brig docs

Compare

Brig compared

On this page

Brig gives a coding agent a machine of its own on your computer. The agent gets a kernel, your project and nothing else, a network rule you write, and its login from your keychain, in one command. This page scores Brig and every other sandbox people run agents in against the five things an unattended agent needs.

The tools fall into three kinds. A process sandbox filters what a process can ask the host kernel for: bubblewrap, Seatbelt, nono, and the sandboxes inside Claude Code, Codex and Cursor. A microVM gives the agent a kernel of its own on your machine: Brig, Docker Sandboxes, Apple container and microsandbox. A cloud sandbox runs the code on someone else's machine: E2B and Daytona.

What a coding agent needs #

Need Why
Its own kernel The agent runs code it did not write, from packages, from the web and from the model. A kernel bug reachable from inside a process sandbox is a way out. A microVM puts a hypervisor in the path
The project, and nothing else The agent needs your repository. It does not need your SSH keys, your cloud credentials, your browser profile or your other repositories
An egress rule by host, enforced outside A sandbox with open internet can send anything it reads anywhere. The rule must name hosts, cover every protocol, and sit where the agent cannot reach it
Credentials by name, off the disk The agent needs its login and perhaps one token. It must get those and no others, and the copy must not reach host disk
An agent in one command The tool must know the agent's paths, its login and its settings, so a run needs no assembly

Scorecard #

Each cell says what the tool does for that need. The pages linked in the first column give the detail and the sources.

Tool Own kernel Project only Egress by host Credentials One command
Brig Yes. hvi on macOS, KVM on Linux Yes. The project and the guest home Yes. Hosts and ranges, at a gateway or in nftables outside the guest Yes. A keychain store, delivered by name as a file. v0.5.0 adds brokerage, with a placeholder in the guest Yes. Eight built-in profiles
bubblewrap No. Namespaces on the host kernel Yes, if you bind only the project No. All or nothing No. Environment variables No. You write the bind list
Seatbelt No. A policy in the host kernel Yes, if the profile allows it. Most profiles read the whole disk No. No rule by hostname No No. You write the profile
nono No. Landlock and Seatbelt on the host kernel Yes. Deny by default Partial. A proxy on the host, or block all Yes. A proxy adds the key to allowed requests Yes. Profiles and client guides
Claude Code, Codex, Cursor No. Seatbelt, bubblewrap and Landlock on the host kernel No. Reads the whole disk, writes the project Partial. A proxy on the host with a domain list Partial. Claude Code masks at the proxy Yes. Built in
Docker Sandboxes Yes. A microVM per sandbox Yes. The workspace Partial. An HTTP proxy, with address rules for other TCP Yes. A keychain store, with a sentinel the proxy swaps Yes. Agent commands
Dev container No. The Docker host's kernel Yes, if you mount only the project No. A firewall script inside the container No. Variables, or the login inside No. You write devcontainer.json
Apple container Yes. A VM per container Yes. The volumes you mount No No. Registry logins only No. You bring an image
microsandbox Yes. A libkrun microVM Yes. The directory you mount Yes. Hostname and address rules, checked on the host Yes. A placeholder the host swaps on allowed hosts No. A recipe per agent
E2B, Daytona Yes, on their machines. Daytona's default is a container Your project is uploaded Yes. Lists by host and range Partial. Stored with the provider Yes, through an SDK

What Brig gives you #

Brig is the one tool on the list that meets all five on your own machine, on macOS and on Linux, as open source.

  • A kernel per sandbox. On macOS, hvi boots the guest on Hypervisor.framework and runs inside a Seatbelt profile of its own. On Linux, urunc boots it on Cloud Hypervisor. Architecture shows each layer.
  • Your project, and nothing else from the host. The guest sees the project at /work/<name> and its own home. Your keychain, SSH agent and other repositories are not there. Security lists what the agent can and cannot reach.
  • A network rule you write. A policy names the hosts and ranges the agent can reach. Brig enforces it at the gateway on macOS and in nftables on Linux, and refuses to boot where it cannot. --network offline leaves no route out. Networking has the format and a recording.
  • Logins from your keychain. brig secret import claude-code carries your login in once. Every run reads that store and delivers the credential as a file on a memory-backed mount. Secrets covers the store.
  • One command per agent. brig run claude ~/code/demo opens Claude Code in its sandbox. Eight profiles ship: Claude Code, Claude Desktop, Codex, Cursor, Gemini CLI, Grok, OpenCode and a plain Ubuntu shell.

microsandbox meets the first four. Its recipe installs the agent once per sandbox. Docker Sandboxes gives a microVM and a keychain store from a closed-source tool. nono is the nearest process sandbox, and runs on an Intel Mac and on a Linux host with no KVM.

Brig states its limits on the security model page. It needs Apple silicon and macOS 15 or newer, or a Linux host with KVM. A sandbox boots a kernel, so a cold start takes longer than a process sandbox. The agent holds its credential, where nono, Docker Sandboxes and Claude Code's mask keep the real value on the host. Brig v0.5.0 adds secret brokerage, and the guest then holds a placeholder. hvi, the VMM on macOS, is in process for an external security audit, and no formal third-party review is published at this time.

Other tools #

These do not have a page of their own. Each is a sandbox, and none is built for a coding agent on your machine.

Tool What it is Why it is not on the scorecard
Firecracker, Kata Containers MicroVM runtimes for Linux servers Linux and KVM only. Firecracker needs root for the network setup, and Kata's shim and virtiofsd run as root. No agent, credential or egress layer. Brig's Linux path uses a cousin, Cloud Hypervisor, through urunc
gVisor A user-space kernel for containers Linux only. It narrows the host kernel's surface, and still runs on it. Gemini CLI can use it
microsandbox A microVM sandbox for untrusted code, with host-side network rules and placeholder secrets It is on the scorecard. Its Claude Code guide installs the agent with a recipe, once per sandbox, and its README calls it beta. The nearest tool to Brig in mechanism
Lima, OrbStack Linux VMs on a Mac General development VMs, with no agent, credential or egress layer. OrbStack runs one VM shared by every container and machine, and its documentation says an isolated machine is not a substitute for a full VM against malicious code
Firejail, nsjail Linux namespace sandboxes Shared kernel. Firejail is setuid root, and its man page says this is a risk
Landlock A Linux kernel mechanism A building block, not a tool. nono and Cursor use it

Sources #

Each linked page lists its sources with the date they were read. The facts about Brig come from Security, Networking, Architecture and Runtimes on this site.

Type a command, a flag or an error message.