Skip to content
All projects
Local AI / Infra2026

Proxmox LXC AI Agent Sandbox

A native Rust orchestration platform and 10-tab terminal control center for running, benchmarking, and coordinating autonomous AI coding agents inside isolated Proxmox LXC containers.

RustLocal AIAI AgentsMulti-Agent SystemsProxmox VELXC ContainersSecurityTerminal UIDeveloper ToolsSelf-Hosted

Project Brief

Role
Solo systems engineer and tool builder
Scope
A Rust-native multi-agent orchestration platform and 10-tab terminal control center for running, benchmarking, and coordinating autonomous AI coding agents across isolated Proxmox LXC containers
Timeline
Originally built in 2026 as a Python single-agent sandbox; rewritten in Rust and extended with swarm orchestration, arena benchmarking, and a security shield later the same year
Result
A tested (565/565 passing), sub-20ms-startup orchestration platform running parallel multi-agent swarms, competitive agent benchmarking, and automated security auditing on top of the original isolation and rollback guarantees

Evidence Included

  • Automated test suite passing clean

    565 of 565 automated CLI tests pass, alongside a full latency/throughput benchmark suite (config engine, path resolution, network probing, swarm consensus, reverse-proxy generation) — verified on a live run, not assumed from a stale badge.

  • Sub-20ms native startup

    Measured `--help` at 15.05ms and `--version` at 11.61ms against a 100–120ms target, following the rewrite from Python curses to a native Rust binary.

  • Hardware-isolated sandbox boundary

    Autonomous coding agents execute inside unprivileged LXC containers on a dedicated Proxmox VE node, keeping untrusted agent scripts off the primary workstation.

  • Zero credentials stored at rest

    Provider API keys are passed directly into ephemeral SSH process memory at command launch and never written to container configuration or persistent disk storage.

15.05ms (--help)

CLI startup

12+ Coding Agents

Agent registry

10 Visual Tabs

TUI Dashboard

Zero Keys on Disk

Secret Hygiene

Interactive System Architecture

Proxmox LXC AI Agent Sandbox Architecture

Host WorkstationLinux / macOS

Developer Client

User machine where source code lives and commands are initiated.

CLI Runner & Sync Engine

sandbox & sandboxer executable

10-Tab Ratatui TUI

Native Rust control dashboard with 10 color palettes

In-Memory Secret Harvester

Zero API keys on disk; passes envs over SSH

Desktop Integration

Global hotkey <Super><Alt>S + Ghostty launch

$ sandbox swarm start --mission "..."
Secure TransportEncrypted LAN / SSH

Tunnel & Sync Bus

Bi-directional sync and port forwarding layer over keyed SSH.

Smart rsync Sync

Ignores .git, node_modules, .venv, caches

5 Port Reverse Tunnels

3000, 5173, 8000, 8080, 8888 → localhost

Ed25519 Key Auth

Strict keyless pairing wizard with host checks

Diff & Review Guard

Colorized terminal diffs before pulling

SSH Port Tunnels + rsync Stream
Proxmox NodeProxmox VE (LXC)

Isolated LXC Container

Unprivileged Linux container housing tools and agent execution.

AI Coding Agent Registry

12+ agents (Pi, OpenCode, Claude Code, Aider...), Docker CE

Swarm & Arena Engine

Parallel/pipeline/debate missions, benchmark leaderboards

Time Machine Snapshots

Pre/post task checkpoints + instant rollback

Multi-Node Cluster & Cloning

Live migration, quorum status, fast LXC cloning

~/workspace/ · Isolated Execution
Core Security & Architectural Guarantees
Air-Gapped Workstation

Uncontrolled agent file edits, runaway loops, or destructive scripts run strictly inside the LXC container.

Zero Secrets Stored

Local environment variables are passed directly into ephemeral SSH process memory without saving keys to disk.

1-Command Rollback

Workspace state is check-pointed before task execution, enabling instant restoration without messing up git history.

