sandbin
Run untrusted code and survive it — no Docker, no root
Details
- External ID
- 1247650
- Source
- PH
- Company
- —
- Product
- Handybin
- Website domain
- producthunt.com
- Launched
- Sept. 12, 2026
- Cohort
- —
- Upvotes
- 2
- Upvotes percentile
- 0.7405388069275176
- Tags
- Open Source, Developer Tools, GitHub, Security
- Fetched at
- Sept. 14, 2026, 1:01 a.m.
- Updated at
- Sept. 14, 2026, 1:01 a.m.
Description
Sandbin runs untrusted code in a real sandbox — bubblewrap + seccomp + cgroups, not a container. No Docker daemon, no root, no VM. ~20ms cold start (17.6× faster than Docker, measured), a 146-syscall allowlist instead of a blocklist, CLI + HTTP/WebSocket API + browser playground. MIT licensed.
Enrichment
- Theme
- self-hosted infrastructure and security tools
- Vertical
- Security
- Function
- Dev tools
- Audience
- Developer
- AI stance
- Not AI
- Project type
- Commercial product
- Normalized one-liner
- sandbox for running untrusted code
- Manually corrected
- False
Could you build this?
No Building a secure multi-layer sandbox using Linux namespaces, cgroups v2, and custom seccomp filters requires deep systems programming and security engineering expertise to prevent sandbox escapes.
What it would actually take: A production version requires low-level systems programming in C, Rust, or Go interacting directly with Linux kernel APIs (`clone`, `unshare`, `pivot_root`, `seccomp-bpf`, and `cgroupv2`). The critical hard part is defining a foolproof syscall allowlist and resource restriction architecture that resists privilege escalation, kernel exploits, and side-channel leaks. This demands deep Linux kernel internals, systems architecture, and offensive/defensive security audit experience.
Competitors
Other products that read as similar to this one — 163 launches clear the similarity bar, closest 8 shown.
Attention rank: #44 of 164 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).
Launched 317 days after the earliest competitor.
- Sandboxing untrusted code using WebAssembly · hn · 2026-02-03 · 76 upvotes · similarity 0.52
- Zerobox · hn · 2026-03-30 · 141 upvotes · similarity 0.50
- Minimal container-like sandbox built from scratch in C · hn · 2025-12-07 · 5 upvotes · similarity 0.49
- Run Claude Code autonomously inside your Docker Compose stack (OSS) · hn · 2026-04-03 · 8 upvotes · similarity 0.47
- Nucleus · hn · 2026-06-09 · 40 upvotes · similarity 0.46
- BVisor · hn · 2026-02-23 · 24 upvotes · similarity 0.45
- Keystone · hn · 2026-02-18 · 12 upvotes · similarity 0.44
- podup · ph · 2026-09-07 · 1 upvotes · similarity 0.44
Other launches for this product
Same idea, different domain
Nobody's really built a dev tools tool for Sales yet.