Pi: The Minimal Agent Within OpenClaw

(lucumr.pocoo.org)

4 points | by tosh 9 hours ago ago

1 comments

  • clawsyndicate 9 hours ago ago

    allowing agents to "extend themselves" via bash forced us to move the whole fleet to gVisor. we run ~10k concurrent pods on k3s and standard container isolation just wasn't enough for arbitrary code execution. the runsc memory overhead is the price you pay for letting users safely install their own packages.