brig docs

Compare

Brig and nono

On this page

Brig gives a coding agent a microVM with a kernel of its own, your project and nothing else, a network rule you write, and its login from your keychain. nono runs the agent as a process on your machine, confined with Landlock on Linux and Seatbelt on macOS.

nono is the closest tool to Brig in purpose. Both wrap Claude Code, Codex and the other agents from the outside. Both deny host files by default, and both can filter the network by hostname. Brig compared puts both beside the other tools.

At a glance #

Brig nono
Made for Coding agents Coding agents, and the tools they call
Runs on macOS 15 or newer on Apple silicon, and Linux macOS 10.15 or newer, Linux 5.13 or newer, and WSL2
Kernel One kernel per sandbox, under a hypervisor The host kernel. The project states it is not a VM
Host files The project and the guest home, and nothing else from the host Deny by default. The current directory after a prompt, plus the paths you allow
Network An egress policy of hosts and ranges, enforced at a gateway or in nftables outside the guest. offline has no route out Open by default. Block all with a kernel filter, or allow domains through a proxy on the host
Credentials A secret store, delivered by name as a file or a variable. The agent holds the real value. v0.5.0 adds secret brokerage, and the guest then holds a placeholder A proxy on the host adds the real key to allowed requests. The agent holds a placeholder
Agent setup Eight built-in profiles A profile registry, and client guides for Claude Code and Codex
Start Boots a kernel Starts a process
Needs Homebrew on macOS. KVM and the runtime bundle on Linux Nothing beyond the kernel. No root, no daemon
Licence Apache-2.0 Apache-2.0

What Brig gives you #

A kernel the host does not share. The agent's system calls go to a kernel inside the microVM. hvi, the VMM Brig uses on macOS, treats the guest as hostile and runs inside a Seatbelt profile of its own. The boundary in hvi describes it. Under nono, the agent's system calls go to your kernel, and Landlock and Seatbelt filter them. nono's architecture overview states what it does not protect against: kernel exploits, covert channels and resource exhaustion on macOS.

The credential design rests on that same boundary. Under Brig, the agent holds its own credential, and the host's keychain is on the other side of the hypervisor. nono's proxy and its keystore run on the host, beside the sandbox, and whatever gets past Landlock or Seatbelt reaches both.

A network filter outside the guest. Brig enforces your policy at the gateway on macOS and in nftables on Linux. A run on a backend that cannot enforce it is refused with exit code 7. See Enforcement. nono's domain filter is a proxy on the host, reached through one allowed port. Everything the kernel filter cannot express goes through that proxy.

Only the project from the host. The guest has the project and the guest home, and no other host path exists in it. See Project mounts. nono shares the current directory, and by default asks first, then adds the paths you allow. The sandbox still runs on your filesystem, and nono documents a window between path canonicalization and sandbox application.

A test for each promise. Claims names the Go test, smoke assertion or VM check that defends every sentence of the security model. hvi is in process for an external security audit, with no formal third-party review published at this time. nono's security page states that its guarantees "are not yet stable" and that production use "is not recommended at this stage".

The whole agent, with its state. Brig keeps a session with the agent's state and the project. You can stop it, run the same ref again later with its state, and remove it clean. nono wraps the command you give it.

What nono does #

nono runs one command under a deny-by-default sandbox that it builds before exec. On Linux, it uses Landlock for the filesystem and TCP, and cgroup v2 for memory and process limits. In the restricted network modes, a seccomp filter denies Internet sockets and io_uring. On macOS, it writes a Seatbelt profile and applies it with sandbox_init. The agent is a process on your machine, with the paths you allowed and nothing else.

The network is open by default. --block-net is a kernel filter and lets nothing out. --allow-domain starts an HTTP proxy outside the sandbox and allows only that port. The proxy filters by domain and by URL pattern, and returns 403 to the rest. A rule by method and path applies to a credential route.

The same proxy delivers credentials. The agent gets a placeholder token and calls the proxy. The proxy swaps in the real key from the keychain, 1Password, Bitwarden or a file, and forwards the request over TLS. The project states that "the agent never sees the API key".

nono also sandboxes the tools an agent calls, such as git, gh and kubectl, each in its own command sandbox behind a broker.

When nono fits #

  • Start time. nono starts a process. Brig boots a kernel.
  • Older hardware and systems. nono runs on an Intel Mac, on macOS 10.15, and on a Linux host with no KVM. Brig needs Apple silicon and macOS 15, or a Linux host with /dev/kvm.
  • The agent never holds the key, today. In nono's proxy mode, the real credential stays on the host and enters only the requests that leave. Brig hands the agent the credential as a file on a memory-backed mount, and Credentials states that limit. Brig v0.5.0 adds secret brokerage, and the guest then holds a placeholder.
  • Finer network rules. nono filters a request by URL pattern, and a credential route by method and path. Brig filters a connection by hostname and range.
  • The host's tools. The agent runs on your macOS or Linux, with your compilers and your shell. Under Brig, the agent runs in a Linux guest image.

Run Claude Code under each #

Under Brig:

brig run claude ~/code/demo

Under nono, with its Claude Code profile:

cd ~/code/demo
nono run --profile nolabs-ai/claude -- claude

The profile shares the current directory read-write, knows Claude Code's paths, and leaves the network open. --allow-domain api.anthropic.com turns on the proxy and allows that host. Under Brig, the same rule is a policy attached to the profile, and the guest sees no proxy.

Sources #

Read on 2026-10-06.

Type a command, a flag or an error message.