May 14, 2026 · 1h 5m · mad
The Agent Harness: Building Secure Sandboxes for Autonomous AI Workloads
gold bands on the timeline = statements, start to end. Hover to read, click to jump. CC turns on captions
In this episode of The MAD Podcast, host Matt Turck interviews Ivan Burazin, CEO of Daytona, about why autonomous AI agents require dedicated, secure cloud computer sandboxes. The conversation covers the architectural and security fundamentals of agent sandboxing, technical infrastructure deep dives, the evolving AI agent stack, and strategic insights for developer tool founders.
How this conversation actually went
Every chapter scored 0–10 on four independent dynamics. Hover any point for the reasoning behind the score. Matt holds 12.9% of the talking time here. How this is scored →
speaking balance: gold is Matt, purple is the guest (3 minute bins)
Ivan forcefully rejects running agents directly on local host hardware due to severe security risks like raw bank credentials, explaining how it broke his thesis for local agent execution.
Hardest push from Matt ▶ 18:46 Pushing back on Markdown files for agent memoryMatt explicitly challenges the premise that simple Markdown files are sufficient for long-term agent memory compared to the robustness offered by structured databases.
Biggest teaching moment ▶ 52:00 Explaining why Kubernetes fails for sandboxesIvan educates Matt on why off-the-shelf schedulers like Kubernetes fail for stateful, low-latency sandboxes, requiring a custom bare-metal scheduler.
Matt holds his own ▶ 1:01:05 Citing Dylan Patel on impending CPU shortageMatt demonstrates sharp industry knowledge by citing Dylan Patel's research on CPU bottlenecks before Ivan expands on the technical details.
the scores for every segment, with the reasoning behind each
| Chapter | Topic | Matt as informed peer | Guest teaching | Guest disagreement | Matt pushing back | Why |
|---|---|---|---|---|---|---|
| Episode Agenda: The Agent Stack and GTM Strategy | 3 | 4 | 1 | 1 | Matt introduces the episode and uses analogies like OpenClaw on a Mac Mini to ground the sandbox concept. Ivan clarifies how sandboxes differ from physical hardware, citing security risks like bank credential leaks during agent execution. | |
| Stateful vs. Stateless Architecture and Sandbox History | 3 | 5 | 2 | 1 | Matt prompts Ivan to explain stateful vs stateless architectures and the origin of sandboxes. Ivan provides historical context on Code Sandbox and microVMs, explaining why developer localhost mindsets are changing due to AI. | |
| Concurrency and Limitations of Local Execution | 3 | 5 | 2 | 1 | Matt asks if all agents need sandboxes or only specific subcategories. Ivan argues that any agent performing knowledge work requires a sandbox computer, contrasting simple chat interfaces with action-oriented tool calls. | |
| Deconstructing the Emerging AI Agent Stack | 4 | 5 | 1 | 2 | Matt brings up specific memory storage approaches like Markdown files versus structured databases. Ivan breaks down the overall agent stack and points out that current LLMs do not genuinely learn from previous tasks. | |
| Agent Harnesses, Managed Services, and OpenAI | 4 | 4 | 1 | 1 | Matt cites recent industry developments including OpenAI Agent SDK and Anthropic Managed Agents. Ivan delineates fully managed agent stacks from modular SDK and sandbox infrastructure integrations. | |
| Founder Journey: Lessons from CodeAnywhere to Daytona | 4 | 3 | 1 | 1 | Matt asks Ivan about lessons learned from his prior company CodeAnywhere and references his tweets on developer tools. Ivan shares insights on distinguishing individual free users from paying enterprise accounts. | |
| Event Marketing and Distribution for Technical Founders | 3 | 3 | 0 | 0 | Matt commends Ivan on developer marketing and distribution capabilities. Ivan recounts how stepping in as a conference host helped him overcome stage fright and master event mechanics. | |
| Three Levers of Product Adoption and Brand Perception | 3 | 4 | 1 | 1 | Matt comments on Daytona's recent Chase Center conference. Ivan outlines the three primary drivers of product adoption borrowed from Sentry: awareness, preference, and deterministic requirements. | |
| Organic Twitter Growth and Navigating Hype Cycles | 3 | 3 | 2 | 1 | Matt brings up Ivan's viral Twitter post regarding working through holidays. Ivan defends his view on capitalising on AI super-cycles and explains how online visibility translates into customer acquisition. | |
| Customer Support as a Growth Advantage | 2 | 4 | 0 | 0 | Matt asks about other components of Daytona's GTM strategy. Ivan explains how his background as a sysadmin shaped Daytona's rapid support SLA framework to remove user anxiety. | |
| Sandbox Architecture: Speed, Density, and Economics | 3 | 6 | 1 | 1 | Matt pivots to technical architecture, asking why startup speed and concurrency matter. Ivan explains the economic trade-offs between idle CPU sandboxes and expensive GPU utilization in RL training runs. | |
| Comparing MicroVMs, Containers, and Runtimes | 4 | 6 | 2 | 1 | Matt asks about technical distinctions across microVMs, containers, and runtimes, mentioning Firecracker specifically. Ivan explains where Firecracker excels and where alternative hypervisors like QEMU are needed for Android or GPU workloads. | |
| Snapshotting, Pausing, and Compute Cost Optimization | 4 | 6 | 2 | 1 | Matt asks why snapshotting matters and why Daytona wrote its own scheduler. Ivan explains compute cost optimization through pausing idle sandboxes and why standard orchestrators like Kubernetes fail for fast stateful sandboxes. | |
| Technical Differences Between Ephemeral and Long-Running Sandboxes | 3 | 6 | 1 | 1 | Matt asks how long-running 24-hour agent tasks alter technical requirements compared to ephemeral ones. Ivan explains live migration complexities and server maintenance without terminating active workloads. | |
| The Hidden Complexity of Building Custom Sandboxes and Storage Performance | 3 | 6 | 1 | 1 | Matt observes that building a custom sandbox in-house is far harder than team founders anticipate. Ivan compares local disk IOPS against network-attached storage performance bottlenecks. | |
| The Impending CPU Shortage for AI Workloads | 5 | 5 | 1 | 1 | Matt cites Dylan Patel and SemiAnalysis regarding an upcoming transition from GPU to CPU shortages. Ivan agrees, detailing how RL and agent scale drive massive CPU demand before Matt wraps up the episode. |