Show HN: Pi pod – Run your pi coding agent in sandboxes on your own server
----
Since moving my company towards AI-native work, I have been really frustrated by the state of "agentic engineering" environments. Products by the labs (claude code, codex) lock you into a single provider for your tokens. Agnostic solutions (factory, devin, arguably cursor) make you pay per-token costs. None of these products allow you to fully customize the harness, and of course they all run on someone else's infrastructure.
I've been an early and fervent user of pi, which I think is fantastically simple and beautiful software. I have felt it needs an environment for it to work across platforms with fully functional composability for teams.
This is very much a work in progress, but for my team this has been a much needed solution and has helped us tremendously. I hope you will give it a try and let me know how you would like it to improve.
- ulimn - 9927 sekunder sedanI'll be sure to check this out but in the meantime, I'd like to ask: Isn't it generally a good practice to run coding agents in a VM? It provides a security boundary so that the agent is restricted to the VM.
How does this compare? I see it's an "isolated sandbox", but what exactly does that mean?
- embik - 13147 sekunder sedanNote: this does not appear to be a Kubernetes-based solution, the "pod" part just heavily sounds like it.
- ineptech - 96931 sekunder sedanHi, I think I might be your target audience, I currently run pi on the server in my basement, in a minimalist docker container that gives it access to my code workspace and a config dir. Give me an idea what benefit I get on top of that by using the self-hosted pi pod?
- fallinditch - 11202 sekunder sedanInteresting, thanks, will keep an eye on this
- eranation - 8274 sekunder sedanDaily reminder that containers are not considered a safe security boundary, and never were. If you really need to run untrusted code, use a MicroVM.
- lowbloodsugar - 9410 sekunder sedanThe barrier to create this myself is so low that 1: I can do it and 2: bad actors can do it. I’d like to use a shared tool that will get iterated on, but I just don’t want to risk it at this point given I can get “good enough” doing it myself.
- Bombthecat - 7487 sekunder sedanI did that with T3 code.
- tamimio - 12511 sekunder sedanIs it different than running any harness in an lxc container or vm in your proxmox (or any) server?
- karakanb - 10577 sekunder sedanHi there, creator of Epho here (https://epho.io).
This looks very interesting, letting people run these in any box they own. I very much agree with the sentiment that there are no proper tools that let you run any coding agent without being locked to a single provider. I just want to run opencode or pi somewhere in a box without having to spin up all of them in my machine, let alone being able to trigger them from within another prouduct as a background agent.
Would pi-pod allow me to standardize pi config on a team/project level so that other people in my org can also use them on the same private infra?
- nezhar - 9706 sekunder sedanHi, creator of VibePod here (https://github.com/VibePod/vibepod-cli)
I spent lots of time on this topic, and had a similar path. Meanwhile the tool also supports a quick way to add custom or local providers to agents: https://vibepod.dev/news/vibepod-cli-0-24/
- shurshilov - 8091 sekunder sedan[flagged]
- jhlee525 - 58238 sekunder sedan[flagged]
- IndiaInfraNotes - 97740 sekunder sedan[flagged]
Nördnytt! 🤓