Uploaded March 2026 | Updated September 2026, 2 weeks ago
Still running your AI agents in standard Docker containers? That’s an architectural mismatch ⛔️ Naresh Ramesh (Cloudflare) argues that an agent doesn't just need a server — it needs a dedicated "Agent Computer" designed for secure, autonomous execution.
In this talk, Naresh presents Cloudflare’s infrastructure strategy for scaling long-running AI workflows.
💫 He breaks down why traditional namespaces fail to protect the host from untrusted, agent-generated code and how to build a truly isolated runtime.
You will learn:
✅ Micro-VM Isolation: Why hardware-level isolation (Firecracker) is the only way to execute arbitrary code without the overhead of full VMs.
✅ Dynamic Networking: How to use Durable Objects to create globally addressable sandboxes with instant browser-to-agent connectivity.
✅ Persistence & Snapshots: Technical strategies to eliminate cold starts using memory snapshots and warm pools for seamless session resumption.
✅ Programmatic Gates: Establishing strict execution boundaries to control the "blast radius" of autonomous actions.
🔥 Naresh Ramesh is a Software Engineer on the Cloudflare Agents team and a YC S23 founder. An AI runtime expert, he built top-ranking SWE-bench agents and previously designed India's payment infrastructure and contributed to gRPC.
👉 Connect with Naresh:
🔗 https://x.com/ghostwriternr
🔗 ghostwriternr.me
📌 Follow the link to watch the full version of the talk and gain access to all AI Coding Summit recordings:
🔗 gitnation.com/events/ai-coding-summit-2026?utm_source=youtube&utm_medium=NareshRamesh
🕐 Timestamps:
00:00 - The Pixel Goose Demo: Autonomous Agent in Action
01:25 - Beyond Localhost: Why Every Agent Needs Its Own "Computer"
02:49 - The 5 Infrastructure Layers of an Agent Sandbox
04:30 - Runtime Decisions: Linux Instances vs. Restricted Shells
05:15 - Beyond Code Runners: Background Processes and Streaming
07:10 - The Security Paradox: Executing Untrusted Agent Output
08:33 - The Isolation Spectrum: Why Docker is a Security Mismatch
09:57 - Networking Architecture: Routing Traffic to Edge Sandboxes
11:37 - Solving Cold Starts: Infrastructure vs. App Readiness
12:51 - Optimization Toolkit: Snapshots, Volumes, and Warm Pools
15:53 - Summary: The 8-Line Production Sandbox
18:08 - The Scale of AI Code: Infrastructure for the Agentic Era
18:48 - The Future of Runtimes: Firecracker vs. V8 Isolates
20:44 - Q&A: Standardization and Tuning Agent Harnesses
25:48 - Blast Radius Control: The Concept of Programmatic Gates
28:35 - The Golden Rule: Controlling Environment over User Behavior
✍️ This talk was part of AI Coding Summit 2026:
Designing Sandboxed Dev Environments for Coding Agents | Naresh Ramesh
🔗 aicodingsummit.com/?utm_source=youtube&utm_medium=NareshRamesh
📌 We’ve hidden a secret code for 20% off your next event.
Join our upcoming conferences!
💫 JSNation 2026 June 11 & 15, 2026 (Amsterdam)
🔗jsnation.com/?utm_source=youtube&utm_medium=NareshRamesh
💫 React Summit, June 12 & 16, 2026 (Amsterdam)
reactsummit.com/?utm_source=youtube&utm_medium=NareshRamesh
💫 TechLeadConf, June 11, 2026 (Amsterdam)
techleadconf.com/?utm_source=youtube&utm_medium=NareshRamesh
💫 Node Congress, March 26 & 27, 2026 (Online)
nodecongress.com/?utm_source=youtube&utm_medium=NareshRamesh
and more!
🚀 Check out all the upcoming events from GitNation:
🔗 gitnation.com/events?utm_source=youtube&utm_medium=NareshRamesh
Don't forget to use INSIDER20 promo code for 20% off on tickets.
