Repository navigation
plimsoll, a code execution sandbox for self-hosted Trigger.dev #5006
carrollco
started this conversation in
Show and tell
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
I built a Docker Compose recipe for adding plimsoll, an open-source code execution sandbox, to self-hosted Trigger.dev.
Trigger.dev’s self-hosting security documentation says the self-hosted setup “is not designed to run untrusted code or untrusted payloads.” AI-generated code is untrusted code, so a task that executes it needs a sandbox.
Plimsoll runs alongside your Trigger.dev worker on your infrastructure. Tasks connect over a private Docker network and send Python or JavaScript to the sandbox. With sessions enabled, variables and files persist between calls, letting an agent work through several steps without starting over.
The sandbox supports gVisor for stronger isolation and plain Docker with runc for local testing. Each result reports the isolation tier used, and callers can require a minimum tier before code runs.
I tested the recipe on one host with Trigger.dev v4.7.2. Plimsoll is Apache-2.0 licensed and pre-1.0. The README lists the deployment limits, including the sandbox daemon’s access to the Docker socket.
Get the Compose recipe and setup instructions
If you try it, tell me what broke, especially during setup or when connecting it to an existing worker.
All reactions