Core: Native Rust (Tokio) · OS: Proxmox VE · Runtime: LXC565 / 565 tests passing

What began as a Python curses tool for running one AI coding agent in one isolated container has grown into a full Rust orchestration platform for a fleet of them. The CLI (sandbox) and its companion Ratatui terminal dashboard (sandbox-tui) still isolate every agent execution inside an unprivileged LXC container on a dedicated Proxmox VE node, with the same zero-credentials-at-rest secret handling and instant workspace rollback the original version had — but the platform now also coordinates multiple agents at once. A swarm coordinator runs parallel, pipelined, or debate-style multi-agent missions across specialized roles (Architect, Developer, Tester, Reviewer) with a live task-dependency graph; an arena mode benchmarks competing coding agents against identical prompts and tracks win-rate leaderboards; a workflow engine chains sync → agent → test → auto-repair → sync pipelines end to end; and a security shield audits container isolation (namespaces, AppArmor, port bindings, key permissions) with a letter-grade score. The rewrite also picked up multi-node Proxmox cluster topology and live container migration, a persistent vector-indexed context store over the workspace and commit history, and a 565-test automated suite that runs clean on every change.

Highlights

  • Rewritten from a Python curses tool into a native Rust core (tokio, clap, serde, crossterm) — CLI startup dropped to single-digit milliseconds, verified live at 15.05ms for `--help` and 11.61ms for `--version` against a 100–120ms budget
  • Multi-agent swarm orchestration — parallel, pipelined, and debate-style missions across specialized agent roles (Architect, Developer, Tester, Reviewer) with a live task-dependency graph and real-time dialogue/tool-call streaming
  • Automated workflow pipelines chaining multi-stage runs (sync → agent execution → test suite → auto-repair → sync back) with dry-run simulation before committing to a live run
  • Multi-agent arena and leaderboards — benchmarks 12+ supported coding agents (Pi, OpenCode, Claude Code, Aider, Goose, Codex CLI, Open Interpreter, Cline, and others) against identical task prompts with automated scoring and win-rate tracking
  • Container security shield — an audit engine that checks user namespaces, AppArmor confinement, loopback port bindings, and authorized-key permissions, then scores the result (A+ down to failing) with concrete remediation steps
  • 10-tab Ratatui control center (LXC, Agents, Ports, Processes, Health, Fleet, Vault, Logs, Swarm, Review) with 10 switchable color palettes, replacing the original 6-tab curses dashboard
  • Still zero credentials at rest: provider API keys are harvested locally and forwarded only into ephemeral SSH session memory, never written to container disk or config files
  • Dual-layer Time Machine — instant hardlink workspace checkpoints for fast rollback, plus full Proxmox LXC block-level snapshots for host-level disaster recovery
  • Persistent, vector-indexed context memory — indexes workspace source files, commit history, and logs into a local store for semantic retrieval across agent sessions
  • Multi-node Proxmox cluster support — container topology listing, live migration between nodes, and quorum status reporting, extending the platform beyond a single host
  • Verified 565/565 automated CLI tests plus a full latency/throughput benchmark suite passing clean (57.4s wall time on the current run), covering config engine, path resolution, network probing, swarm consensus, and the reverse-proxy config generator

Architecture & Infrastructure

01

Native Rust Core & Ratatui Control Center

The CLI and TUI are a single native Rust binary pair built on tokio, clap, serde, and crossterm, replacing the original Python implementation. Startup latency is sub-20ms end to end, and the 10-tab Ratatui dashboard renders idle frames in well under a millisecond.

02

Proxmox LXC Hardware Isolation Boundary

Proxmox VE hosts isolated, unprivileged Linux Container (LXC) instances. Every agent execution, file system write, and shell command runs strictly inside a container boundary, air-gapping the developer's primary workstation from uncontrolled agent behavior.

03

Multi-Agent Swarm Coordinator

A dedicated swarm engine schedules parallel, pipelined, or debate-format multi-agent missions across specialized roles, tracking task dependencies as a live graph and streaming each agent's dialogue and tool calls back to the dashboard in real time.

04

Container Security Shield

An audit engine inspects user-namespace configuration, AppArmor profile enforcement, loopback port exposure, and authorized-key permissions on every managed container, producing a scored report (A+ through failing) rather than a pass/fail check.

05

Ephemeral In-Memory Secret Injection

Provider API keys are gathered from the local environment and injected as ephemeral exports directly into SSH process memory per invocation — never persisted to container disk, config files, or shell profiles.

06

Dual-Layer Time Machine & Disaster Recovery

Instant hardlink checkpoints provide fast workspace-level rollback for everyday agent mistakes; full Proxmox vzdump block snapshots provide complete container-level disaster recovery when something goes wrong at the host level.

Stack

RustRatatuiTokioProxmox VELinux LXCSSH / Ed25519rsyncDocker CE