Runeward runs on your own machine — the client starts it, so there is no endpoint to ping. Last commit 10 Sep 2026.
Governed execution cells for AI agents: Docker/K8s sandboxes with policy, audit, and approvals.
We read the source, 20 h ago · rules 3dff92dd89df
Things with no honest explanation: a promise that contradicts the code, code that runs at install time while hiding what it does, data leaving the machine.
const gcpMetadataDefaultBase = "http://metadata.google.internal"
What this server is able to do. For an MCP server this is often the job itself — a terminal server runs commands because that is what it is for. Listed so you know what you are plugging in, not as an accusation.
joined := filepath.Join(s.root, rel)
match = "**/.ssh/*"
Found in continuous integration, deployment or infrastructure files, or in a neighbouring package of the same monorepo. None of this is installed when you add the server: it describes how the project is built and released. We list it because a leaked key in a build pipeline is still a real problem, but it is not something this server does on your machine.
# code-server 4.135.0 bundles five JavaScript packages with published # HIGH/CRITICAL fixes. Build the replacements away from the final image so npm # and its dependency tree do not enlarge the runtime attack surface. USER root
Is this your server and something here is wrong? Tell us — corrections are free and do not require a plan.
Code changes quietly between releases, and nobody reads the diff of a dependency. We do, on every release — watch Runeward and you get told the day something new turns up.
Guardrailed fleet ops for AI agents: multi-cluster Kubernetes via OCM with policy, approval, audit.
Guardrailed fleet ops for AI agents: multi-cluster Kubernetes via OCM with policy, approval, audit.
Persistent Docker/SSH sandbox for AI agents: shell exec, file ops, audit log.
Kubernetes RCA agent that sandboxes its own AI with OPA Gatekeeper. MCP-ready for any client.
Safe Kubernetes access for AI agents via MCP. Read-only by default, with explicit permission modes.
Give any LLM its own computer — Docker sandboxes with bash, browser, docs, and sub-agents
Execution engine for AI agents. 412 modules: browser, file, Docker, data, crypto.
TypeScript MCP server for AI-powered containerization workflows with Docker and Kubernetes support
Answers built from our own checks of this server.