Matt Brockman explains why running agent-generated code needs an isolated environment with controlled resources and access. The workshop uses snapshot-based sandboxes and a capture-the-flag exercise to demonstrate runaway CPU, excessive memory use and disk growth, showing how to investigate rather than assume that isolation solves every operational problem.
Later exercises cover task runtimes, idle timeouts, orphan processes, persistent user-to-sandbox assignment and separate read-only template and writable runtime caches. Questions highlight tradeoffs in storage, networking, long-running services and GPU workloads. The examples are workshop demonstrations with stated limits, not a claim that every infrastructure use case is supported.
Watch on YouTube




