Compare
Brig and Docker
On this page
Brig gives a coding agent a microVM with a kernel of its own, your project and nothing else, a network rule you write, and its login from your keychain, as open source with a test behind each claim. Docker runs an agent two ways: a dev container that shares the Docker host's kernel, and Docker Sandboxes, a microVM from a closed-source tool.
Anthropic's documentation lists a dev container as one option for unattended Claude Code, and names a dedicated VM for a repository you do not trust. Docker's sbx is the closest tool to Brig in shape. This page covers both. Brig compared puts them beside the other tools.
At a glance #
| Brig | Docker Sandboxes (sbx) |
Dev container | |
|---|---|---|---|
| Made for | Coding agents | Coding agents | A development environment |
| Runs on | macOS 15 or newer on Apple silicon, and Linux with KVM | macOS 14 or newer on Apple silicon, Ubuntu 24.04 or newer with KVM, Windows 11 | Anywhere Docker runs |
| Kernel | One kernel per sandbox, under a hypervisor | One kernel per sandbox, under Docker's VMM | The Docker host's kernel. On a Mac, the one Linux VM every container shares |
| Host files | The project and the guest home, and nothing else from the host | The workspace, through virtiofs, or a private clone of it | Whatever you bind mount |
| Network | An egress policy of hosts and ranges, enforced at a gateway or in nftables outside the guest | Proxies on the host. HTTP rules by host, method and path. Other TCP by hostname. ICMP blocked | Open, unless you add firewall rules inside the container |
| Credentials | A secret store in the keychain, delivered by name as a file. The agent holds the value. v0.5.0 adds secret brokerage, and the guest then holds a placeholder | A secret store in the keychain. The agent holds a sentinel the proxy swaps, unless a kit passes the token through | Environment variables, or the login inside the container |
| Agent setup | Eight built-in profiles | Agent commands for Claude Code, Codex, Copilot, Cursor, Gemini and more | You write devcontainer.json |
| Start | Boots a kernel | Boots a kernel | Starts a container |
| Licence | Apache-2.0, three repositories | All rights reserved. The docs say local use is free | An open specification. Anthropic's reference files are under its commercial terms |
What Brig gives you #
A kernel per sandbox. Brig boots one kernel per sandbox. hvi, the VMM Brig uses on macOS, treats the guest as hostile and runs inside a Seatbelt profile of its own. The boundary in hvi describes it. Every process in a dev container makes its system calls to the Docker host's kernel. On a Mac, that kernel also serves every other container on the machine. A kernel bug reachable from the agent is a way out.
A network rule outside the guest. Brig enforces its policy at the gateway on macOS and in nftables on Linux, below the protocol, for every packet the guest sends. A host rule covers the names the guest resolves, and a cidr rule covers addresses it dials. A run on a backend that cannot enforce the policy is refused with exit code 7. See Enforcement. Docker's egress rules live in two proxies on the host, one for HTTP and one for other TCP, and ICMP is blocked. The dev container's reference firewall is a script inside the container, with NET_ADMIN capability, and the agent runs as a user in that same container.
Open source, end to end. Brig, hull and hvi are Apache-2.0, and Architecture says where to start reading each one. sbx is closed. Its VMM, its proxy and its secret handling are not readable. Its licence permits local use.
A test for each claim. Security states every boundary and its limits. Claims names the test behind each sentence, and a check runs on every pull request.
Linux hosts. Brig runs on Linux hosts with KVM, on x86-64 and arm64. sbx supports Ubuntu 24.04 and newer and does not test derivatives. A dev container on Linux runs on the host kernel.
Your login, from your keychain. Brig delivers the agent's login from a secret store in the keychain, as a file on a memory-backed mount that does not reach host disk. Credentials states each limit. Brig v0.5.0 adds secret brokerage, and the guest then holds a placeholder in place of the real value.
What each Docker path does #
A dev container is an ordinary container. Your editor builds it from devcontainer.json, bind mounts the repository, and runs the agent inside. Anthropic publishes a reference with a firewall script that allows a list of domains with iptables. The container shares the host kernel on Linux. On a Mac, it shares the one Linux kernel of the Docker Desktop VM with every other container. Anthropic's documentation says that under --dangerously-skip-permissions a dev container does "not prevent a malicious project from exfiltrating anything accessible inside the container". That includes the Claude Code credentials. It says to use one only with trusted repositories.
Docker Sandboxes is a separate tool, sbx. It needs no Docker Desktop and no Docker Engine. Each sandbox is a microVM with its own kernel and its own Docker daemon, on Hypervisor.framework, KVM or the Windows Hypervisor Platform. The workspace is mounted through virtiofs at the same path, or cloned. HTTP and HTTPS leave through a proxy on the host, and other TCP through a transparent proxy that takes hostname rules, with a domain list in three presets. Logins and API keys stay in the host keychain. The sandbox sees a sentinel, and the proxy swaps in the real value after the request has left the microVM. A kit can pass an OAuth token through instead, and a headless Linux host keeps the secrets in a file. Claude Code runs with --dangerously-skip-permissions inside it by default. The licence file says all rights reserved, and the documentation says local use is free.
When Docker fits #
- Windows.
sbxruns on Windows 11. Brig does not run on Windows. - Credentials, today. Under
sbx, the agent holds a sentinel and the proxy swaps in the real key. Brig hands the agent the credential as a file on a memory-backed mount until v0.5.0 adds secret brokerage. - macOS 14.
sbxsupports macOS 14. Brig's default backend needs macOS 15. On macOS 14, Brig runs on thevzbackend, without an egress policy. - Your editor in the container. VS Code, JetBrains and Codespaces open a dev container as the workspace. Brig runs the agent in a terminal, and your editor works on the project on the host.
- Any Docker host. A dev container runs on any machine with Docker, Intel Macs and Windows included.
Run Claude Code under each #
Under Brig:
brig run claude ~/code/demoUnder Docker Sandboxes:
sbx run claude ~/code/demoWith a dev container, open the repository in an editor that supports the specification, with Anthropic's reference .devcontainer copied in, and run claude --dangerously-skip-permissions in its terminal.
Sources #
Read on 2026-10-06.
- Docker Sandboxes, its architecture, credentials and network access controls. Release 0.47.0, 2026-10-05. Licence.
- Why microVMs, Docker's architecture post.
- Claude Code dev container and the reference files in anthropics/claude-code.