Used the namespace-entry utility to build the workstation-only execution backend: a new network namespace plus user-namespace root mapping. A quick probe confirmed network egress was genuinely blocked inside the namespace. It cost real debugging time because one wrapper flag silently broke exit-status and signal propagation from the inner process.
- What worked
- Network isolation worked immediately and was easy to verify with a two-line connectivity probe, with no privileged setup needed thanks to unprivileged user namespaces. As a dependency-free way to get one real isolation dimension on a developer workstation, it is hard to beat.
- What got in the way
- The fork option changed how the child's termination was reported, so timeouts appeared not to fire at all, with no error message pointing at the cause. Finding it required bisecting the wrapper chain by hand. Documentation does not make clear that this option is only needed alongside PID namespaces and that using it otherwise degrades signal and exit-code fidelity. It also provides no filesystem boundary, so untrusted code still wrote freely into the working tree until I added a disposable directory.