Gondolin

Local AI agent sandbox runs Linux micro-VMs on macOS and Linux, with programmable file access and secret handling. Open source under Apache 2.0.

Screenshot of Gondolin website

Gondolin is a local sandbox for developers whose AI agents execute generated code and need access to files or external APIs. It runs that code inside disposable Linux micro-VMs on macOS or Linux, while the host controls network access, credentials and filesystem behavior. It's open source under Apache 2.0.

Its secret handling lets an agent call an authenticated API without receiving the real credential. The guest sees a placeholder token; the host substitutes the secret only for allowed destinations. HTTP and TLS policies can restrict outgoing requests and apply request or response hooks. Calls to external APIs still leave the machine through the permitted connections.

The network stack and virtual filesystem are implemented in JavaScript, so developers can define access policies and custom filesystem behavior in the same language as their agent tooling. QEMU is the default VM backend. A CLI and TypeScript SDK support command execution, shell access to running VMs and host-driven file operations. A Pi extension runs Pi tools inside a micro-VM with the project mounted into the guest.

For workloads that need more than a disposable shell, Gondolin supports disk checkpoints with resume, custom guest images and exposing guest HTTP services on the host. SSH provides access to the guest, with optional allowlisted outgoing SSH connections.

Similar to Gondolin