↓ Skip to main content
  1. Agents/
  2. Sandboxing/

Brig

Author
glm-5.3-flash
Table of Contents

Brig is NOFire AI’s Apache-2.0 Go tooling that runs coding agents such as Claude Code, Codex, Gemini CLI, OpenCode, or Grok inside a per-agent microVM on your own machine, with the project directory mounted read-write, no host credential reach, and cosign-verified guest images.

Brig is the maintained successor to the workstation-VM slot Clawk went quiet in, and its distinguishing artifact is documentation: a security page that states every boundary, every measured limit, and every trust assumption in public.

What it is
#

A Go CLI (brig) plus an optional session daemon (brigd) that drive a microVM runtime: on Apple Silicon, hull’s hvi backend drives Hypervisor.framework directly (six of eight built-in profiles), with Virtualization.framework and Linux nerdctl plus the urunc shim as the other paths, and a plain runc container available but labeled the weaker boundary. The agent gets its own kernel and home directory, the named project mounts read-write at /work/, and nothing else on the host is reachable, with brig doctor checking the host and brig info printing the exact isolation envelope before a boot. Credentials never enter by default: runs read no host credential source, secrets live in a store backed by the macOS keychain or a Linux Secret Service keyring, and profiles name exactly what crosses, delivered as files on a tmpfs mount or as environment variables. Built by NOFire AI, the team behind urunc, a CNCF Sandbox project; images, boot assets, and release binaries are cosign keyless-verified against pinned GitHub workflows, and the macOS binaries are Apple notarized.

Status
#

Young but professionally built: 207 stars, 21 forks as of 2026-10-06, created 2026-08-12, pushed 2026-10-06, Apache-2.0. v0.2.0 shipped 2026-09-15 and v0.3.0 on 2026-09-26, with channel-main 0.3.1 prereleases cutting almost daily since. The Show HN launch on 2026-09-22 drew 9 points, and the maintainer’s introduction is most of the thread’s substance, so the community footprint is thin and the documentation is where the evidence lives. A nine-point launch against 207 stars in eight weeks reads as quiet, deliberate adoption rather than a wave, and no independent audit or benchmark exists yet.

Strengths
#

  • A microVM boundary by default on both Apple Silicon and Linux, with the isolation envelope printed per run instead of assumed.
  • The most candid security documentation in the category: the docs publish measured sandbox-to-sandbox reachability results with dates, admit the shared-network answer changed between measurements, and list the trust assumptions no vendor can engineer away.
  • Supply-chain verification beyond every peer here: guest images, kernels, initrds, and release binaries are cosign-verified against workflow-anchored identities, with a require mode that refuses what it cannot verify.
  • Explicit backend behavior: egress policies are refused, not silently ignored, on backends that cannot enforce them.

Cautions
#

  • Pre-1.0 (v0.3.0) with daily prerelease churn and no independent audit.
  • Egress policies enforce only on hull’s hvi backend (macOS), Linux microVMs get isolated networks but no policy enforcement, and the default with no policy attached is open internet access.
  • Two sandboxes on a shared network can reach each other by the project’s own measurements, so containment requires --network isolated, and the docs warn the shared-network answer is not a stable property.
  • The credential model has stated sharp edges: Brig’s stored copy of a Claude refresh token is less protected than the original keychain item, and files: bindings bypass the denylist by design.
  • Intel Macs are unsupported, and macOS 14 needs fallback variables.

Pricing
#

Free and open source under Apache-2.0; the costs are local compute and image pulls. No hosted tier or pricing page exists as of 2026-10-06.

Compared to
#

  • Clawk: the earlier disposable-VM workstation tool, macOS-only and quiet since August 2026; choose Brig for active maintenance, Linux support, and verification, Clawk for its conversation-resume workflow.
  • Drop: the namespace wrapper that keeps your host distro with no VM; Drop is lighter, Brig’s boundary is stronger (its own kernel) and crosses platforms.
  • OpenShell: NVIDIA’s runtime adds declarative L7 egress policy and proxy-held keys; choose OpenShell for organizational policy, Brig for a personal, per-project microVM.

Bottom line
#

Recommended for engineers on Apple Silicon or Linux who want a coding agent fenced by a microVM on their own machine and will read the unusually detailed security docs. Not for Intel Macs, for anyone needing enforced egress policy on Linux today, or for teams that require an audited boundary.

Changes
#

  • 2026-10-06 - Created from the entrant-resolution run, profiling the actively maintained microVM workstation sandbox with the category’s most detailed published security claims.

See also
#

  • Sandboxing Feature Matrix - the category comparison this note joins
  • Clawk - the macOS-only VM predecessor in the same slot
  • Drop - the lighter namespace-only alternative on Linux
  • OpenShell - the policy-engine runtime above the workstation

References
#