Proxmox LXC AI Agent Sandbox
A native Rust orchestration platform and 10-tab terminal control center for running, benchmarking, and coordinating autonomous AI coding agents inside isolated Proxmox LXC containers.
Project Brief
- Role
- Solo systems engineer and tool builder
- Scope
- A Rust-native multi-agent orchestration platform and 10-tab terminal control center for running, benchmarking, and coordinating autonomous AI coding agents across isolated Proxmox LXC containers
- Timeline
- Originally built in 2026 as a Python single-agent sandbox; rewritten in Rust and extended with swarm orchestration, arena benchmarking, and a security shield later the same year
- Result
- A tested (565/565 passing), sub-20ms-startup orchestration platform running parallel multi-agent swarms, competitive agent benchmarking, and automated security auditing on top of the original isolation and rollback guarantees
Evidence Included
Automated test suite passing clean
565 of 565 automated CLI tests pass, alongside a full latency/throughput benchmark suite (config engine, path resolution, network probing, swarm consensus, reverse-proxy generation) — verified on a live run, not assumed from a stale badge.
Sub-20ms native startup
Measured `--help` at 15.05ms and `--version` at 11.61ms against a 100–120ms target, following the rewrite from Python curses to a native Rust binary.
Hardware-isolated sandbox boundary
Autonomous coding agents execute inside unprivileged LXC containers on a dedicated Proxmox VE node, keeping untrusted agent scripts off the primary workstation.
Zero credentials stored at rest
Provider API keys are passed directly into ephemeral SSH process memory at command launch and never written to container configuration or persistent disk storage.
15.05ms (--help)
CLI startup
12+ Coding Agents
Agent registry
10 Visual Tabs
TUI Dashboard
Zero Keys on Disk
Secret Hygiene
Interactive System Architecture
Proxmox LXC AI Agent Sandbox Architecture
Developer Client
User machine where source code lives and commands are initiated.
CLI Runner & Sync Engine
sandbox & sandboxer executable
10-Tab Ratatui TUI
Native Rust control dashboard with 10 color palettes
In-Memory Secret Harvester
Zero API keys on disk; passes envs over SSH
Desktop Integration
Global hotkey <Super><Alt>S + Ghostty launch
Tunnel & Sync Bus
Bi-directional sync and port forwarding layer over keyed SSH.
Smart rsync Sync
Ignores .git, node_modules, .venv, caches
5 Port Reverse Tunnels
3000, 5173, 8000, 8080, 8888 → localhost
Ed25519 Key Auth
Strict keyless pairing wizard with host checks
Diff & Review Guard
Colorized terminal diffs before pulling
Isolated LXC Container
Unprivileged Linux container housing tools and agent execution.
AI Coding Agent Registry
12+ agents (Pi, OpenCode, Claude Code, Aider...), Docker CE
Swarm & Arena Engine
Parallel/pipeline/debate missions, benchmark leaderboards
Time Machine Snapshots
Pre/post task checkpoints + instant rollback
Multi-Node Cluster & Cloning
Live migration, quorum status, fast LXC cloning
Core Security & Architectural Guarantees
Uncontrolled agent file edits, runaway loops, or destructive scripts run strictly inside the LXC container.
Local environment variables are passed directly into ephemeral SSH process memory without saving keys to disk.
Workspace state is check-pointed before task execution, enabling instant restoration without messing up git history.
What began as a Python curses tool for running one AI coding agent in one isolated container has grown into a full Rust orchestration platform for a fleet of them. The CLI (sandbox) and its companion Ratatui terminal dashboard (sandbox-tui) still isolate every agent execution inside an unprivileged LXC container on a dedicated Proxmox VE node, with the same zero-credentials-at-rest secret handling and instant workspace rollback the original version had — but the platform now also coordinates multiple agents at once. A swarm coordinator runs parallel, pipelined, or debate-style multi-agent missions across specialized roles (Architect, Developer, Tester, Reviewer) with a live task-dependency graph; an arena mode benchmarks competing coding agents against identical prompts and tracks win-rate leaderboards; a workflow engine chains sync → agent → test → auto-repair → sync pipelines end to end; and a security shield audits container isolation (namespaces, AppArmor, port bindings, key permissions) with a letter-grade score. The rewrite also picked up multi-node Proxmox cluster topology and live container migration, a persistent vector-indexed context store over the workspace and commit history, and a 565-test automated suite that runs clean on every change.
