Sidecars:沙箱的低延迟信任边界|Modal 博客

Modal Blog ·

奥利维亚·约翰斯顿(Olivia Johnston)介绍了 Modal Sidecars——一种与主沙箱并行运行的隔离容器。她探讨了针对智能体生成代码的信任边界,报告了在所述对比中跨边界通信速度更快,并解释了将智能体运行时环境(agent harness)及其工具调用(tool calls)共同托管所带来的风险。 阅读 3 条观点,查看支持证据与原始来源。

理解这篇

3 个要点

综合解读

  1. 现有隔离机制采用过时的信任单元

    约翰斯顿指出,gVisor 和 Firecracker 等技术可将平台与用户彼此隔离、用户之间彼此隔离。她称这种信任单元已过时,并提出疑问:如何保护用户免受其‘自身’代码的侵害?

    支持这项说法 1

    诸如 gVisor 和 Firecracker 之类的技术在近八年前就“解决”了“隔离”问题。但对我们而言不幸的是,它们所解决的是一种如今已过时的信任单元的问题。你该如何保护用户免受其“自己”代码的影响?

    Olivia Johnston · 段落 1

    原始摘录
    technologies like gVisor and Firecracker “solved” “isolation” nearly eight years ago. Unfortunately for us, they solved it for an now-outdated unit of trust. How do you protect users from their “own” code?
    上下文

    在 Modal,我们的客户依赖 Sandbox 来执行由其下游用户编写的、或者如今几乎完全由智能体编写的不受信任的代码。运行不受信任的代码并不是一个新问题:每家云提供商都必须从第 1 天起就这样做,以便将其平台与用户隔离开来,并将用户彼此隔离。幸运的是,

    原始上下文

    At Modal, our customers rely on Sandboxes to execute untrusted code written by their downstream users or, almost exclusively now, by agents. Running untrusted code isn’t a new problem: every cloud provider has to do this from day 1 to isolate their platform from their user and their users from each other. Fortunately,

    回到原文语境 →
  2. Sidecars 在所述对比中实现快 3 倍的跨信任边界通信

    约翰斯顿将 Sidecars 描述为与主沙箱在同一主机上并行运行的隔离容器。她报告称,在所述对比中,跨信任边界的通信速度比使用独立沙箱快 3 倍,尤其适用于操作密集型工作负载。

    支持这项说法 1

    Sidecars 可实现比使用独立沙箱快 3 倍的跨信任边界通信——这对操作密集型工作负载尤为有利。

    Olivia Johnston · 段落 2

    原始摘录
    Sidecars enable 3x faster communication across trust boundaries than using separate Sandboxes — which is particularly helpful for operation-heavy workloads.
    上下文

    今天我们很高兴推出 Sidecars,这是我们在更广范围内应对该问题的方案。Sidecars 是与您的主沙箱在同一主机上并行运行的隔离容器,可在可信或不可信代码之间提供真实的安全边界。

    原始上下文

    Today we’re excited to introduce Sidecars, which are our broader answer to this problem. Sidecars are isolated containers that run alongside your main Sandbox on the same host and provide a real security boundary between trusted or untrusted code.

    回到原文语境 →
  3. 智能体 harness 位于同一 Sandbox 中构成致命三角

    Johnston 引用了 Simon Willison 的“致命三角”:访问私有数据、暴露于不受信任的内容以及对外通信的能力,这三者可能让被欺骗的智能体泄露数据。她表示,一个其 harness 在自身 Sandbox 中运行的编码智能体默认就同时具备这三项条件。

    支持这项说法 1

    西蒙·威利森(Simon Willison)将其称为“致命三重组合”:一个能够访问私有数据、接触不可信内容,并具备对外通信能力的智能体,可能被诱骗而泄露该数据。一个运行于沙箱(Sandbox)中的编码智能体,其执行环境(harness)默认即同时具备这三种特性。

    Olivia Johnston · 段落 8

    原始摘录
    Simon Willison calls it the lethal trifecta : an agent with access to private data, exposure to untrusted content, and the ability to communicate externally can be tricked into leaking that data. A coding agent whose harness runs in its Sandbox has all three by default.
    上下文

    将执行环境(harness)与工具调用(tool calls)共同托管存在安全风险:执行环境的凭据与生成的代码并置;智能体可从网络(例如软件包和代码仓库)读取不可信内容;且沙箱内任何内容均可发起网络请求。

    原始上下文

    Hosting the harness and the tool calls together is a security risk. The harness's credentials sit next to generated code, the agent can read untrusted content from the web, like packages and repos, and anything in the Sandbox can make network calls..

