There's some questionable apps posted on here all the time. Honestly, it's not so much the vibecoding, but that these apps could be malicious/incompetent and leaking your data by uploading it to the dev's servers. I don't have time to review anything tbh, but I often want to try stuff. If you use Docker, there's a somewhat simple technique that can give you piece of mind. Using this approach, you can run any untrusted service, but it's not allowed to connect out. It can only reply to incoming requests. Good enough for most apps. Essentially, you write a docker-compose file that runs the service as usual, but put it behind a 2nd service that acts as a gateway that blocks outbound traffic. (Side note: many repos make the awful decision of giving 'docker run' examples for running them in docker. Ask any LLM 'Convert the following docker run command to a docker compose file'. I recommend you always use compose files in your life anyway, it's 'docker run' with easy repeatability + backupability/git committing + more features like multiple services in one file which we need here. Then you just cd to ~/dockerstuff/someapp/ and run 'docker compose up') Let's say the original unstrusted app's compose file is this, example is a service on port 8000 services untrustedservice: image: python:latest container_name: untrustedservice ports: - "0.0.0.0:8000:8000" command: [python, -m, http.server, "8000", --directory, /srv] Use this instead, where we: 1) lock out untrusted service from the main network, 2) use socat as a one-way gateway to reach the untrusted service. socat is a tiny open-source binary, only 1.2MB RAM needed by the extra container. services: # socat gateway untrustedservice_gateway: image: alpine/socat:latest container_name: untrustedservice_gateway init: true #Redirect incoming port 8000 connections to untrustedservice's port 8000 command: TCP4-LISTEN:8000,fork,reuseaddr TCP4:offline_untrustedservice:8000 ports: - "0.0.0.0:8000:8000" networks: # Only this gateway connects to both networks - public_network - isolated_network depends_on: - untrustedservice # The expanded untrusted service definition # Notice how "ports" has been removed, the gateway is our entrypoint untrustedservice: image: python:latest container_name: offline_untrustedservice init: true command: [python, -m, http.server, "8000", --directory, /srv] # untrustedservice is limited to isolated_network networks: - isolated_network # some extra lockdown measures I don't really understand. Optional. cap_drop: - NET_ADMIN - NET_RAW security_opt: - no-new-privileges:true networks: # Normal network needed by gateway public_network: {} # Network without internet but allowing replies to gateway connections isolated_network: internal: true   submitted by   /u/dtdisapointingresult [link]   [comments]