Nicheloom

Market intelligence for builders — see what's gaining traction before it's crowded.

Drop

A rootless Linux sandbox with gVisor support

Details

External ID
49801329
Source
HN
Company
—
Product
Drop
Website domain
droprun.sh
Launched
Sept. 22, 2026
Cohort
—
Upvotes
189
Upvotes percentile
0.9633173843700159
Tags
—
Fetched at
Sept. 26, 2026, 10:53 p.m.
Updated at
Sept. 26, 2026, 10:53 p.m.

Description

I created Drop because I always felt uneasy installing and running third-party programs using my main user account. A single compromised dependency means a full compromise of the system. What is even worse, because I ship software from my computer, a single compromised dependency can lead to compromise of all the users of my software.Containers and VMs are one solution, but for local work, they are often detrimental to productivity. It takes effort to configure a machine with all the tools and configs needed for productive work, but a container or a VM will be stripped of all these tools. This is great for production deployments, where the aim is a reproducible system with minimal dependencies, but can get in the way of productive local work.Drop is language independent, but the workflow is inspired by Python's virtualenv. With virtualenv the environment isolation is only a convention that relies on installed dependencies being good citizens. With Drop the isolation is enforced.Each Drop environment gets its own writable and easily disposable home dir, with only selected config files and dirs from the original home mounted, mostly read-only.Drop uses Linux namespaces for isolation (user, mount, network, PID, IPC, cgroup), doesn't require root and, as an option, uses gVisor user-space kernel, which adds protection against exploiting host kernel vulnerabilities to escape the sandbox.I don't want to make the introductory post too lengthy, but I'm here to answer any questions and give any additional technical details.Note: This is my 3rd submission of the project, the first two did not draw attention. Since then I have added support for gVisor and created a project website to better explain the concept and organize documentation.

Enrichment

Theme
self-hosted infrastructure and security tools
Vertical
Security
Function
Dev tools
Audience
Developer
AI stance
Not AI
Project type
Hobby / open-source project
Normalized one-liner
rootless sandbox for linux developers
Manually corrected
False

Could you build this?

No Drop is a systems-level Linux sandbox operating across user, mount, network, and cgroup namespaces with gVisor user-space kernel integration and privilege dropping, requiring deep OS kernel and security engineering expertise.

What it would actually take: Implementation requires systems programming (Rust/C/Go) leveraging Linux namespaces (`unshare`, `clone`), cgroups v2 resource limiting, seccomp filtering, and integration with the gVisor (`runsc`) virtualized kernel runtime. Correctly securing rootless mount propagation and filesystem virtualization without creating privilege escalation vulnerabilities requires specialized operating system security engineering.

Discussion

20 comments analyzed.

Competitors mentioned: bwrap, nono, proot, Substrate, Boxy

Concerns raised: Does not prevent agent from uploading/exfiltrating sensitive files, Cannot run or start containers from the sandbox, AppArmor allowlists on distros like Ubuntu complicate installation, Tarpit space with many shallow or complex solutions

Feature requests: GUI application sandboxing, VM runtime support, Ability to start containers within sandbox

Competitors

Other products that read as similar to this one — 141 launches clear the similarity bar, closest 8 shown.

Attention rank: #10 of 142 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).

Launched 318 days after the earliest competitor.

Other launches for this product

Same idea, different domain

Nobody's really built a dev tools tool for Sales yet.