I wanted to give Claude Code the freedom to execute arbitrary code without giving it access to the rest of my machine.
This series is about using rootless containers to create that boundary, and understanding exactly what it does — and doesn't — protect against.
Read on for my investigation into sandboxing local coding agents with Podman.