Highlights
- Rewritten from a Python curses tool into a native Rust core (tokio, clap, serde, crossterm) — CLI startup dropped to single-digit milliseconds, verified live at 15.05ms for `--help` and 11.61ms for `--version` against a 100–120ms budget
- Multi-agent swarm orchestration — parallel, pipelined, and debate-style missions across specialized agent roles (Architect, Developer, Tester, Reviewer) with a live task-dependency graph and real-time dialogue/tool-call streaming
- Automated workflow pipelines chaining multi-stage runs (sync → agent execution → test suite → auto-repair → sync back) with dry-run simulation before committing to a live run
- Multi-agent arena and leaderboards — benchmarks 12+ supported coding agents (Pi, OpenCode, Claude Code, Aider, Goose, Codex CLI, Open Interpreter, Cline, and others) against identical task prompts with automated scoring and win-rate tracking
- Container security shield — an audit engine that checks user namespaces, AppArmor confinement, loopback port bindings, and authorized-key permissions, then scores the result (A+ down to failing) with concrete remediation steps
- 10-tab Ratatui control center (LXC, Agents, Ports, Processes, Health, Fleet, Vault, Logs, Swarm, Review) with 10 switchable color palettes, replacing the original 6-tab curses dashboard
- Still zero credentials at rest: provider API keys are harvested locally and forwarded only into ephemeral SSH session memory, never written to container disk or config files
- Dual-layer Time Machine — instant hardlink workspace checkpoints for fast rollback, plus full Proxmox LXC block-level snapshots for host-level disaster recovery
- Persistent, vector-indexed context memory — indexes workspace source files, commit history, and logs into a local store for semantic retrieval across agent sessions
- Multi-node Proxmox cluster support — container topology listing, live migration between nodes, and quorum status reporting, extending the platform beyond a single host
- Verified 565/565 automated CLI tests plus a full latency/throughput benchmark suite passing clean (57.4s wall time on the current run), covering config engine, path resolution, network probing, swarm consensus, and the reverse-proxy config generator
Architecture & Infrastructure
Native Rust Core & Ratatui Control Center
The CLI and TUI are a single native Rust binary pair built on tokio, clap, serde, and crossterm, replacing the original Python implementation. Startup latency is sub-20ms end to end, and the 10-tab Ratatui dashboard renders idle frames in well under a millisecond.
Proxmox LXC Hardware Isolation Boundary
Proxmox VE hosts isolated, unprivileged Linux Container (LXC) instances. Every agent execution, file system write, and shell command runs strictly inside a container boundary, air-gapping the developer's primary workstation from uncontrolled agent behavior.
Multi-Agent Swarm Coordinator
A dedicated swarm engine schedules parallel, pipelined, or debate-format multi-agent missions across specialized roles, tracking task dependencies as a live graph and streaming each agent's dialogue and tool calls back to the dashboard in real time.
Container Security Shield
An audit engine inspects user-namespace configuration, AppArmor profile enforcement, loopback port exposure, and authorized-key permissions on every managed container, producing a scored report (A+ through failing) rather than a pass/fail check.
Ephemeral In-Memory Secret Injection
Provider API keys are gathered from the local environment and injected as ephemeral exports directly into SSH process memory per invocation — never persisted to container disk, config files, or shell profiles.
Dual-Layer Time Machine & Disaster Recovery
Instant hardlink checkpoints provide fast workspace-level rollback for everyday agent mistakes; full Proxmox vzdump block snapshots provide complete container-level disaster recovery when something goes wrong at the host level.