Developer ljedrz has released Kamchatka, a Linux terminal agent built on the nachalnik runtime that prioritizes transparency and security over convenience. Unlike typical AI agents that rely on prompt-based guardrails or simple command blocklists, Kamchatka leverages native Linux kernel featuresβspecifically Landlock and seccompβto confine its shell environment. This approach ensures that the agent cannot access the network or write to files unless explicitly permitted, offering a level of control that resonates with security-conscious developers who distrust the 'black box' nature of current LLM tooling.
Kernel-Enforced Security Boundaries
The core differentiator of Kamchatka is its reliance on OS-level confinement rather than application-level checks. The agentβs shell is sandboxed by Landlock, restricting file system writes to specific directories, while a seccomp filter intercepts every network attempt until the user grants permission. This design choice means that supply-chain risks are mitigated at the kernel level; the agent literally cannot execute network calls or modify private files outside its working directory without a valid answer from the operator. This is a stark departure from tools that simply ask 'are you sure?' and hope the model behaves.
Granular Permission Policies and Context Control
Kamchatka implements a fine-grained permission system where tools are treated as domains (e.g., fs, shell) and operations as subjects (e.g., fs:read, shell:run). Users can grant permissions for specific operations rather than entire tools, and the system supports live toggling of tools via commands like '/tools toggle shell' without restarting the session. Furthermore, the agent exposes its context window directly to the user through a dedicated tab, showing exactly what information is included in the next request and what has been compacted or held back. This transparency addresses common frustrations with token accounting and 'forgotten' context in long-running sessions.
Minimalist Architecture and Rust Efficiency
Built entirely in Rust, Kamchatka requires no external system libraries or pkg-config dependencies, relying instead on rustls over ring for TLS. It ships as a static musl binary for x86_64 and aarch64 architectures, ensuring portability across modern Linux kernels. The agent features a 'step' mode that allows users to drive the state machine one transition at a time, pausing at the 'ready' state to inspect, prune, or drop pending tool calls before execution. This deterministic control flow, combined with local, auditable transcripts of all conversations, positions Kamchatka as a serious tool for developers who need rigorous oversight of their AI-assisted workflows.
Key Takeaways
- Kamchatka uses Landlock and seccomp for kernel-level sandboxing, not just command blocklists.
- Permissions are granular (e.g., fs:read vs. fs:grep) and can be toggled live without restarts.
- The context window is fully transparent, showing exactly what the model sees and why.
- Built in Rust with no external dependencies, shipping as static musl binaries for Linux.
- A 'step' mode allows users to inspect and modify tool calls before they execute.
The Bottom Line
Kamchatka proves that AI agents don't need to be opaque magic boxes; with kernel-level enforcement and transparent context, we can finally trust our tools to do exactly what we say. This release is a welcome signal that the industry is moving past the 'prompt engineering' era into true system integration. For those of us who treat the terminal as a sacred space, Kamchatka offers the control we've been demanding.