What the cage does and doesn't do.
- The rest of your home (
~/.ssh, other repos). bur refuses to start when the project root would resolve to$HOMEitself - the classic trap is a dotfiles.gitin~- so the home mount can never happen by accident; a.bur.yamlplaced there is the explicit opt-in. - Your nix store (mounted read-only), your OS.
- Workspace file ownership - the agent runs as your uid via
--userns=keep-id, so workspace files stay yours. - Published
ports:bind to127.0.0.1by default, so a service the agent starts is reachable from the host but not the LAN. Opt into wider exposure per-port with an explicit host IP ("0.0.0.0:5173:5173"). - Your display server. Clipboard paste goes through a read-only bridge (text and image types only); no Wayland or X11 socket is ever mounted, and clipboard writes are not bridged - an agent that could seed your clipboard could poison your next paste into a terminal.
- The project mount is your live checkout, fully writable - including
.git, so local history can go down with the ship. The remote is the real safety net, and since neither~/.sshnor~/.git-credentialsis mounted, the agent normally has no way to push to it either. - A cloned repo is trusted input before any cage exists: its
.bur.yamlcan add mounts, publish ports, set env, and replace the command, and its devshell (shell.nix/ flake) is evaluated and built on the host whenburstarts. Review both before the first run in an untrusted checkout. ~/.claudeis mounted rw - the agent can edit its own global settings.- Secrets you pass via
envor.bur.env+ open egress = an exfiltration channel. Keeping them out of git does not keep them out of the cage. Usenetwork: nonefor sensitive work; a deny-by-default egress allowlist (network: filtered) is the planned v2 flagship. - Host services bound to
127.0.0.1are unreachable even withhostAccess(pasta mapshost.containers.internalto the host's external address) - bind0.0.0.0or, better, run the service in the sandbox. - The host clipboard is readable by the agent the whole time a sandbox
runs - that is what makes paste work. Copy a password from your manager
mid-session and the agent could read it; set
clipboard: falsefor sensitive work. bur-pkglets the agent fetch any nixpkgs package via the host - trusted code from your own nixpkgs pin, never evaluated from agent-writable files, and gone after the next GC, but still your disk and bandwidth. Setnix.pkgAdd: falseto close that valve.
Changing the environment mid-session is still deliberate friction: the
agent edits shell.nix, you restart bur - devshell changes get reviewed
like code. bur-pkg is the sanctioned exception for grabbing a one-off
tool, which is why it is limited to bare attribute names from the host's
own nixpkgs and leaves no trace past the sandbox.