Yes. On macOS particularly you can do sandbox-exec(1) with custom / per-task SBPL profiles. Combined with strict control over environment variables that are passed into the agent process plus an outbound firewall like LittleSnitch.
Important is to isolate tasks from each other. Example: for work related tasks I let the agent access Datadog or Docker socket. Everything else does not have access to these.
I was looking for this comment. Seems to fit right in between “just” docker compose and a “fully-fledged” K8s. This book is running Erlang clusters on Swarm on EC2: https://www.goodreads.com/book/show/216601296.
There are a couple of smaller "cloud" providers who do not ([1]). I think this might be simply because they lack the tech for traffic shaping here. So they usually implement a "fair use policy" (whatever that means). But yes, ingress and egress traffic is essentially offered for free.
[1]: Another one is gridscale.io, also from Germany
Turning to drugs to improve learning performance is bad advice. Note: I don’t say what you do is bad, this is totally up to you. But giving someone else the advice using drugs is just bad.
This is bad advice, sorry. Not the financial one I mean, it’s always good to save up some money for bad times, but the “you will burn out” part.
If you think that you will eventually burn out, like in “its just a matter of time”, you should seriously consider switching jobs, work in a less demanding industry, or do something else. There is so much more to life than just this work and nothing keeps you from working just at half the pace. You even might get some different insights from that. Seriously, I don’t want to sound like a total jerk but when this is the approach you choose, it’s going to be needlessly rough.
Your username indicates your attitude, btw. Talk to a friend or professional. Maybe you need some good advice.
Oh, wow. I see. With push notifications, mobile clients, TLS encryption this _could_ work in a company setting …provided you keep logs and make search results available for staff, too. Cool. Thanks for the links!