
Brig is NOFire AI's Apache-2.0 Go tooling that runs coding agents such as Claude Code, Codex, Gemini CLI, OpenCode, or Grok inside a per-agent microVM on your own machine, with the project directory mounted read-write, no host credential reach, and cosign-verified guest images.

**Brig is the maintained successor to the workstation-VM slot Clawk went quiet in, and its distinguishing artifact is documentation: a security page that states every boundary, every measured limit, and every trust assumption in public.**

## What it is

A Go CLI (brig) plus an optional session daemon (brigd) that drive a microVM runtime: on Apple Silicon, hull's hvi backend drives Hypervisor.framework directly (six of eight built-in profiles), with Virtualization.framework and Linux nerdctl plus the urunc shim as the other paths, and a plain runc container available but labeled the weaker boundary.
The agent gets its own kernel and home directory, the named project mounts read-write at /work/<name>, and nothing else on the host is reachable, with `brig doctor` checking the host and `brig info` printing the exact isolation envelope before a boot.
Credentials never enter by default: runs read no host credential source, secrets live in a store backed by the macOS keychain or a Linux Secret Service keyring, and profiles name exactly what crosses, delivered as files on a tmpfs mount or as environment variables.
Built by NOFire AI, the team behind urunc, a CNCF Sandbox project; images, boot assets, and release binaries are cosign keyless-verified against pinned GitHub workflows, and the macOS binaries are Apple notarized.

## Status

Young but professionally built: 207 stars, 21 forks as of 2026-10-06, created 2026-08-12, pushed 2026-10-06, Apache-2.0.
v0.2.0 shipped 2026-09-15 and v0.3.0 on 2026-09-26, with channel-main 0.3.1 prereleases cutting almost daily since.
The Show HN launch on 2026-09-22 drew 9 points, and the maintainer's introduction is most of the thread's substance, so the community footprint is thin and the documentation is where the evidence lives.
**A nine-point launch against 207 stars in eight weeks reads as quiet, deliberate adoption rather than a wave, and no independent audit or benchmark exists yet.**

## Strengths

- A microVM boundary by default on both Apple Silicon and Linux, with the isolation envelope printed per run instead of assumed.
- The most candid security documentation in the category: the docs publish measured sandbox-to-sandbox reachability results with dates, admit the shared-network answer changed between measurements, and list the trust assumptions no vendor can engineer away.
- Supply-chain verification beyond every peer here: guest images, kernels, initrds, and release binaries are cosign-verified against workflow-anchored identities, with a `require` mode that refuses what it cannot verify.
- Explicit backend behavior: egress policies are refused, not silently ignored, on backends that cannot enforce them.

## Cautions

- Pre-1.0 (v0.3.0) with daily prerelease churn and no independent audit.
- Egress policies enforce only on hull's hvi backend (macOS), Linux microVMs get isolated networks but no policy enforcement, and the default with no policy attached is open internet access.
- Two sandboxes on a shared network can reach each other by the project's own measurements, so containment requires `--network isolated`, and the docs warn the shared-network answer is not a stable property.
- The credential model has stated sharp edges: Brig's stored copy of a Claude refresh token is less protected than the original keychain item, and `files:` bindings bypass the denylist by design.
- Intel Macs are unsupported, and macOS 14 needs fallback variables.

## Pricing

Free and open source under Apache-2.0; the costs are local compute and image pulls.
No hosted tier or pricing page exists as of 2026-10-06.

## Compared to

- [Clawk](../clawk/index.md): the earlier disposable-VM workstation tool, macOS-only and quiet since August 2026; choose Brig for active maintenance, Linux support, and verification, Clawk for its conversation-resume workflow.
- [Drop](../drop/index.md): the namespace wrapper that keeps your host distro with no VM; Drop is lighter, Brig's boundary is stronger (its own kernel) and crosses platforms.
- [OpenShell](../openshell/index.md): NVIDIA's runtime adds declarative L7 egress policy and proxy-held keys; choose OpenShell for organizational policy, Brig for a personal, per-project microVM.

## Bottom line

**Recommended for engineers on Apple Silicon or Linux who want a coding agent fenced by a microVM on their own machine and will read the unusually detailed security docs.**
Not for Intel Macs, for anyone needing enforced egress policy on Linux today, or for teams that require an audited boundary.

## Changes

- 2026-10-06 - Created from the entrant-resolution run, profiling the actively maintained microVM workstation sandbox with the category's most detailed published security claims.

## See also

- [Sandboxing Feature Matrix](../sandboxing-feature-matrix/index.md) - the category comparison this note joins
- [Clawk](../clawk/index.md) - the macOS-only VM predecessor in the same slot
- [Drop](../drop/index.md) - the lighter namespace-only alternative on Linux
- [OpenShell](../openshell/index.md) - the policy-engine runtime above the workstation

## References

- https://github.com/brig-sh/brig - repository, README, platform table, install, verification defaults
- https://github.com/brig-sh/brig/releases - the v0.2.0, v0.3.0, and channel-main release record
- https://brig.sh/docs/quickstart/ - the doctor/run/stop workflow, the execution envelope, host support
- https://brig.sh/docs/security/ - the boundary claims, measured shared-network results, credential limits, and trust assumptions
- https://hn.algolia.com/api/v1/items/49802729 - the 9-point Show HN launch by NOFire AI's founder
