brig docs

Compare

Brig and Docker

On this page

Brig gives a coding agent a microVM with a kernel of its own, your project and nothing else, a network rule you write, and its login from your keychain, as open source with a test behind each claim. Docker runs an agent two ways: a dev container that shares the Docker host's kernel, and Docker Sandboxes, a microVM from a closed-source tool.

Anthropic's documentation lists a dev container as one option for unattended Claude Code, and names a dedicated VM for a repository you do not trust. Docker's sbx is the closest tool to Brig in shape. This page covers both. Brig compared puts them beside the other tools.

At a glance #

Brig Docker Sandboxes (sbx) Dev container
Made for Coding agents Coding agents A development environment
Runs on macOS 15 or newer on Apple silicon, and Linux with KVM macOS 14 or newer on Apple silicon, Ubuntu 24.04 or newer with KVM, Windows 11 Anywhere Docker runs
Kernel One kernel per sandbox, under a hypervisor One kernel per sandbox, under Docker's VMM The Docker host's kernel. On a Mac, the one Linux VM every container shares
Host files The project and the guest home, and nothing else from the host The workspace, through virtiofs, or a private clone of it Whatever you bind mount
Network An egress policy of hosts and ranges, enforced at a gateway or in nftables outside the guest Proxies on the host. HTTP rules by host, method and path. Other TCP by hostname. ICMP blocked Open, unless you add firewall rules inside the container
Credentials A secret store in the keychain, delivered by name as a file. The agent holds the value. v0.5.0 adds secret brokerage, and the guest then holds a placeholder A secret store in the keychain. The agent holds a sentinel the proxy swaps, unless a kit passes the token through Environment variables, or the login inside the container
Agent setup Eight built-in profiles Agent commands for Claude Code, Codex, Copilot, Cursor, Gemini and more You write devcontainer.json
Start Boots a kernel Boots a kernel Starts a container
Licence Apache-2.0, three repositories All rights reserved. The docs say local use is free An open specification. Anthropic's reference files are under its commercial terms

What Brig gives you #

A kernel per sandbox. Brig boots one kernel per sandbox. hvi, the VMM Brig uses on macOS, treats the guest as hostile and runs inside a Seatbelt profile of its own. The boundary in hvi describes it. Every process in a dev container makes its system calls to the Docker host's kernel. On a Mac, that kernel also serves every other container on the machine. A kernel bug reachable from the agent is a way out.

A network rule outside the guest. Brig enforces its policy at the gateway on macOS and in nftables on Linux, below the protocol, for every packet the guest sends. A host rule covers the names the guest resolves, and a cidr rule covers addresses it dials. A run on a backend that cannot enforce the policy is refused with exit code 7. See Enforcement. Docker's egress rules live in two proxies on the host, one for HTTP and one for other TCP, and ICMP is blocked. The dev container's reference firewall is a script inside the container, with NET_ADMIN capability, and the agent runs as a user in that same container.

Open source, end to end. Brig, hull and hvi are Apache-2.0, and Architecture says where to start reading each one. sbx is closed. Its VMM, its proxy and its secret handling are not readable. Its licence permits local use.

A test for each claim. Security states every boundary and its limits. Claims names the test behind each sentence, and a check runs on every pull request.

Linux hosts. Brig runs on Linux hosts with KVM, on x86-64 and arm64. sbx supports Ubuntu 24.04 and newer and does not test derivatives. A dev container on Linux runs on the host kernel.

Your login, from your keychain. Brig delivers the agent's login from a secret store in the keychain, as a file on a memory-backed mount that does not reach host disk. Credentials states each limit. Brig v0.5.0 adds secret brokerage, and the guest then holds a placeholder in place of the real value.

What each Docker path does #

A dev container is an ordinary container. Your editor builds it from devcontainer.json, bind mounts the repository, and runs the agent inside. Anthropic publishes a reference with a firewall script that allows a list of domains with iptables. The container shares the host kernel on Linux. On a Mac, it shares the one Linux kernel of the Docker Desktop VM with every other container. Anthropic's documentation says that under --dangerously-skip-permissions a dev container does "not prevent a malicious project from exfiltrating anything accessible inside the container". That includes the Claude Code credentials. It says to use one only with trusted repositories.

Docker Sandboxes is a separate tool, sbx. It needs no Docker Desktop and no Docker Engine. Each sandbox is a microVM with its own kernel and its own Docker daemon, on Hypervisor.framework, KVM or the Windows Hypervisor Platform. The workspace is mounted through virtiofs at the same path, or cloned. HTTP and HTTPS leave through a proxy on the host, and other TCP through a transparent proxy that takes hostname rules, with a domain list in three presets. Logins and API keys stay in the host keychain. The sandbox sees a sentinel, and the proxy swaps in the real value after the request has left the microVM. A kit can pass an OAuth token through instead, and a headless Linux host keeps the secrets in a file. Claude Code runs with --dangerously-skip-permissions inside it by default. The licence file says all rights reserved, and the documentation says local use is free.

When Docker fits #

  • Windows. sbx runs on Windows 11. Brig does not run on Windows.
  • Credentials, today. Under sbx, the agent holds a sentinel and the proxy swaps in the real key. Brig hands the agent the credential as a file on a memory-backed mount until v0.5.0 adds secret brokerage.
  • macOS 14. sbx supports macOS 14. Brig's default backend needs macOS 15. On macOS 14, Brig runs on the vz backend, without an egress policy.
  • Your editor in the container. VS Code, JetBrains and Codespaces open a dev container as the workspace. Brig runs the agent in a terminal, and your editor works on the project on the host.
  • Any Docker host. A dev container runs on any machine with Docker, Intel Macs and Windows included.

Run Claude Code under each #

Under Brig:

brig run claude ~/code/demo

Under Docker Sandboxes:

sbx run claude ~/code/demo

With a dev container, open the repository in an editor that supports the specification, with Anthropic's reference .devcontainer copied in, and run claude --dangerously-skip-permissions in its terminal.

Sources #

Read on 2026-10-06.

Type a command, a flag or an error message.