Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Pi Pod is an open-source system for running Pi coding-agent sessions in remote pods on a server you control. Its architecture separates client apps, a control plane, identity services, and a native sandbox service—but the pods share the host kernel. That means Pi Pod provides process and resource isolation as documented by the project, not a separate-kernel virtual machine boundary. The operator remains responsible for the host, network exposure, credentials, and recovery.

How Pi Pod’s components fit together

Pi Pod’s repository describes a control plane and native sandbox service running on the same host. The CLI and phone apps are clients: they communicate with the server, which provides the REST API, session gateway, pod lifecycle management, and lifecycle workers. When a session needs a pod, the server starts one through the sandbox service. Pi runs inside that pod behind a small shim, while clients control sessions through the server gateway.

The project identifies a CLI, server, sandbox service, iOS and Android apps, and a self-host deployment. Its identity system uses Zitadel with OIDC; the repository says the server does not store passwords. The public Pi Pod page describes the product as a way to run Pi sessions in isolated sandboxes, while the repository says its hosted service is not yet available. In practice, the documented deployment is for operators who run the software themselves.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What boundary contains a pod—and what it does not

The self-host guide describes multiple isolated sandboxes inside one privileged container. The sandbox service uses the host cgroup namespace, mounts /sys/fs/cgroup read-write, and creates network namespaces. The project identifies the host kernel as the isolation boundary. These are project-documented implementation details, not evidence of independent penetration testing.

#1 Best Overall
CanaKit Raspberry Pi 5 Starter Kit PRO - Turbine Black (128GB Edition) (8GB RAM)
  • Includes Raspberry Pi 5 with 2.4Ghz 64-bit quad-core CPU (8GB RAM)
  • Includes 128GB Micro SD Card pre-loaded with 64-bit Raspberry Pi OS, USB MicroSD Card Reader
  • CanaKit Turbine Black Case for the Raspberry Pi 5
  • CanaKit Low Noise Bearing System Fan
  • Mega Heat Sink - Black Anodized

A pod is therefore not a virtual machine with its own kernel. Because the sandbox service is privileged and the host kernel underpins isolation, the project recommends using a dedicated machine before allowing untrusted users to run code. The operator’s host and its configuration are part of the security model.

Why the distinction matters for Pi

Pi’s official security documentation explains that generated commands, extensions, installers, language servers, and child processes run with the permissions of the account that started Pi unless an operating-system or virtualization boundary limits them. Pi’s project trust controls affect which project resources load; they do not themselves sandbox execution. Pi’s documentation puts the principle this way: “Safety comes from limiting the files, credentials, processes, and network services Pi can access and affect if a generated action is wrong or hostile.”

Pi’s isolation documentation also distinguishes putting all of Pi inside an environment from keeping Pi on the host and delegating only selected tools into it. In the tool-only pattern, the host Pi process and extensions that do not delegate remain outside that tool boundary. Writable mounts, environment variables, network access, or exposed Pi configuration can also bring host data or credentials into an environment. That is general Pi guidance; Pi Pod’s own boundary is the host-kernel-based sandbox described above.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What secrets can a pod access?

Pi Pod’s self-host guide says its API does not return stored secret values and that envelope encryption is intended to protect against database theft. That protection applies to stored data, not to secrets while they are in use: the control plane and an authorized pod can access secrets within their scope, and code running in that pod can read values it inherits. Treat template and init-script editors as trusted with the secrets available to the pods they configure.

The guide says a pod’s Pi auth file can contain provider API keys and leased OAuth access tokens, but not OAuth refresh tokens. Removing a credential from Pi Pod does not necessarily revoke it with the upstream provider. If a credential may have been exposed, revoke it with that provider as well. For disaster recovery, keep encryption keys separate from database backups and retain earlier key versions for as long as database backups encrypted under them may need restoring.

How network access and public exposure are handled

The self-host guide warns that the initial server port, 8080, listens on every interface. Do not expose it to the public internet before completing the documented public-deployment steps. It also warns that Docker-published ports may bypass host firewall rules such as ufw, so a firewall rule alone may not provide the protection an operator expects.

Rank #3
RasTech Raspberry Pi 5 8GB Kit 64GB Edition with Active Cooler,27W GaN 5.1V5A USB-C Power Supply,Pi5 8GB Board,64GB Card Readers Kit,Pi 5 Case,Dual 4K Micro HD Out Cables and User Manual
  • Pi5 8GB Pack: RasTech Pi 5 8GB kit includes 1 x Pi5 8GB board ,1 x 64GB Card, 2 x Card Readers,1 x Active Cooler,1 x Case for Pi5, 2 x 4K Micro HD Out Cable,1 x GaN 27W 5A USB-C Power supply,1 x Screwdriver and 1 x instructions.
  • Pi5 8GB Board: The Pi5 board is equipped with a 64-bit quad-core Arm Cortex-A76 processor running at 2.4GHz and an 800MHz VideoCore VII GPU with support for OpenGL ES 3.1 and Vulkan 1.2, which delivers a significant increase in graphics performance. Dual HD Out 4Kp60 display outputs and a built-in dual 4-channel MIPI camera/display transceiver provide state-of-the-art camera support. The Pi 5 offers a 2-3 times increase in CPU performance compare to Pi4.
  • Important Graphics Features: Equipped with an 800MHz VideoCore VII GPU and providing better graphics performance, suitable for multimedia applications,gaming,and graphics intensive tasks.Provides 1 UART interface,1 card slot that supports high-speed operation, 2 USB. 3 0.5 ports that support synchronous 0Gbps operation,2 USB 2.0 port ports,2 4Kp60 display outputs that support HDR.Built-in dedicated dual 4-channel 1Gbps MIPI DSI/CSI connectors,triple the total bandwidth.
  • Cooling Kit for Pi 5: Compatible with Active Cooler for Raspberry Pi5, It can provide Pi 5 board with better cooling effect in using. The Case can accurately access usb-c power jack,Micro HD Out ports, usb ports, Ethernet jack, card slot, power button, 4-lane MIPI DSI/CSI connectors and so on, and it also supports installation of cooling fan.
  • 64GB Card Kit and GaN 27W USB-C Power Supply: With extra 64GB card to store more files and card readers for multiple medium, keep better performance for Raspberry Pi 5, 27W USB C Power Supply is Compatible with Pi5 8GB, offers a variety of output voltage options, including 5.1V at 5A, 9.0V at 3.0A, 12.0V at 2.25A, and 15.0V at 1.8A, providing for different device requirements.

