Nicheloom

Market intelligence for builders — see what's gaining traction before it's crowded.

CLRK, an open-source agent runtime with gVisor and MitM guardrails

Details

External ID
48822750
Source
HN
Company
—
Product
CLRK, an open-source agent runtime with gVisor and MitM guardrails
Website domain
github.com
Launched
July 7, 2026
Cohort
—
Upvotes
5
Upvotes percentile
0.1081242532855436
Tags
—
Fetched at
Sept. 7, 2026, 9:26 p.m.
Updated at
Sept. 7, 2026, 9:26 p.m.

Description

TL;DR: we built a framework-agnostic agent runtime that uses gVisor for isolation and runs on k8s. It’s open-source under AGPLv3Recently we’ve been working on a customer support “AI assistant” - essentially an interactive knowledge base/L1 support but with an option to touch resources that belong to a customer it’s talking to. We found existing tools to be lacking in these aspects:1. Fully intercepted i/o. We wanted to trace out LLM calls as well as any other networking calls attempted by the harness so that guardrails and audit trails apply to all current and future systems uniformly. Nobody’s agent can accidentally make raw database calls or send PII data to an overseas LLM provider.2. Coherent API and framework agnostic. There’re a lot of frameworks out there that do similar things in slightly different way and most we found had telemetry, guardrails and other tooling tightly bound into the framework. We wanted something with an infrastructure-first approach because we think it’s a more flexible way to compose such systems.3. k8s compatible runtime. We run part of our stack on k8s and know it well so we wanted to take advantage of this if we could.We searched for an existing solution, but especially with Daytona going closed sourced recently, there were no options we could find that were open-source and met our needs, so we built one. A more in-depth design writeup can be found here: https://apoxy.dev/blog/enter-clrkQuestions, FRs, hot takes or funny insults are welcome!

Enrichment

Theme
AI agent frameworks and developer tools
Vertical
Horizontal
Function
Agent / copilot
Audience
Developer
AI stance
AI-native
Project type
Hobby / open-source project
Normalized one-liner
sandboxed agent runtime with security controls
Manually corrected
False

Could you build this?

No Implementing a secure multi-tenant agent runtime combining gVisor sandboxing, man-in-the-middle network inspection guardrails, and Kubernetes container orchestration requires specialized systems and security engineering.

What it would actually take: The system requires a Kubernetes operator/controller that dynamically provisions ephemeral pods backed by gVisor (runsc) runtime handlers, paired with eBPF or an integrated TLS-intercepting transparent proxy (like Envoy or custom Go proxy) to inspect agent traffic in real time. The hardest parts involve enforcing strict kernel sandboxing while maintaining low invocation latency and implementing MitM TLS termination without breaking agent network protocols or opening security holes.

Discussion

No comments on this launch.

Competitors

Other products that read as similar to this one — 303 launches clear the similarity bar, closest 8 shown.

Attention rank: #275 of 304 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).

Launched 240 days after the earliest competitor.

Other launches for this product

Same idea, different domain

Nobody's really built a agent / copilot tool for Agriculture yet.