Seth Curry releases Abyss, a local-first ACP agent containerization framework with middleware support that provisions per-agent Docker environments, mounts, and secrets while keeping agents isolated from the host by default.
state: seedheat: mediumuncertainty: mediumconvergesscott: highagent-sandboxing agent-harnesses acp-protocolSeth Curryeverforward
What is this?
Abyss is a newly announced local-first framework by Seth Curry (GitHub: everforward) for running ACP (Agent Communication Protocol) agents in isolated Docker containers with middleware support. The Show HN title indicates it provisions per-agent Docker environments, mounts, and secrets while keeping agents isolated from the host by default. No web results were returned (search deadline reached), so this grounding rests solely on the case hypothesis and HN title β the framework's exact capabilities, maturity, and adoption are unverified.
Why it matters to Scott
Seth Curry's Abyss independently arrives at the padded-cell / sandboxed-execution architecture Scott's canon treats as load-bearing: per-agent Docker isolation, middleware composition, secrets/mounts at the execution boundary, and a local-first ACP harness. This is a consequential builder shipping the pattern Scott argues for in SiloOS, Code-First Architecture, and the single-tenant appliance model β not merely an example of the topic.
ip:framework.siloosip:concept.sandboxed-executionip:concept.runtime-containmentip:framework.code-first-architecturedev:concept.padded-cell-agent-architecturedev:concept.single-tenant-ai-appliancedev:project.openclawradar:abah-offline-firmware-agentradar:agentthread-per-channel-agent-containersradar:agenticos-self-hosted-governance
queries asked of Scott's wikis
- agent-sandboxing isolation models Docker vs WASM vs process
- ACP protocol adoption local-first agent harnesses
- agent-harnesses middleware composition patterns
- local-inference agent containers secrets management
- everforward Seth Curry prior work agent tooling
Measured heat
now 0 pts/hpeak 6 pts/hcomments 0/hpeers p14momentum: steady2 platformsage 1178h
points/hour across evidence Β· reading as of 2026-10-12 02:59:37.977291+11:00 Β· deterministic, not a model opinion
How the heat travelled
Evidence (2) β β canonical anchor
| source | object | author | score | comments |
| π§ hn | Show HN: Abyss β ACP Agent Isolation with Middleware SupportRetrieved article excerptOpen article Β· Retrieved 2026-10-08T17:49:34.456845+00:00 [Abyss](https://abyss.scurry.io/)
##### Abyss
- [Docs](https://abyss.scurry.io/docs/guides/what-is-abyss/)
- [Blog](https://abyss.scurry.io/blog/)
- [GitHub](https://github.com/SethCurry/abyss)
[Get started](https://abyss.scurry.io/docs/guides/getting-started/)
[Get started](https://abyss.scurry.io/docs/guides/getting-started/)
## Search
Loading search indexβ¦
No recent searches
No results for "**Query here**"
- to select
- to navigate
- to close
Search by [FlexSearch](https://github.com/nextapps-de/flexsearch)
# Welcome to Abyss
The easy way to containerize your AI agents.
[Get Started](https://abyss.scurry.io/docs/guides/getting-started/)
Abyss is an orchestrator for running agents in containers.
You configure your editor like a normal ACP agent, and Abyss handles everything Docker for you.
Sample screenshot showing Zed connecting to Abyss
```
docker:
# This is a pre-built image with Abyss and Pi pre-installed
image: "ghcr.io/sethcurry/abyss-pi:latest"
# Abyss speaks ACP, so we invoke Pi via pi-acp
agent_command:
- pi-acp
host_mounts:
# This mounts the current directory inside the container.
# It doesn't take a target path because ACP sends a `cwd`
# so we need the paths to line up between the host and
# container
- source: "./"
# This mounts your .pi directory so that the agent has
# API keys for your LLM, prior sessions, plugins, etc.
#
# You can put this in the `copy_files` config section
# which will prevent the LLM from modifying your config files
# but your sessions won't end up on your host PC so the session
# files are lost when the container gets deleted.
- source: "~/.pi"
destination: "/root/.pi"
```
Works with any ACP client you want!
## How Abyss stacks up
A purpose-built runtime for agents, not a general-purpose container tool you have to bend into one.
| | Abyss | Docker Compose | Docker Agent | Regular ACP |
| --- | --- | --- | --- | --- |
| Agent-Agnostic | β | β | β | β |
| Native ACP Support | β | β | β | β |
| Containerization | β | β | β | β |
| ACP Middleware Plugins | β | β | β | β |
| Startup scripts & provisioning | β | Manual | β | β |
## See No Evil
Your secrets stay secret. Abyss keeps your agent in the dark until you explicitly shine a light on something β nothing is visible by default.
## Hear No Evil
Every filesystem and shell request your agent makes is intercepted and executed inside the container β never on your real machine.
## Speak No Evil
Declare your environment once: files to copy, mounts to create, scripts to run. Abyss provisions the whole thing for you, every time.
## Read the docs
Learn more in the [Docs](https://abyss.scurry.io/docs/guides/what-is-abyss/).
Top | everforward | 1 | 0 |
| π§ echo.github β | Primary artifact is the author's own repo ("A control plane for isolating your LLM agents"). README: "abyss is a system for running your age | Seth Curry (GitHub: SethCurry; HN: everforward; scurry.io) | β | β |
Interpretation history
2026-10-08T20:54:27Z
origin walked (opencode/cheap-glm, conf 0.95): anchor hn.story.50007023 -> echo.github.13500fb68d by Seth Curry (GitHub: SethCurry; HN: everforward; scurry.io)
2026-10-08T19:04:54Z
grounded: converges/high β Seth Curry's Abyss independently arrives at the padded-cell / sandboxed-execution architecture Scott's canon treats as load-bearing: per-agent Docker isolation,
2026-10-08T18:50:17Z
case created β New framework targeting ACP agent isolation and middleware reuse; directly relevant to hot agent-sandboxing and agent-harnesses topics.
Decision trace
- 10-09 18:08attention_communicatedSeth Curry (everforward) releases Abyss, a control plane that runs ACP agents in Docker containers, proxies editor connections, and provides reusable middleware (RAG, subagents) via WASM plugins. Agen
- 10-09 18:08attention_routeFurther reading for 6 PM briefing: first released framework independently arriving at Scott's load-bearing containment architecture; directly relevant to his agent-harness work (OpenClaw, Ask) an
- 10-09 10:25attention_routeFirst released framework independently arriving at Scott's load-bearing containment architecture; directly relevant to his agent-harness work (OpenClaw, Ask) and runtime containment thesis. Inclu
- 10-09 10:06attention_routeFirst released framework independently arriving at Scott's load-bearing containment architecture; directly relevant to his agent-harness work (OpenClaw, Ask) and runtime containment thesis. Brief
- 10-09 07:59attention_routeFirst released framework independently arriving at Scott's load-bearing containment architecture; directly relevant to his agent-harness work (OpenClaw, Ask) and runtime containment thesis. Brief
- 10-09 07:54attention_candidatecreate
- 10-09 07:54promote_anchororigin walk conf 0.95
- 10-09 06:04groundSeth Curry's Abyss independently arrives at the padded-cell / sandboxed-execution architecture Scott's canon treats as load-bearing: per-agent Docker isolation, middleware composition, secre
- 10-09 05:50createNew framework targeting ACP agent isolation and middleware reuse; directly relevant to hot agent-sandboxing and agent-harnesses topics.