Posts
All the articles I've posted.
Can Docker Safely Run AI Agents? Containers vs. MicroVMs
Updated:Docker protects trusted workloads, but containers share the host kernel. Compare Docker and microVM boundaries for untrusted AI agent code.
NVIDIA OpenShell vs SmolVM: Two Approaches to Secure AI Agent Sandboxes
Compare NVIDIA OpenShell and Celesto SmolVM across isolation, security policies, microVMs, Windows support, browser automation, snapshots, and agent workloads.
How to Run Pi Coding Agent on a Celesto Cloud Computer
Keep Pi and your model credentials local while its coding tools run in an isolated Celesto cloud workspace, then safely sync the changes back.
Firecracker on macOS: Develop with QEMU, Deploy with Firecracker
Firecracker does not run natively on macOS. Learn how to develop with SmolVM and QEMU on a Mac, then switch to Firecracker on Linux with one backend flag.