{"repo":"mensfeld/code-on-incus","free":true,"listed":false,"github":"https://github.com/mensfeld/code-on-incus","clone":"git clone https://github.com/mensfeld/code-on-incus.git","description":"Give each AI agent its own isolated machine with root, Docker, and systemd. Active defense detects and stops threats automatically.","language":"Go","stars":654,"topics":["claude","claude-code","ai-tools","anthropic","cli","coding-assistant","containers","developer-tools","incus","lxc"],"license":"MIT","category":"deployment-docker-iac","readme_excerpt":"code-on-incus ( coi ) Isolated machines for AI coding agents - with active defense. COI gives each AI agent its own machine - a full system container with root access, systemd, Docker, and the ability to install anything. Agents work like they would on a real server: run services, manage packages, use cron - without touching your actual system. Files stay correctly owned, no permission hacks needed. Your credentials stay on the host. SSH keys, environment variables, and Git tokens are never exposed to AI tools unless you explicitly mount them. If something goes wrong, COI catches it - reverse shells, credential scanning, data exfiltration - and pauses or kills the container automatically. No manual intervention needed. Built by developers, for developers who run AI agents and want to know what those agents are doing. Not a product, not a startup - a tool that does the job. Who this is for - You run AI coding agents and want them to have full machine access - root, Docker, package managers, services - without risking your host - You want to know when an agent does something suspicious, not find out after the fact - You run multiple agents in parallel and need them isolated from each other - You want persistent dev environments that survive restarts and reboots, not throwaway containers that lose your setup every time - You care about your credentials not ending up inside an agent-controlled environment Watch the BetterStack video about Code on Incus Table of Contents - Who thi","default_branch":null,"files":null,"tree":[],"storefront":"/r/mensfeld","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/mensfeld/code-on-incus/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}