brig docs

Compare

Brig and Apple container

On this page

Brig gives a coding agent a microVM with a kernel of its own, your project and nothing else, a network rule you write, and its login from your keychain, on macOS 15 and newer and on Linux. Apple's `container` runs each Linux container in a lightweight VM of its own on macOS 26, as a container runtime with no agent, policy or credential layer.

Both are open source under Apache-2.0, and both put one kernel under each workload on Apple silicon. Brig compared puts them beside the other tools.

At a glance #

Brig Apple container
Made for Coding agents Building and running OCI containers on a Mac
Runs on macOS 15 or newer on Apple silicon, and Linux macOS 26 on Apple silicon. macOS 15 with limits
Kernel One kernel per sandbox, under a hypervisor One kernel per container, under Virtualization.framework
Host files The project and the guest home, and nothing else from the host The volumes you mount, through virtio-fs, read-write or read-only
Network An egress policy of hosts and ranges, enforced at a gateway outside the guest. offline has no route out A network per group of containers, with an address each. --internal makes a network with no way out. No rule by host
Credentials A secret store in the keychain, delivered by name as a file Registry logins in the keychain. --env passes a variable. --ssh mounts the host's SSH agent socket
Agent setup Eight built-in profiles None. You bring an image and a command
Published ports --publish, loopback by default --publish
Licence Apache-2.0 Apache-2.0

What Brig gives you #

A network rule. You attach a policy of hosts and ranges, and Brig enforces it at the gateway, outside the guest. A run on a backend that cannot enforce the policy is refused with exit code 7. See Networking. container gives a container a network and an address, or an internal network with no way out. It has no rule for where the container can connect.

The agent's login, from your keychain. Brig keeps the agent's login in a secret store, and a profile delivers it by name as a file on a memory-backed mount. The file does not reach host disk, and a deny list keeps a metered key out of the guest. Credentials states each limit. Brig v0.5.0 adds secret brokerage, and the guest then holds a placeholder in place of the real value. container keeps registry logins in the keychain, and has no store for an agent's login.

Profiles and sessions. A Brig profile names the image, the paths the agent keeps between runs, the credentials it gets and the network it needs. A session carries that state, and brig run resumes it. With container, you compose the same thing from container run flags, and you keep the login inside the container or in a volume you manage.

The host's SSH agent stays on the host. Brig forwards no SSH agent and reads no host credential source on a run. See What the agent cannot reach.

Linux, and full support on macOS 15. Brig runs on macOS 15 and newer, and on Linux hosts with KVM. container supports macOS 26, and runs on macOS 15 without container networks.

What Apple container does #

container is Apple's command line tool for OCI images on a Mac. It builds images, pulls them, and runs each container in a lightweight VM. The default kernel at release 1.5.0 is a Kata Containers build. Its technical overview states that each container "has the isolation properties of a full VM". A small init process inside the guest takes commands over vsock.

Volumes mount through virtio-fs. Named volumes are ext4 disk images. Containers on one network reach each other, and networks are isolated from one another. The tool supports macOS 26. It runs on macOS 15 without container networks, and the maintainers do not address issues there.

When Apple container fits #

  • Any container workload. container builds images and runs services. It is a general runtime. Brig runs an agent and the stack a profile declares.
  • Apple's VMM. Apple maintains the Containerization framework, on Virtualization.framework. Brig's VMM on macOS, hvi, is a project of Brig's own. It is in process for an external security audit, with no formal third-party review published at this time. Architecture describes its boundary.
  • The SSH agent. --ssh hands a container the host's SSH agent socket. Brig does not forward the agent.

Run Claude Code under each #

Under Brig:

brig run claude ~/code/demo

Under container, with an image that has Claude Code installed:

container run -it --volume ~/code/demo:/work/demo --volume ~/.claude:/root/.claude \
  --workdir /work/demo <image> claude

The container line mounts ~/.claude read-write for the settings. On a Mac, Claude Code keeps the login in the keychain, so the agent asks you to log in again inside. The container has the whole network. Brig's profile does the same work, with the login from the secret store and a policy on the network.

Sources #

Read on 2026-10-06.

Type a command, a flag or an error message.