Isolated VMs for coding agents

Your agents.
Their own space.

Disposable Linux VMs for Claude Code and Codex. Give your agents a full development environment, with a clear boundary between their work and your Mac.

iso up && iso claude

macOS 27+ · Apple Silicon · Built with Swift

A sealed box inside a boundary.

The agent works inside. Your host stays outside.

DISPOSABLE LINUX VM
~/code/my-project

# Your project. A separate Linux VM.

❯iso up

✓Linux VM ready

✓Workspace copied → /workspace

✓Host credential proxy connected

❯iso claude

Claude Code is running inside the VM.

isolated Linux guestprovider-only preset

Host-side credential proxy

Provider API keys stay on your Mac.

outside the VM

Illustrative session · after setup, with provider-only configured

Your familiar tools.
A different boundary.

Claude Code Codex Docker git your toolchain

Room to work. Limits you set.

Full tools. A smaller blast radius.

Let the agent build, break, and try again.
Decide what crosses the boundary.

A VM. Not just a prompt.

A real Linux environment with Docker, git, compilers, and package managers. Give the agent room to work in a disposable guest.

Explore the runtime

Your keys. Your side.

Route provider requests through a Swift host-side proxy. Required proxy mode keeps provider credentials out of the guest environment.

Meet the credential proxy

Review what comes back.

Inspect changes with iso diff, or stage files with iso pull --review. Check the guest’s work before applying it to your project.

See staged pulls

Small CLI. Clear separation.

Three commands.
One clear boundary.

Prepare an image once. Start a VM for your project.
Let your favorite agent get to work.

  1. iso setup

    Create your config and build the template image.

  2. iso up

    Start a VM with your project at /workspace.

  3. iso claude # or: iso codex

    Run your agent with its tools inside the guest.

// A boundary you control.
{
  "security": {
    "preset": "provider-only"
  },
  "limits": {
    "session_ttl": "8h"
  }
}

Less access. On purpose.

The provider-only preset disables direct guest internet access, requires the credential proxy, and stages file returns. Set a session deadline, too.

proxy requiredstaged pulls8h session TTL

Hardening is opt-in; the default is networked. No-egress mode can still reach services on your Mac. A VM is a boundary, not a guarantee. Read the trust model ↗

A little separation goes a long way

Your next session,
a little more isolated.

Build from source, prepare your environment, and give your next coding session a space of its own.

Read the getting started guide

macOS 27+ · Apple Silicon · Xcode 27

# Build the host, proxy, and VM runtime.
git clone --branch swift \
  https://github.com/chr33s/coop.git
cd coop
python3 scripts/build-release.py --release

Extract the archive in .build/release-archive/ and install all three executables together on PATH. The Apple container service and guest kernel are also required. Backend setup ↗

Source compatibility: this page uses isolate / iso. The repository currently builds coop; the session example adds an iso alias. Its configuration remains at ~/.coop/config.jsonc.