Nono agent sandboxing: setup and Docker comparison

Learn how Nono profiles restrict agent file access, network requests and secrets on macOS and Linux, with Windows support through WSL 2.

Player not loading? Watch on YouTube

Bret Fisher talks with Luke Hinds about Nono, an open source CLI for sandboxing processes, including a coding assistant or other AI agent. The discussion covers local use on macOS and Linux, with WSL 2 as the Windows route. Hinds describes a quickstart that pulls a profile and launches the chosen agent through Nono.

The technical explanation focuses on native kernel controls: Seatbelt on macOS and Landlock on Linux. Hinds says Nono runs without root privileges. JSON profiles can inherit a parent profile and add specific grants and denials, so teams can share restrictions while allowing access to different environments.

Hinds explains how a trusted supervisor records activity and gives the sandbox phantom tokens instead of real credentials. Policies can restrict URL paths, HTTP methods and command arguments. Examples include limiting AWS CLI requests to read operations and restricting GitHub API writes. Individual tool calls can receive their own short-lived sandbox and secret access.

The Docker comparison includes a clear limitation: Hinds says Nono provides less complete isolation than containers or microVMs and recommends combining them in production. Runtime approvals have a programmatic interface, but the demonstrated approval service is not bundled. GUI applications can work, though Electron apps and extensions make profiles more complex. The conversation also covers GitHub Actions, skill-file verification and plans to improve documentation and stability.