Abhishek Bhardwaj explains how to build Arrakis, an open-source AI sandbox service that uses microVMs for secure code execution. The presentation covers Linux sandboxing fundamentals, comparing containers vs virtualization, and details the architecture including overlay filesystems, networking setup, and snapshot/restore capabilities. MicroVMs provide better security than containers by isolating guest kernels while maintaining fast boot times under 7 seconds. The system enables AI agents to execute code safely, backtrack on failures, and handle multi-step workflows through checkpointing.

40m watch time

Sort: