide to ban an entire category of source repo.<p>It makes Codeberg seem like an unserious project.</p>
]]></description><pubDate>Thu, 23 Jul 2026 02:29:43 +0000</pubDate><link>https://news.ycombinator.com/item?id=49016108</link><dc:creator>dbmikus</dc:creator><comments>https://news.ycombinator.com/item?id=49016108</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49016108</guid></item><item><title><![CDATA[New comment by dbmikus in "IP Crawl: Living atlas of open webcams discovered on the public internet"]]></title><description><![CDATA[
<p>Really freaky seeing how many of these are bedrooms.</p>
]]></description><pubDate>Sat, 27 Jun 2026 19:47:40 +0000</pubDate><link>https://news.ycombinator.com/item?id=48701113</link><dc:creator>dbmikus</dc:creator><comments>https://news.ycombinator.com/item?id=48701113</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48701113</guid></item><item><title><![CDATA[New comment by dbmikus in "MicroVMs: Run isolated sandboxes with full lifecycle control"]]></title><description><![CDATA[
<p>Is the talk going to be shared online anywhere? Would be interested in checking it out later!</p>
]]></description><pubDate>Sat, 27 Jun 2026 15:27:57 +0000</pubDate><link>https://news.ycombinator.com/item?id=48699090</link><dc:creator>dbmikus</dc:creator><comments>https://news.ycombinator.com/item?id=48699090</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48699090</guid></item><item><title><![CDATA[New comment by dbmikus in "MicroVMs: Run isolated sandboxes with full lifecycle control"]]></title><description><![CDATA[
<p>exe.dev is great, but the VMs are not really "apps". They are durable computers / VMs.<p>An example of a "sandboxed agent app", would be: give the app all your past emails. An agent scans them and finds sales emails you need to follow up on. It shows you the suggested follow ups in a UI, and you approve/reject them. Then, it mass sends the approved emails and emits an update to your CRM with the changes.<p>The sandbox is deleted when the app runs. It's ephemeral for the lifecycle of the app. And you can re-run the same app repeatedly with new inputs, but it gets the same clean starting slate.</p>
]]></description><pubDate>Sat, 27 Jun 2026 04:11:13 +0000</pubDate><link>https://news.ycombinator.com/item?id=48695052</link><dc:creator>dbmikus</dc:creator><comments>https://news.ycombinator.com/item?id=48695052</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48695052</guid></item><item><title><![CDATA[New comment by dbmikus in "MicroVMs: Run isolated sandboxes with full lifecycle control"]]></title><description><![CDATA[
<p>Def!<p>My personal belief is that the future of an "app" is a combo:<p><pre><code>    1. micro VM
    2. agent on the VM
    3. software bundled into the VM

</code></pre>
So, it should be stupid simple to run these local sandboxed apps/agents. Right now, not too hard for technical users (esp. with things like <a href="https://smolmachines.com/">https://smolmachines.com/</a> and <a href="https://microsandbox.dev/" rel="nofollow">https://microsandbox.dev/</a>), but not as easy as clicking an app icon or typing `/path/to/binary` in the CLI</p>
]]></description><pubDate>Fri, 26 Jun 2026 17:29:36 +0000</pubDate><link>https://news.ycombinator.com/item?id=48689361</link><dc:creator>dbmikus</dc:creator><comments>https://news.ycombinator.com/item?id=48689361</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48689361</guid></item><item><title><![CDATA[New comment by dbmikus in "MicroVMs: Run isolated sandboxes with full lifecycle control"]]></title><description><![CDATA[
<p>Firecracker has more tooling for the orchestration layer that manages many sandboxes at once. Stuff like K8S integration, an external REST API control plane,  more first-class support for snapshotting, etc.<p>You'd have to build more of that with libkrun<p>The core tech of both are great though.</p>
]]></description><pubDate>Fri, 26 Jun 2026 17:27:15 +0000</pubDate><link>https://news.ycombinator.com/item?id=48689326</link><dc:creator>dbmikus</dc:creator><comments>https://news.ycombinator.com/item?id=48689326</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48689326</guid></item><item><title><![CDATA[New comment by dbmikus in "MicroVMs: Run isolated sandboxes with full lifecycle control"]]></title><description><![CDATA[
<p>Why do you want to self-host vs. using one of the many providers out there?<p>Daytona, E2B, OpenComputer, Freestyle, Blaxel, Vercel, Modal, Cloudflare, Tensorlake, Superserve, etc. etc.<p>Some of them work by pre-purchasing credits, so you can control the blast radius of spend.<p>Also, if you want a more embedded sandbox runtime as a library instead of a daemon + REST API, you can check out libkrun (and friendly layers on top of it like <a href="https://microsandbox.dev/" rel="nofollow">https://microsandbox.dev/</a> and <a href="https://smolmachines.com/">https://smolmachines.com/</a>)</p>
