Home / Companies / Modal / Blog / Post Details
Content Deep Dive

Sidecars: A low-latency trust boundary for Sandboxes

Blog post from Modal

Post Details
Company
Date Published
Author
-
Word Count
1,380
Company Posts That Month
4
Language
English
Hacker News Points
-
Post removed?
No
Summary

Modal has introduced Sidecars, beta isolated containers that run alongside Sandboxes on the same host to separate trusted agent components, such as credentials, harness logic, proxies, and monitoring tools, from untrusted generated code. The company argues that conventional Sandbox isolation was designed around a broader unit of trust and leaves agents vulnerable to data exfiltration when private data, untrusted content, and external network access coexist. Existing approaches, including remote control planes and network egress controls, can improve security but may add latency or lack the flexibility needed for custom agent infrastructure. Sidecars use gVisor or VM isolation boundaries while communicating locally through an internal TCP/UDP bridge network, which Modal says is at least three times faster than communication between separate Sandboxes in the same region. They can be created dynamically through the SDK, share host CPU and memory resources with their Sandbox, support independent outbound network policies, and can be used to force Sandbox traffic through a proxy. Ramp is cited as an early user, employing Sidecars to run custom egress proxies for its Inspect coding agent, which handles more than 75% of Ramp’s merged pull requests.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Kubernetes 1 No monthly metrics for this publish month.
Loop engineering 1 No monthly metrics for this publish month.
Secrets Management 1 No monthly metrics for this publish month.
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.