http://treasurechest.i2p/setup.html
Trying to run it inside the VM would thwart my efforts to block outgoing traffic, so I prefer this risk to its alternative. On top of this, I apply some good practices for additional peace of mind: all the chest's services (HTTP and SFTP), plus I2P, run with the least privilege needed when a service needs to run as root (like the SFTP server, which needs to call chuid()), it is placed inside a chroot jail.