The guide’s public deployment example puts the API server and Zitadel behind a reverse proxy under separate HTTPS names, with the internal server port bound to loopback. Follow the current guide’s complete configuration rather than treating those elements as a complete deployment recipe on their own.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For pod traffic, Pi Pod documents a policy that keeps pods off private, shared, and reserved IP addresses regardless of egress mode. If a pod needs to reach a private destination, the operator must configure that private egress explicitly. This documented behavior should not be read as meaning that all outbound traffic is blocked, or that every deployment has an outbound allowlist.

Host requirements and pod capacity

The project’s self-host guide targets a Linux host with cgroup v2, Docker and the Compose plugin, Git, and OpenSSL. Its CLI installation instructions require Node 22.19 or later. The guide recommends 8 GB of RAM as a baseline and defines the standard pod and planning examples below. These are Pi Pod’s published 2026 planning figures, not independent performance benchmarks.

Documented item Project figure or behavior How to interpret it
Baseline host memory 8 GB RAM Pi Pod’s 2026 self-host recommendation.
Standard pod 2 vCPU and 4 GiB memory The project’s documented standard pod shape.
Planning example: 8 GB host One standard pod at a time Pi Pod’s 2026 planning example under its documented setup.
Planning example: 16 GB host Three standard pods Pi Pod’s 2026 planning example under its documented setup.
Default per-pod ceilings 8 vCPU, 24 GiB memory, and 20 GiB disk Project defaults; operators can lower or adjust them.

Do not equate a CPU ceiling with a memory reservation. The guide says CPU is capped, while the full memory allocation counts against admission for each live pod. A pod retains that share until it stops, including during the documented idle-stop behavior. The guide also cautions that setting a Docker memory limit on the sandbox service does not, by itself, bound nested sandbox cgroups as configured. For capacity control, it points operators to the fleet reserve and fleet ceiling settings.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Upgrades, backups, and workspace recovery

The documented upgrade procedure rebuilds the server and sandbox from the checked-out project version. If the sandbox image changes, recreating it ends live sessions. Pod workspaces remain on the sandbox_state volume, allowing a user to attach again after the change.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Pi Pod’s guide says database backups are written during Compose startup and that the newest seven are retained by default. That retention is not an off-host backup: the operator must copy backups elsewhere. Workspace persistence has a separate path. Sandbox workspaces are not stored in Postgres; only archived workspaces reach object storage, and the default local archive driver does not survive loss of the host.

Best Value
CanaKit Raspberry Pi 5 Desktop PC with SSD (Fully Assembled) (256 GB SSD)
  • Fully assembled for plug-and-play operation
  • Includes Raspberry Pi 5 with 8GB RAM
  • 256 GB PCIe Pi NVMe SSD (Pre-loaded with Pi 64-Bit OS)
  • M.2 HAT+
  • CanaKit Turbine Black Case for the Pi 5
  • Back up the database and copy those backups off the server.
  • Back up Zitadel’s master key and Pi Pod’s secret encryption key offline and separately from database backups.
  • Retain older key versions while any database backups that require them remain in the recovery window.
  • Decide separately how active sandbox workspaces and archived workspaces will be preserved and restored.

A database dump alone is not a complete recovery plan: restoring the database, decrypting secrets, and recovering workspace files involve different data and dependencies.

Who should consider self-hosting Pi Pod?

Pi Pod may suit an operator who wants to run Pi sessions remotely, manage the server and identity setup, and accept responsibility for a shared-kernel isolation boundary. It is not a set-and-forget security perimeter. Before offering pods to other people or running untrusted code, consider whether a dedicated host, deliberate egress configuration, tightly scoped secrets, and a tested off-host recovery plan meet your threat model.

Project defaults and implementation details can change. Check Pi Pod’s current repository and self-host guide, as well as Pi’s current security and isolation documentation, before deploying or relying on a specific setting.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Quick Recap

Bestseller No. 1
CanaKit Raspberry Pi 5 Starter Kit PRO - Turbine Black (128GB Edition) (8GB RAM)
CanaKit Raspberry Pi 5 Starter Kit PRO - Turbine Black (128GB Edition) (8GB RAM)
Includes Raspberry Pi 5 with 2.4Ghz 64-bit quad-core CPU (8GB RAM); CanaKit Turbine Black Case for the Raspberry Pi 5
$259.95
Bestseller No. 5
CanaKit Raspberry Pi 5 Desktop PC with SSD (Fully Assembled) (256 GB SSD)
CanaKit Raspberry Pi 5 Desktop PC with SSD (Fully Assembled) (256 GB SSD)
Fully assembled for plug-and-play operation; Includes Raspberry Pi 5 with 8GB RAM; 256 GB PCIe Pi NVMe SSD (Pre-loaded with Pi 64-Bit OS)
$339.97

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.