Source note

Show HN: Cordium – FOSS identity-based sandbox platform with zero-trust access

Kubernetes SandboxZero Trust AccessIdentity Based AuthAI Agent WorkflowsRemote Development

Cordium is a self-hosted Kubernetes sandbox platform for developers, AI agents, and CI jobs. It combines isolated workspaces with identity-based, secretless access to internal systems.

  • Remote dev boxes and agent sandboxes still need secrets copied into the workspace for SSH, databases, and APIs.
  • That creates credential sprawl and makes access control harder to audit.
  • Teams also need one setup for interactive coding sessions and short-lived automated jobs.
  • Runs each workspace as a rootless container sandbox on Kubernetes.
  • Defines environments in YAML with image, repo, tasks, variables, ports, and resource limits.
  • Uses Octelium identity-aware proxy and per-request ABAC policies to grant access at the protocol layer, so the workspace never receives upstream credentials.
  • Supports browser terminal, SSH, CLI, and gRPC, plus persistent or ephemeral workspaces.
  • Uses prebuilt VolumeSnapshot templates to cut startup time for heavy environments.
  • The excerpt gives no benchmark table or measured evaluation results.
  • It claims workspaces can access SSH servers, databases, internal HTTP APIs, Kubernetes clusters, and mTLS services without API keys, passwords, SSH private keys, or kubeconfigs entering the sandbox.
  • It claims prebuilt templates reduce cold startup from minutes to seconds.
  • It supports any Kubernetes cluster, from a single-node VM to multi-node production installs, and exposes OpenTelemetry audit logs for every request.