Sidecars: A low-latency trust boundary for Sandboxes
Blog post from Modal
Modal has introduced Sidecars, beta isolated containers that run alongside Sandboxes on the same host to separate trusted agent components, such as credentials, harness logic, proxies, and monitoring tools, from untrusted generated code. The company argues that conventional Sandbox isolation was designed around a broader unit of trust and leaves agents vulnerable to data exfiltration when private data, untrusted content, and external network access coexist. Existing approaches, including remote control planes and network egress controls, can improve security but may add latency or lack the flexibility needed for custom agent infrastructure. Sidecars use gVisor or VM isolation boundaries while communicating locally through an internal TCP/UDP bridge network, which Modal says is at least three times faster than communication between separate Sandboxes in the same region. They can be created dynamically through the SDK, share host CPU and memory resources with their Sandbox, support independent outbound network policies, and can be used to force Sandbox traffic through a proxy. Ramp is cited as an early user, employing Sidecars to run custom egress proxies for its Inspect coding agent, which handles more than 75% of Ramp’s merged pull requests.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Kubernetes | 1 | No monthly metrics for this publish month. | |||
| Loop engineering | 1 | No monthly metrics for this publish month. | |||
| Secrets Management | 1 | No monthly metrics for this publish month. | |||
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.