yeetyeet
docs
articles
blogtopical takes
pricingaboutcareers
Login / RegisterBook a demo

Topical Takes

Short, opinionated posts on eBPF, Linux internals, and the tools we all run in production.

AlleBPF7linux6observability4yeet3HTTP2kubernetes2networking2tcpdump2802.111AI agents1ai-sre1Cilium1integration-testing1rf1root-cause-analysis1security1uprobes1websocket1wifi1wireless1wss1+21 more
AlleBPF7linux6observability4yeet3HTTP2kubernetes2networking2tcpdump2802.111AI agents1ai-sre1Cilium1integration-testing1rf1root-cause-analysis1security1uprobes1websocket1wifi1wireless1wss1
August 20, 2026

How to Sandbox an AI Coding Agent on Linux in 2026: What the Kernel Can Refuse That Permissions Only Ask About

Claude Code, Codex, Aider and self-hosted agents run with your full filesystem access and choose what to read on their own — here are the six real ways to confine one, what each actually covers, and why the built-in sandboxes govern shell commands rather than the agent's own file reads.

eBPFlinuxsecurityAI agents
Read more →
FECM

yeet

Made in Chicago with ❤️

JavaScript at the kernel boundary. Build the tool you need, run it in seconds.

★768

© 2026 Virt Inc.

Product

DocsBlogTopical Takes

Company

Contact usTermsPrivacy