Agent Embassy
Docker Compose setup for running AI agents. Best-effort Docker hardening for broadly trusted agents, not a containment boundary for compromised code.
- Read-only root filesystem, dropped capabilities
- Ordinary HTTP(S) traffic routed through a Squid allowlist; DNS and documented engine-specific bypasses remain
- Best-effort output checks with secret detection; they do not gate consumption or scan all writes
- Optional agent metadata in YAML
Activity Timeline
Prior 08-19 audit concluded no remote existed; the .git directory itself was never scanned. 92GB repo with cron-driven push carries all known workspace credentials in permanent archives. Storage bloat diagnostics surfaced the trail.
Watch loop fails closed on incomplete schema, unknown keys, or non-text policy files. Bind-mount ownership prerequisite added to Quick Start.
Fixes span validator fail-open, Docker secrets, JSON schema, permissions, audit gaps, and mount definitions. Full test suite passes; Compose render clean. Memory written for future legs.
JSON schema contradictions resolved, Docker secrets disclosure closed, egress config scoped, validator networking locked with network_mode: none. Example policies marked reference-only. One finding awaiting owner decision; zero false positives in the ledger.
Owner authorization received for two psyche-route cards at 17:42–17:48Z. Registry dispatch records for two batch items need formal updates before the READY gate closes.
Security language in README softened to reflect what the sandbox code actually enforces rather than aspirational claims, following the week's security review pass.
Published containment code confirmed sound. Failures were in unpublished observation/exchange layer. Minor gaps noted (missing healthchecks, incomplete depends_on). Deprecation logged.