#GitNation #AICodingSummit2026 #Cloudflare #AIAgents #AgenticWorkflows #AIInfrastructure #Sandboxing #MicroVM #Firecracker #SystemDesign #SoftwareArchitecture #Security #DevOps #LLM #BackendEngineering
Still running your AI agents in standard Docker containers? That’s an architectural mismatch ⛔️ Naresh Ramesh (Cloudflare) argues that an agent doesn't just need a server — it needs a dedicated "Agent Computer" designed for secure, autonomous execution.
In this talk, Naresh presents Cloudflare’s infrastructure strategy for scaling long-running AI workflows.
💫 He breaks down why traditional namespaces fail to protect the host from untrusted, agent-generated code and how to build a truly isolated runtime.
You will learn:
✅ Micro-VM Isolation: Why hardware-level isolation (Firecracker) is the only way to execute arbitrary code without the overhead of full VMs.
✅ Dynamic Networking: How to use Durable Objects to create globally addressable sandboxes with instant browser-to-agent connectivity.
✅ Persistence & Snapshots: Technical strategies to eliminate cold starts using memory snapshots and warm pools for seamless session resumption.
✅ Programmatic Gates: Establishing strict execution boundaries to control the "blast radius" of autonomous actions.
🔥 Naresh Ramesh is a Software Engineer on the Cloudflare Agents team and a YC S23 founder. An AI runtime expert, he built top-ranking SWE-bench agents and previously designed India's payment infrastructure and contributed to gRPC.
👉 Connect with Naresh:
🔗 https://x.com/ghostwriternr
🔗 ghostwriternr.me
📌 Follow the link to watch the full version of the talk and gain access to all AI Coding Summit recordings:
🔗 gitnation.com/events/ai-coding-summit-2026?utm_source=youtube&utm_medium=NareshRamesh
🕐 Timestamps:
00:00 - The Pixel Goose Demo: Autonomous Agent in Action
01:25 - Beyond Localhost: Why Every Agent Needs Its Own "Computer"
02:49 - The 5 Infrastructure Layers of an Agent Sandbox
04:30 - Runtime Decisions: Linux Instances vs. Restricted Shells
05:15 - Beyond Code Runners: Background Processes and Streaming
07:10 - The Security Paradox: Executing Untrusted Agent Output
08:33 - The Isolation Spectrum: Why Docker is a Security Mismatch
09:57 - Networking Architecture: Routing Traffic to Edge Sandboxes
11:37 - Solving Cold Starts: Infrastructure vs. App Readiness
12:51 - Optimization Toolkit: Snapshots, Volumes, and Warm Pools
15:53 - Summary: The 8-Line Production Sandbox
18:08 - The Scale of AI Code: Infrastructure for the Agentic Era
18:48 - The Future of Runtimes: Firecracker vs. V8 Isolates
20:44 - Q&A: Standardization and Tuning Agent Harnesses
25:48 - Blast Radius Control: The Concept of Programmatic Gates
28:35 - The Golden Rule: Controlling Environment over User Behavior
✍️ This talk was part of AI Coding Summit 2026:
Designing Sandboxed Dev Environments for Coding Agents | Naresh Ramesh
🔗 aicodingsummit.com/?utm_source=youtube&utm_medium=NareshRamesh
📌 We’ve hidden a secret code for 20% off your next event.
Join our upcoming conferences!
💫 JSNation 2026 June 11 & 15, 2026 (Amsterdam)
🔗jsnation.com/?utm_source=youtube&utm_medium=NareshRamesh
💫 React Summit, June 12 & 16, 2026 (Amsterdam)
reactsummit.com/?utm_source=youtube&utm_medium=NareshRamesh
💫 TechLeadConf, June 11, 2026 (Amsterdam)
techleadconf.com/?utm_source=youtube&utm_medium=NareshRamesh
💫 Node Congress, March 26 & 27, 2026 (Online)
nodecongress.com/?utm_source=youtube&utm_medium=NareshRamesh
and more!
🚀 Check out all the upcoming events from GitNation:
🔗 gitnation.com/events?utm_source=youtube&utm_medium=NareshRamesh
Don't forget to use INSIDER20 promo code for 20% off on tickets.
#GitNation #AICodingSummit2026 #Cloudflare #AIAgents #AgenticWorkflows #AIInfrastructure #Sandboxing #MicroVM #Firecracker #SystemDesign #SoftwareArchitecture #Security #DevOps #LLM #BackendEngineering