]]></description><pubDate>Fri, 26 Jun 2026 17:03:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=48688989</link><dc:creator>dbmikus</dc:creator><comments>https://news.ycombinator.com/item?id=48688989</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48688989</guid></item><item><title><![CDATA[New comment by dbmikus in "MicroVMs: Run isolated sandboxes with full lifecycle control"]]></title><description><![CDATA[
<p>There are sooooo many sandbox providers out there.<p>They do spike on different features like:<p><pre><code>    - snapshotting and forking
    - good SSH and VPN access for end-users
    - agent-friendly features, like obscuring secrets at network layer

</code></pre>
Then there's also the option to use libkrun to run local sandboxes on your own computer. That doesn't scratch the itch for hosted services, but works if your goal is to run agents inside isolated environments for your own work.<p>I've been working on some open-core stuff[1] to coordinate sandboxes, and we're making changes to have a library that lets people coordinate any number of remote or local sandboxes using any provider, kinda like how the Docker CLI works for managing containers, git repos, and coding agents. Flue[2] is another player in this space, and is more of a pure framework, while we're building it as an interactive product for using sandboxed agents and workflows.<p>[1] <a href="https://github.com/gofixpoint/amika/blob/main/ROADMAP.md" rel="nofollow">https://github.com/gofixpoint/amika/blob/main/ROADMAP.md</a><p>[2]: <a href="https://flueframework.com/" rel="nofollow">https://flueframework.com/</a></p>
]]></description><pubDate>Fri, 26 Jun 2026 16:58:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=48688930</link><dc:creator>dbmikus</dc:creator><comments>https://news.ycombinator.com/item?id=48688930</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48688930</guid></item><item><title><![CDATA[New comment by dbmikus in "Claude Desktop spawns 1.8 GB Hyper-V VM on every launch, even for chat-only use"]]></title><description><![CDATA[
<p>Yes, running locally certainly helps if you want your sandboxed AI to be able to use the internet without getting blackholed by Cloudflare</p>
]]></description><pubDate>Wed, 10 Jun 2026 21:58:13 +0000</pubDate><link>https://news.ycombinator.com/item?id=48483275</link><dc:creator>dbmikus</dc:creator><comments>https://news.ycombinator.com/item?id=48483275</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48483275</guid></item><item><title><![CDATA[New comment by dbmikus in "Claude Desktop spawns 1.8 GB Hyper-V VM on every launch, even for chat-only use"]]></title><description><![CDATA[
<p>Yeah, Docker Sandbox is in the right direction. But there's a lot of parts that are still not ironed out yet.<p>How do you package a Docker Sandbox up into an app that can expose UI widgets, with an agent hiding behind them? What widgets is the agent allowed to modify? How do you run a workflow like "give agent all these files, modify the files, and do changeset management on the modifications?"<p>I'm not 100% sure which part of these will be baked into the application standard format, and which are orthogonal. But current way of packaging up and running these agents doesn't feel right.<p>I think about this a lot because my startup is building cloud VMs for agents to do code-gen and auto-validate changes, so we have a workflow like:<p><pre><code>    1. git repo, skills, CLI tools, biz context goes in
    2. agent iterates against running dev environment
    3. changes go out into git PRs and CI

</code></pre>
I think this type of app/agent workflow will expand outside coding use-cases.</p>
]]></description><pubDate>Wed, 10 Jun 2026 21:56:58 +0000</pubDate><link>https://news.ycombinator.com/item?id=48483265</link><dc:creator>dbmikus</dc:creator><comments>https://news.ycombinator.com/item?id=48483265</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48483265</guid></item><item><title><![CDATA[New comment by dbmikus in "Claude Desktop spawns 1.8 GB Hyper-V VM on every launch, even for chat-only use"]]></title><description><![CDATA[
<p>Understand that it is annoying to spin up a heavyweight VM whenever running Claude Desktop, but I actually think per-app + agent virtualization is the future. Next version of an app is:<p><pre><code>    1. micro VM
    2. agent on the VM
    3. software bundled into the VM
</code></pre>
Then the agent is totally sandboxed at the hardware virtualization level. It can use the software tools on the VM or write its own. VM can control which software is "frozen" and which is open to agent modification. And VM can also control which services are exposed outside the VM through sockets, HTTP server, X window system, whatever<p>It's self-modifying apps that are sealed off from touching parts of the computer they shouldn't.</p>
