Features / Secrets & isolation

Be deliberate about secrets and host access.

Use OS keyring-backed secrets and optional Docker isolation for local stdio servers.

Why it matters

More intention.
Less guesswork.

Local tools may need credentials and access to files. Choose how secrets are supplied and what resources a server can reach.

01

Keyring integration

Reference secrets from a supported operating-system keyring instead of duplicating literal credentials in configuration.

02

Docker isolation

Run supported stdio servers in containers with configured mounts and network access.

03

Resource limits

Set memory and CPU limits for containerized servers.

An example workflow

Give a local server only the resources it needs.

  1. Reference its credentials through a supported OS keyring.
  2. Optionally run the stdio server in Docker.
  3. Choose the mounts, network access and resource limits for that server.

Where the boundary is

Docker isolation is optional and requires a working Docker daemon. Access depends on your mounts and networking. Keyring availability depends on the host and selected secret provider.

Explore the rest of your setup