A VM. Not just a prompt.
A real Linux environment with Docker, git, compilers, and package managers. Give the agent room to work in a disposable guest.
Explore the runtimeIsolated VMs for coding agents
Disposable Linux VMs for Claude Code and Codex. Give your agents a full development environment, with a clear boundary between their work and your Mac.
iso up && iso claude
macOS 27+ · Apple Silicon · Built with Swift
The agent works inside. Your host stays outside.
# Your project. A separate Linux VM.
❯iso up
✓Linux VM ready
✓Workspace copied → /workspace
✓Host credential proxy connected
❯iso claude
Claude Code is running inside the VM.
Provider API keys stay on your Mac.
Illustrative session · after setup, with provider-only configured
Your familiar tools.
A different boundary.
Room to work. Limits you set.
Let the agent build, break, and try again.
Decide what crosses the
boundary.
A real Linux environment with Docker, git, compilers, and package managers. Give the agent room to work in a disposable guest.
Explore the runtimeRoute provider requests through a Swift host-side proxy. Required proxy mode keeps provider credentials out of the guest environment.
Meet the credential proxy
Inspect changes with iso diff, or stage files with
iso pull --review. Check the guest’s work before applying
it to your project.
Small CLI. Clear separation.
Prepare an image once. Start a VM for your project.
Let your favorite
agent get to work.
Create your config and build the template image.
Start a VM with your project at /workspace.
Run your agent with its tools inside the guest.
// A boundary you control.
{
"security": {
"preset": "provider-only"
},
"limits": {
"session_ttl": "8h"
}
}
The provider-only preset disables direct guest internet access, requires the credential proxy, and stages file returns. Set a session deadline, too.
Hardening is opt-in; the default is networked. No-egress mode can still reach services on your Mac. A VM is a boundary, not a guarantee. Read the trust model ↗
A little separation goes a long way
Build from source, prepare your environment, and give your next coding session a space of its own.
Read the getting started guidemacOS 27+ · Apple Silicon · Xcode 27
# Build the host, proxy, and VM runtime.
git clone --branch swift \
https://github.com/chr33s/coop.git
cd coop
python3 scripts/build-release.py --release
Extract the archive in .build/release-archive/ and
install all three executables together on PATH. The
Apple container service and guest kernel are also required.
Backend setup ↗
alias iso=coop
iso setup
cd ~/code/my-project
iso up
iso claude # or: iso codex
Run after installing the binaries. The alias applies to the current shell; add it to your shell configuration to keep it. Configure provider authentication before launching your agent. Configuration guide ↗
Source compatibility: this page uses isolate /
iso. The repository currently builds coop; the
session example adds an iso alias. Its configuration remains at
~/.coop/config.jsonc.