]]></description><pubDate>Wed, 10 Jun 2026 21:03:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=48482687</link><dc:creator>dbmikus</dc:creator><comments>https://news.ycombinator.com/item?id=48482687</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48482687</guid></item><item><title><![CDATA[New comment by dbmikus in "Backpressure is all you need"]]></title><description><![CDATA[
<p>Claude Code's dynamic workflows are AI-generated JavaScript, so unlike `/goal` they can in theory import libraries and perform I/O (not sure that they can currently).<p>On checkpointing: I explained myself poorly. You're right that using higher level workflows doesn't turn off checkpointing. One can simply make harnesses non-interactive, but that can make models lose coherence over long tasks (because they can't ask for feedback). A higher level coordinator (/goal, CC dynamic workflows) is designed to provide this feedback without human intervention.<p>On price: older models keep getting cheaper, and most tasks don't need frontier capability. (I'm ignoring the part about subscription subsidies right now, and just talking about API price for tokens)<p>On my startup Amika: we run programmable cloud computers for agents, plus the workflow systems to guide them. We let people run any agent (Codex, Claude, etc.), prompt it from anywhere (Slack, web, CLI + SSH, API). It's like devboxes for humans + agents, with guardrails[1] to deterministically ensure things about the changes coding agents make (ie don't let agent modify module boundaries, require every DB query carry a multi-tenant org ID filter).<p>Maybe our website is bad at explaining it, in which case I appreciate any feedback!<p>[1]: <a href="https://docs.amika.dev/guides/code-annotations">https://docs.amika.dev/guides/code-annotations</a></p>
]]></description><pubDate>Mon, 01 Jun 2026 03:51:13 +0000</pubDate><link>https://news.ycombinator.com/item?id=48352416</link><dc:creator>dbmikus</dc:creator><comments>https://news.ycombinator.com/item?id=48352416</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48352416</guid></item><item><title><![CDATA[New comment by dbmikus in "Backpressure is all you need"]]></title><description><![CDATA[
<p>To stop agents from pausing for checkpointing, you can have a deterministic outer loop that re-runs until a stop condition is met.<p>I think teams need to be able to write nested workflows that transition between code-led and agent-led, with either supporting human-in-the-loop checkpoints.<p>Been iterating on what this should look like at our startup (<a href="https://www.amika.dev/">https://www.amika.dev/</a>). Model labs are also improving capabilities here, such as Codex's `/goal` and Claude Code's dynamic workflows[1]<p>The points about API usage cost still stand, but model intelligence is getting cheaper every month! No need to use the frontier model for every part of the work.<p>[1]: <a href="https://code.claude.com/docs/en/workflows" rel="nofollow">https://code.claude.com/docs/en/workflows</a></p>
]]></description><pubDate>Sun, 31 May 2026 21:29:47 +0000</pubDate><link>https://news.ycombinator.com/item?id=48349943</link><dc:creator>dbmikus</dc:creator><comments>https://news.ycombinator.com/item?id=48349943</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48349943</guid></item><item><title><![CDATA[New comment by dbmikus in "Regression: malware reminder on every read still causes subagent refusals"]]></title><description><![CDATA[
<p>I think with a proper managed agents platform, the user should have total control over the VM, the software on it, which model to use, and which agent harness to use. Then you can just override the system prompt and you don't need to follow Anthropic's rules!<p>Maybe Anthropic will give more control over configuring the Claude harness and VM, but they definitely won't let you swap out to other models and harnesses.<p>We've been building open core infra (<a href="https://github.com/gofixpoint/amika" rel="nofollow">https://github.com/gofixpoint/amika</a>) for running any agent on any type of VM or sandbox, with the main use case for safely automating internal code-gen, but technically could repurpose our stack for anything.<p>There should be a model agnostic platform for running these types of agentic apps.</p>
]]></description><pubDate>Wed, 29 Apr 2026 02:16:39 +0000</pubDate><link>https://news.ycombinator.com/item?id=47943484</link><dc:creator>dbmikus</dc:creator><comments>https://news.ycombinator.com/item?id=47943484</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47943484</guid></item></channel></rss>