Ask HN:AI 代理与容器化/安全性的建议
2 分•作者: dv35z•3 个月前
各位 HN 的朋友们:
我注意到一种趋势,人们允许 AI 代理访问本地项目和用户文件夹,甚至更广泛的操作系统文件。
因此,我想提出一个问题:
我们如何才能安全地使用 AI 工具,同时保护我们系统和数据的完整性,并且足够易于高效使用?尤其是在工作流程经常涉及本地系统命令和网络命令的情况下。
评论结构建议:
操作系统 / 代理容器 / 代理 / 安全策略与工具栈 / 工作流程
举个例子:我目前在 Linux Mint Debian Edition (LMDE) 上使用 OpenCode(配合 DeepSeek),我注意到代理和容器经常请求在 `/tmp/` 目录下创建文件。我通常会禁止这样做,并指示它只使用当前文件夹中的文件。我更希望该工具能够通过系统强制的方式,仅访问指定的项目文件夹(`~/Projects/PROJECT-NAME`)。然而,我发现代理经常需要运行系统命令(例如,使用 `ps` 调试本地开发服务器,使用 `pandoc` 或 `ffmpeg` 进行文件转换等)。这开始模糊界限——所以我认为,为了让 AI 代理有用,我可以考虑给予它访问一个隔离操作系统的权限,这让我联想到虚拟机、Docker 容器等。但这又引入了复杂性,例如“我是否应该在我的系统/虚拟机之间使用共享文件夹?”等等。
我很想听听大家有哪些行之有效的方法,“理想”状态是什么样的,以及我们如何实际实现它。
我需要提到的是,我经常向一些技术新手(包括 AI)授课,所以我正在努力寻找一个平衡点,既能让他们轻松有效地完成工作,又能默认让他们掌握安全/完整性实践,以免他们陷入糟糕的境地(“AI 删除了我的项目/电脑!”)。
谢谢!
查看原文
Hello HN crew -<p>I am seeing the tendency for people to allow AI agents to access local project & user folders, and beyond (operating system files).<p>I thought to ask the question:
How can we best use AI tools safely - where the workflow often runs local system commands and network commands - to protect the integrity of our systems & data AND be easy enough to use productively?<p>Comment structure idea:<p>Operating system / Agent harness / Agent / Security strategy & tool stack / Workflow<p>To give some examples: I am currently using OpenCode (+DeepSeek) on Linux Mint Debian Edition (LMDE), and I notice that the Agent & harness is frequently asking to create files in /tmp/ - I usually forbid this, and instruct it to only use files in the current folder. I would rather that the tool ONLY have access to a given project folder (~/Projects/PROJECT-NAME) in a system-enforced way. However, I see that the agent often wants to run system commands (like `ps` to debug a local dev server, `pandoc` or `ffmpeg` for file conversion, etc). This starts blurring the line - so I'm thinking that in order for the AI agent to be useful, I can consider giving it access to an isolated operating system - leading me to think about Virtual Machines, Docker containers, and so on. That introduces complexity like, "Should I be using shared folders between my system/VM?" etc.<p>Would love to hear what's been working for you, the "ideal" state, and practically how we can implement it.<p>I ought to mention that I'm frequently teaching technology (including AI) to somewhat newbies - so I am trying to find that balance, that lets them get easily something done effectively, but gives them security/integrity practices by default starting off, so they don't get into an awful jam ("The AI deleted my project/computer!").<p>Thanks!