SysConf 2026 · Locked
Rexec: How to Safely Give AI Agents a Terminal
Alex Idowu · Co-founder & CTO, PipeOps · Lagos
Sat 3 Oct · 12:25-12:55 WAT · Room 1 · Standard 30m
How to safely give AI agents a terminal using Rexec - isolation, limits, network, and lifecycle for disposable Linux sandboxes. Live demo.
Public deck unlocks after the session (2026-10-03). Field notes use the same speaker unlock.
Field notes (locked) · Repo · All talks
SysConf 2026 · Standard · 25 + 5
Rexec: How to Safely Give AI Agents a Terminal
Present P · Theme toggle in chrome · → ← · ?present=1 · speaker ?key=
01 · Intro
How to safely give AI agents a terminal - using Rexec
Rexec: How to Safely Give AI Agents a Terminal
Alex Idowu · PipeOps · Lagos · SysConf 2026
02 · Intro · about
Quick intro
I’m Alex Idowu - Co-founder & CTO at PipeOps, based in Lagos.
- I build platforms, sandboxes, and isolation for a living - Rexec, agents, multi-tenant Kubernetes.
- Decade-plus in cloud infra, IaC, and runtime security (gVisor, Firecracker, the messy middle).
- When I’m not in production logs: One Piece, open source for fun, and shipping small tools that scratch my own itch.
That’s enough about me - let’s talk terminals.
03 · Goals
What this talk covers
How to safely give AI agents a terminal using Rexec - and the controls that still matter if you wire your own stack.
- The problem - agent exec on your workstation, not a sandbox terminal → next
- Security & limits - isolation ladder, CPU / memory / TTL
- Reach & disposal - what the terminal can talk to, and when it dies
- Rexec build - components, then request dataflow
- Demo - create → prove → delete
Rexec is the through-line. The controls travel without it.
04 · Content · problem
Agents still get a terminal.
It just shouldn’t be your workstation.
They need to run commands - that’s the product. The shortcut is running those commands as you on a laptop, bastion, or shared runner.
This talk is not “harden your personal shell for AI.”
It’s give the agent its own disposable terminal - isolated, capped, networked on purpose, then deleted. That’s what Rexec is for.
05 · Content · security & limits
Security & limits
-
cgroup + caps - baseline Linux resource and privilege controls.
-
gVisor (
runsc) - user-space kernel; my default for agent sandboxes. -
Firecracker - microVM when you need a guest kernel / harder boundary.
-
Default Docker (
runc) - shares the host kernel; say so if that’s all you’re using. - TTL CPU / mem / PID + TTL - hard caps; thrash is a DoS on yourself. Limits = security.
Trade-off: density + no KVM → gVisor default; escalate to Firecracker when the threat model says so.
06 · Content · reach & disposal
What the terminal can reach, and when it dies
-
Shell = network endpoint - peer traffic, metadata, HTTPS, DNS, demo ports.
- NET Egress modes - none · allowlist · full (you accepted the leak).
-
ICC off - stops sandbox-to-sandbox on a Docker bridge; not “no internet.”
- TTL Lifecycle - create → short-lived secrets → run → attach → delete.
-
Long-lived sandboxes - become bastions with worse accountability.
07 · Content · components
Stack
- UI Browser / CLI - where humans and agents attach (xterm.js, API clients).
- API Control API - auth, policy, create / exec / delete, WebSocket sessions.
-
PostgreSQL - users, agents, session metadata.
-
Container Manager → Docker - disposable cloud sandboxes (limits, network, runtime).
-
Agent Handler → BYOS - outbound WebSocket to your machine; no inbound SSH.
08 · Content · dataflow
What happens when you send a request
Input → API (auth/route) → persist → Docker sandbox or BYOS agent → stream output back.
09 · Content · demo
Live: create → prove → delete
- Create sandbox (limits + network)
- Show the block
- Run something agent-shaped
- Delete
10 · Conclusion
Build the agent a terminal.
Don’t share the one you live in.
- Secrets and prod never meet an agent on your laptop
- One sandbox per task. Then delete it
- Untrusted agent code → gVisor or stronger
- Egress is a decision. DNS is data
- Hard caps + TTL. Outbound agents, not inbound SSH
No Rexec? Same controls with Kubernetes Jobs + RuntimeClass + NetworkPolicy.
11 · Resources
Resources
This talk
- Rexec - github.com/PipeOpsHQ/Rexec
- Docs - rexec.sh/docs
- Field notes - nitrocode.sh/blog/…
- Deck - nitrocode.sh/talks/sysconf-2026
Isolation & runtimes
- gVisor - gvisor.dev · github.com/google/gvisor
- Firecracker - firecracker-microvm.github.io
- runc - github.com/opencontainers/runc
- cgroup v2 - kernel docs
- capabilities - capabilities(7)
Platform building blocks
- Docker - docs.docker.com
- PostgreSQL - postgresql.org/docs
- Jobs - Kubernetes Jobs
- RuntimeClass - RuntimeClass
- NetworkPolicy - NetworkPolicy
Questions? · @nitrocode · Lagos