0
At Tigera, we spend a lot of time thinking about agent security: identity, policy, runtime controls, and the record left behind after an agent acts.
Coding agents create an interesting problem because, in most organizations, they didn’t arrive through the front door.
Few companies ran a platform evaluation and rolled Claude Code out to 500 developers. Developers installed it themselves. By the time security and platform teams started asking how coding agents should be governed, they were already running on laptops with access to source code, credentials, SSH keys, kubeconfigs, internal services, and whatever else the developer could reach.
The long-term answer is increasingly clear I think: move coding agents into isolated environments you control.
Anthropic’s sandboxing work draws filesystem and network boundaries using OS primitives such as bubblewrap and seatbelt. Its reference devcontainer includes an egress firewall. Docker has introduced sandboxes for running coding agents, and Kubernetes-based approaches can add stronger workload isolation, network policy, and disposable development environments.
That direction makes sense.
Isolation governs what an agent can do. A gateway governs what it can send.
And unlike a complete move to remote development environments, the second boundary is something you can introduce today.