Posted by steveybrown 5 days ago
As a fallback I have qwen3.8 27B and deepseek-flash
I do this for a lot of things actually. If the bot can't see/read something, take the content and dump it to a file, then have the bot read that.
Gets around a lot of red tape of asking for approval for "integrations" or when companies are snippy.
And if there were a dimension of day-job v personal use, I'd be even happier
Does anyone know if such a thing exists
Only layer beyond this I want is the permission scoping, stronger sandboxing per session and centralized control. I have not seen a clean product around this though where I own the compute.
Works like Claude code but with stronger guarantees for me on file system and network access. Still playing around with it, but so far I've been liking the setup.
I still run the sandbox inside a VM for now, but I feel far more comfortable in running Claude Code in unsupervised mode because I restrict the outbound network access and secrets never hit inside the sandbox.
I was wondering if other employers are asking their SWE to do the same?
I also pretty much exclusively work at my desktop - if you use multiple systems I can see where this matters.
I do work mainly on my desktop, but let's say I'm traveling right, I'd have to turn it off and was missing access to some pretty important information, so I ended up getting a VM and hosting some of those things on there instead. I still use both, but things I want available, I'll host it on my "homelab" and secure both machines via tailscale. it's pretty easy and it ensures that only my phone, my main mac, and my homelab have access to each other and nothing else.
For my phone I have tailscale + https://termrover.sh/, but https://getmoshi.app/ is also pretty good (herdr integration is paywalled).
Thank you for putting this together!
Here’s my setup: https://mysetup.ai/u/katspaugh
Mostly vanilla Claude but inside a VM.