Skip to main content
Pre-release

This release is a pre-release and may not be stable for production use.

Isag

Isag (/aɪˈzɑɡ/, "Isolated Agent") — sandboxes coding agents in containers with hard limits on what it can read, write, and reach.

Why

Isag gives the agent full freedom inside a container, while keeping your machine safe outside it. You get:

  • A filesystem scoped to what you mount. The agent sees only the directories you explicitly add. Your home directory, your SSH keys, the rest of your host — invisible.
  • Read-only mounts when you want them. Mount your project :ro to let the agent analyze without editing. Mount datasets :ro. Mount a scratch directory :rw. The kernel rejects writes to a read-only bind mount regardless of file permissions.
  • A network firewall. Outbound traffic is locked to a domain allowlist enforced at the kernel level. Anything else fails to connect — the agent can't lift the rule from inside.
  • Optional GPU passthrough. Flip one flag in the config to give the container CUDA + the NVIDIA toolkit.
  • Disposable container. Try experimental tooling without consequence — pip at runtime, system packages via extra_packages + rebuild. If something breaks, the host is untouched and Isag brings up a clean one.

Requirements

  • Linux host with Docker.
  • GPU mode needs the NVIDIA Container Toolkit.
  • Tested on Linux and WSL2. macOS (Docker Desktop / Rancher Desktop) and native Windows Docker should work but are untested.

Try it

Install:

pip install isag

Run:

isag init
isag run

You're inside the agent CLI now, in a container that can reach github.com, pypi.org, npm, and the vendor's API — and nothing else.

Expose a container service on the host's loopback. E.g., reach the container's SSH or Jupyter from your host (useful for IDEs and browsers):

isag ssh -L 2222:localhost:22 -L 8888:localhost:8888

Expose a host service to the container. E.g., give the container access to the host's adb server, and through it any devices the host can reach (USB, network, or via VPN):

isag ssh -R 5037:localhost:5037

The config file

isag init writes a starter isag.yaml. The lines you'll touch:

project: ~/code/my-project:/workspace/project:rw   # use :ro for analysis-only runs
agent:
  vendor: claude                                   # claude or codex
  cli_flags: null                                  # extra arguments, e.g. ["--model", "my-model"]
  share_vendor_homes: false                        # true also mounts existing other vendor folders read-write
  host_home: ~/agents                              # vendors persist here as host_home/.claude, host_home/.codex; set to ~ to share history + credentials with your host install
container:
  python: 3.14                                     # container system-wide Python
  image: ubuntu24.04                               # or e.g. nvidia/cuda:12.8.1-runtime-ubuntu24.04 if gpu:true
  gpu: false                                       # true for CUDA + NVIDIA toolkit
  host_cache_dir: ~/isag-cache                     # mounting pip, npm, and other caches          
limit_network:
  domains:                                         # everything else is blocked
    - github.com
    - pypi.org
    - registry.npmjs.org
mounts:
  - ~/datasets:/workspace/datasets:ro              # add more mounts; :ro makes them read-only
exclude:                                           # hide paths inside any mount (set to null to disable)
  files:
    - .env
  folders:
    - .git
  • agent.cli_flags and agent.share_vendor_homes are required; add both to existing configs. Flags are appended after the YOLO flag; null or [] adds nothing.
  • Set limit_network: null to turn the firewall off entirely. Useful on trusted networks; not the default for a reason.
  • Excluded paths are host paths; if they fall under project or any mounts entry, the corresponding container path is overlaid with an empty mount.
  • Both absolute and relative paths on the host are permitted for all fields. If a field path is relative, it is resolved relative to the project host path. If the project host path is also relative, it is first resolved relative to the YAML file path.
  • Command isag run displays the cache directory. Open it to view the files and commands used to run the project.

What it doesn't protect

  • Anything you mount writable — the agent has full access there.
  • Sibling containers, if you opt into external_networks.
  • Anything the agent can do at an allowlisted endpoint with credentials you gave it.

License

Apache-2.0.

Metadata

Release files for isag 0.5.0a1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for isag 0.5.0a1
File Size Uploaded
isag-0.5.0a1.tar.gz 28.1 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for isag 0.5.0a1
File Interpreter ABI Platform
isag-0.5.0a1-py3-none-any.whl Python 3 none any Details

Total release size: 59.3 kB

Release files / isag-0.5.0a1.tar.gz

Download URL isag-0.5.0a1.tar.gz
Size 28.1 kB
Tags Source
SHA-256 checksum
How to use checksums
12ad5718b49abb8a2903f33aa85382c5457c6cb9f923c5f57f0aa336102e9244
BLAKE2b-256 checksum
How to use checksums
3571f0b770ec3552d909890303cc41c583b76dc66b8b55976ca2f2af4e789a2a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.13

Release files / isag-0.5.0a1-py3-none-any.whl

Download URL isag-0.5.0a1-py3-none-any.whl
Size 31.2 kB
Tags Python 3
SHA-256 checksum
How to use checksums
831fa86cdeb0e959284ee9c548ee8f31ec6e46b2a1e29a203f97796da8b06327
BLAKE2b-256 checksum
How to use checksums
7604143615306ddcd3765e74b0a3af386bfc39e556a0ffbf647b4e41871463a9
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.13
Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page