Ask HN:AI 代理与容器化/安全性的建议

2 分•作者: dv35z•3 个月前
各位 HN 的朋友们: 我注意到一种趋势,人们允许 AI 代理访问本地项目和用户文件夹,甚至更广泛的操作系统文件。 因此,我想提出一个问题: 我们如何才能安全地使用 AI 工具,同时保护我们系统和数据的完整性,并且足够易于高效使用?尤其是在工作流程经常涉及本地系统命令和网络命令的情况下。 评论结构建议: 操作系统 / 代理容器 / 代理 / 安全策略与工具栈 / 工作流程 举个例子:我目前在 Linux Mint Debian Edition (LMDE) 上使用 OpenCode(配合 DeepSeek),我注意到代理和容器经常请求在 `/tmp/` 目录下创建文件。我通常会禁止这样做,并指示它只使用当前文件夹中的文件。我更希望该工具能够通过系统强制的方式,仅访问指定的项目文件夹(`~/Projects/PROJECT-NAME`)。然而,我发现代理经常需要运行系统命令(例如,使用 `ps` 调试本地开发服务器,使用 `pandoc` 或 `ffmpeg` 进行文件转换等)。这开始模糊界限——所以我认为,为了让 AI 代理有用,我可以考虑给予它访问一个隔离操作系统的权限,这让我联想到虚拟机、Docker 容器等。但这又引入了复杂性,例如“我是否应该在我的系统/虚拟机之间使用共享文件夹?”等等。 我很想听听大家有哪些行之有效的方法,“理想”状态是什么样的,以及我们如何实际实现它。 我需要提到的是,我经常向一些技术新手(包括 AI)授课,所以我正在努力寻找一个平衡点,既能让他们轻松有效地完成工作,又能默认让他们掌握安全/完整性实践,以免他们陷入糟糕的境地(“AI 删除了我的项目/电脑!”)。 谢谢!
查看原文
Hello HN crew -<p>I am seeing the tendency for people to allow AI agents to access local project &amp; user folders, and beyond (operating system files).<p>I thought to ask the question: How can we best use AI tools safely - where the workflow often runs local system commands and network commands - to protect the integrity of our systems &amp; data AND be easy enough to use productively?<p>Comment structure idea:<p>Operating system &#x2F; Agent harness &#x2F; Agent &#x2F; Security strategy &amp; tool stack &#x2F; Workflow<p>To give some examples: I am currently using OpenCode (+DeepSeek) on Linux Mint Debian Edition (LMDE), and I notice that the Agent &amp; harness is frequently asking to create files in &#x2F;tmp&#x2F; - I usually forbid this, and instruct it to only use files in the current folder. I would rather that the tool ONLY have access to a given project folder (~&#x2F;Projects&#x2F;PROJECT-NAME) in a system-enforced way. However, I see that the agent often wants to run system commands (like `ps` to debug a local dev server, `pandoc` or `ffmpeg` for file conversion, etc). This starts blurring the line - so I&#x27;m thinking that in order for the AI agent to be useful, I can consider giving it access to an isolated operating system - leading me to think about Virtual Machines, Docker containers, and so on. That introduces complexity like, &quot;Should I be using shared folders between my system&#x2F;VM?&quot; etc.<p>Would love to hear what&#x27;s been working for you, the &quot;ideal&quot; state, and practically how we can implement it.<p>I ought to mention that I&#x27;m frequently teaching technology (including AI) to somewhat newbies - so I am trying to find that balance, that lets them get easily something done effectively, but gives them security&#x2F;integrity practices by default starting off, so they don&#x27;t get into an awful jam (&quot;The AI deleted my project&#x2F;computer!&quot;).<p>Thanks!