    回到原文语境 →

关键段落3

带明确归属与语境的原文片段。打开原始文本核查出处。

性能与安全权衡

Sidecars 在所述对比中实现快 3 倍的跨信任边界通信

Sidecars 可实现比使用独立沙箱快 3 倍的跨信任边界通信——这对操作密集型工作负载尤为有利。

原始摘录
Sidecars enable 3x faster communication across trust boundaries than using separate Sandboxes — which is particularly helpful for operation-heavy workloads.
上下文

今天我们很高兴推出 Sidecars,这是我们在更广范围内应对该问题的方案。Sidecars 是与您的主沙箱在同一主机上并行运行的隔离容器,可在可信或不可信代码之间提供真实的安全边界。

原始上下文

Today we’re excited to introduce Sidecars, which are our broader answer to this problem. Sidecars are isolated containers that run alongside your main Sandbox on the same host and provide a real security boundary between trusted or untrusted code.

信任边界设计

现有隔离机制采用过时的信任单元

诸如 gVisor 和 Firecracker 之类的技术在近八年前就“解决”了“隔离”问题。但对我们而言不幸的是,它们所解决的是一种如今已过时的信任单元的问题。你该如何保护用户免受其“自己”代码的影响?

原始摘录
technologies like gVisor and Firecracker “solved” “isolation” nearly eight years ago. Unfortunately for us, they solved it for an now-outdated unit of trust. How do you protect users from their “own” code?
上下文

在 Modal,我们的客户依赖 Sandbox 来执行由其下游用户编写的、或者如今几乎完全由智能体编写的不受信任的代码。运行不受信任的代码并不是一个新问题:每家云提供商都必须从第 1 天起就这样做,以便将其平台与用户隔离开来,并将用户彼此隔离。幸运的是,

原始上下文

At Modal, our customers rely on Sandboxes to execute untrusted code written by their downstream users or, almost exclusively now, by agents. Running untrusted code isn’t a new problem: every cloud provider has to do this from day 1 to isolate their platform from their user and their users from each other. Fortunately,

智能体安全风险

智能体 harness 位于同一 Sandbox 中构成致命三角

西蒙·威利森(Simon Willison)将其称为“致命三重组合”:一个能够访问私有数据、接触不可信内容,并具备对外通信能力的智能体,可能被诱骗而泄露该数据。一个运行于沙箱(Sandbox)中的编码智能体,其执行环境(harness)默认即同时具备这三种特性。

原始摘录
Simon Willison calls it the lethal trifecta : an agent with access to private data, exposure to untrusted content, and the ability to communicate externally can be tricked into leaking that data. A coding agent whose harness runs in its Sandbox has all three by default.
上下文

将执行环境(harness)与工具调用(tool calls)共同托管存在安全风险:执行环境的凭据与生成的代码并置;智能体可从网络(例如软件包和代码仓库)读取不可信内容;且沙箱内任何内容均可发起网络请求。

原始上下文

Hosting the harness and the tool calls together is a security risk. The harness's credentials sit next to generated code, the agent can read untrusted content from the web, like packages and repos, and anything in the Sandbox can make network calls..

这里提到的

全部提及对象

Firecracker

仅提及

奥利维亚·约翰斯顿提到 Firecracker 是一种为过时的信任单元解决隔离问题的技术,未表达支持或反对。

查看支持证据 · Olivia Johnston

gVisor

仅提及

奥利维亚·约翰斯顿提到 gVisor 是一种为过时的信任单元解决隔离问题的技术,未表达支持或反对。

查看支持证据 · Olivia Johnston

来源与研究方法

这些观点均关联原始来源。转述已明确标注,不作为逐字原话展示。

打开转录或来源材料 (在新标签页中打开)报告问题

继续了解这些人物的观点