Herd’s maintainer claims the released daemon can deploy arbitrary Docker images inside Firecracker microVMs, providing stronger workload isolation than shared-kernel containers without sacrificing practical deployment compatibility.
state: expiredheat: lowuncertainty: highknownscott: mediummicrovm-sandboxing agentic-security ai-infrastructureHerd
What is this?
Herd is presented as a newly released microVM orchestration daemon whose maintainer says it can deploy arbitrary Docker images inside Firecracker microVMs. The stated value is Docker-compatible deployment with a stronger isolation boundary: unlike containers sharing the host kernel, each microVM has its own kernel and uses hardware virtualization. The supplied results support that general security and compatibility pattern, especially for untrusted or multi-tenant workloads, but they do not independently verify Herd’s implementation, performance, or “any Docker image” claim.
Why it matters to Scott
Scott already holds the structural-containment position in Sandboxed Execution and SiloOS, while the radar tracks the same microVM-sandbox territory in Docker AI Agent Sandboxes and its microVM concept page. Herd could be a practical Docker-compatible substrate for those active architectures, but its isolation, performance, and broad image-compatibility claims remain unverified.
ip:concept.sandboxed-executionip:framework.siloosdev:project.silo-osradar:docker-ai-agent-sandboxesradar:concept.microvms
queries asked of Scott's wikis
- microVM sandboxes for untrusted agent execution
- Docker compatibility versus hardware-isolated workloads
- security boundaries for coding-agent harnesses
- Firecracker orchestration in AI infrastructure
- agent-generated code threat model
- sandbox deployment ergonomics and isolation trade-offs
Measured heat
no measured readings yet — the hourly heat pass fills this in
How the heat travelled
no chain yet — the hourly chain pass fills this in
Evidence (2) — ⭐ canonical anchor
Interpretation history
2026-08-31T02:26:51Z
The launch has produced no independent testing, adoption, or implementation evidence; two comments without substantive supplied evidence do not advance the maintainer’s compatibility or performance claims.
2026-08-29T01:32:28Z
The reevaluation adds no independent validation, implementation evidence, or adoption; Herd remains a plausible but maintainer-claimed microVM substrate rather than a demonstrated Docker-compatible sandbox.
2026-08-29T01:31:00Z
grounded: known/medium — Scott already holds the structural-containment position in Sandboxed Execution and SiloOS, while the radar tracks the same microVM-sandbox territory in Docker A
2026-08-29T01:29:30Z
origin walked (codex/luna, conf 0.98): anchor hn.story.49485801 -> echo.github.abc8f259a7 by Sankalp Narula
2026-08-29T01:27:36Z
case created — The linked open-source daemon is a concrete infrastructure artifact with transferable value for isolating untrusted agent and developer workloads.
Decision trace
- 08-31 12:26expireThe launch has produced no independent testing, adoption, or implementation evidence; two comments without substantive supplied evidence do not advance the maintainer’s compatibility or performance cl
- 08-31 12:26alert_silentThe only change is negligible discussion activity, not a consequential technical delta; the project can re-enter the radar if independent benchmarks, security review, or real deployment evidence appea
- 08-31 12:26alert_routeThe only change is negligible discussion activity, not a consequential technical delta; the project can re-enter the radar if independent benchmarks, security review, or real deployment evidence appea
- 08-29 11:32repriceThe reevaluation adds no independent validation, implementation evidence, or adoption; Herd remains a plausible but maintainer-claimed microVM substrate rather than a demonstrated Docker-compatible sa
- 08-29 11:32alert_silentThere is no new consequential delta beyond the already assessed first-party release, and the compatibility, isolation, and performance claims remain unverified; this can wait for evidence of testing o
- 08-29 11:32alert_routeThere is no new consequential delta beyond the already assessed first-party release, and the compatibility, isolation, and performance claims remain unverified; this can wait for evidence of testing o
- 08-29 11:31alert_silentHerd is a real first-party open-source daemon directly relevant to microVM sandboxing, but the only evidence is its maintainer’s launch material: broad Docker-image compatibility, isolation quality, s
- 08-29 11:31surface_candidateHerd is a real first-party open-source daemon directly relevant to microVM sandboxing, but the only evidence is its maintainer’s launch material: broad Docker-image compatibility, isolation quality, s
- 08-29 11:31alert_routeHerd is a real first-party open-source daemon directly relevant to microVM sandboxing, but the only evidence is its maintainer’s launch material: broad Docker-image compatibility, isolation quality, s
- 08-29 11:31groundScott already holds the structural-containment position in Sandboxed Execution and SiloOS, while the radar tracks the same microVM-sandbox territory in Docker AI Agent Sandboxes and its microVM concep
- 08-29 11:29promote_anchororigin walk conf 0.98
- 08-29 11:27createThe linked open-source daemon is a concrete infrastructure artifact with transferable value for isolating untrusted agent and developer workloads.