<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: tastyeffectco</title><link>https://news.ycombinator.com/user?id=tastyeffectco</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Mon, 08 Jun 2026 20:53:46 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=tastyeffectco" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by tastyeffectco in "Running Python code in a sandbox with MicroPython and WASM"]]></title><description><![CDATA[
<p>one question i have about the project?  what is the main need to be scoped to python only ? it is for perf ? infrastructure stack ? or something else ?</p>
]]></description><pubDate>Sun, 07 Jun 2026 22:15:13 +0000</pubDate><link>https://news.ycombinator.com/item?id=48439123</link><dc:creator>tastyeffectco</dc:creator><comments>https://news.ycombinator.com/item?id=48439123</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48439123</guid></item><item><title><![CDATA[New comment by tastyeffectco in "Show HN: Boxes.dev: ditch localhost; run Claude Code and Codex in the cloud"]]></title><description><![CDATA[
<p>you may checkout sandboxd project, it allow you ti run on your own vps plenty of sandboxes for differents usages : <a href="https://github.com/tastyeffectco/sandboxd" rel="nofollow">https://github.com/tastyeffectco/sandboxd</a></p>
]]></description><pubDate>Sun, 07 Jun 2026 21:37:43 +0000</pubDate><link>https://news.ycombinator.com/item?id=48438828</link><dc:creator>tastyeffectco</dc:creator><comments>https://news.ycombinator.com/item?id=48438828</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48438828</guid></item><item><title><![CDATA[New comment by tastyeffectco in "Self-hosted dev sandboxes with preview URLs (Docker, Go, no K8s)"]]></title><description><![CDATA[
<p>This project  takes the Docker route instead of Firecracker — each container drops all capabilities, runs no-new-privileges, read-only rootfs, per-sandbox memory/PID limits, isolated networks. but!  Not kernel-level separation like microVM.<p>depending on use cases but its enough for most  and way simpler to operate and maintain.<p>If you need stronger isolation, the other replies in this thread mention (gVisor on k8s) Depends on your threat model and how much infra complexity you want to manage.</p>
]]></description><pubDate>Thu, 04 Jun 2026 11:53:21 +0000</pubDate><link>https://news.ycombinator.com/item?id=48397363</link><dc:creator>tastyeffectco</dc:creator><comments>https://news.ycombinator.com/item?id=48397363</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48397363</guid></item><item><title><![CDATA[New comment by tastyeffectco in "Self-hosted dev sandboxes with preview URLs (Docker, Go, no K8s)"]]></title><description><![CDATA[
<p>Yes, but not fully!
each sandbox have all linux capabilities! runs with no-new-privileges, a read-only rootfs! capped limits on PID and Memory, network isolated per design! 
all that said! this is not a VM isolation level like Firecracker for example, but quit enough for most use cases for early stage products or entreprise internal products</p>
]]></description><pubDate>Thu, 04 Jun 2026 11:49:26 +0000</pubDate><link>https://news.ycombinator.com/item?id=48397325</link><dc:creator>tastyeffectco</dc:creator><comments>https://news.ycombinator.com/item?id=48397325</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48397325</guid></item><item><title><![CDATA[New comment by tastyeffectco in "Self-hosted dev sandboxes with preview URLs (Docker, Go, no K8s)"]]></title><description><![CDATA[
<p>For a 8 CPU, 12GB Ram you can run app to 10 concurrents sandboxes that do heavy builds! the project itself is not ram/cpu heavy at all! depending on what you will run inside ! that was one of  the main points why i didnt chose to go for real kvm isolation.<p>i would just say if its for an early stage product got for it! at scale reconsider security and isolation layers</p>
]]></description><pubDate>Thu, 04 Jun 2026 10:57:04 +0000</pubDate><link>https://news.ycombinator.com/item?id=48396861</link><dc:creator>tastyeffectco</dc:creator><comments>https://news.ycombinator.com/item?id=48396861</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48396861</guid></item><item><title><![CDATA[New comment by tastyeffectco in "Self-hosted dev sandboxes with preview URLs (Docker, Go, no K8s)"]]></title><description><![CDATA[
<p>upilote (mellosouls): your second reading is correct.<p>This is not a Lovable competitor, and it's not all of upilote.<p>upilote is the product: chat → agent builds → live preview.<p>This repo is just the infrastructure layer underneath it that we extracted and open-sourced under MIT. It handles one container per project, preview URLs, running agents, sleeping when idle, waking on request, persistence, and recovery after reboots.<p>For us, it simplified a lot of things. Instead of managing all that logic ourselves, it became: submit a task and stream events back.</p>
]]></description><pubDate>Thu, 04 Jun 2026 10:03:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=48396419</link><dc:creator>tastyeffectco</dc:creator><comments>https://news.ycombinator.com/item?id=48396419</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48396419</guid></item><item><title><![CDATA[Self-hosted dev sandboxes with preview URLs (Docker, Go, no K8s)]]></title><description><![CDATA[
<p>Article URL: <a href="https://github.com/tastyeffectco/sandboxes">https://github.com/tastyeffectco/sandboxes</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=48388909">https://news.ycombinator.com/item?id=48388909</a></p>
<p>Points: 111</p>
<p># Comments: 34</p>
]]></description><pubDate>Wed, 03 Jun 2026 19:43:37 +0000</pubDate><link>https://github.com/tastyeffectco/sandboxes</link><dc:creator>tastyeffectco</dc:creator><comments>https://news.ycombinator.com/item?id=48388909</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48388909</guid></item></channel></rss>