From-scratch Rust VMM boots AI sandboxes in milliseconds on your Mac
It’s a from-scratch Rust replacement for Docker Desktop on Mac, with a side of Firecracker microVMs for your AI agents.
An open-source Rust runtime for macOS that unifies containers, VMs, and AI-agent sandboxes to displace closed-source alternatives.

What it does
ArcBox is a macOS-native container and VM runtime built from scratch in Rust. It exposes a Docker-compatible socket for drop-in container and Compose support, runs full Linux VMs with their own kernels, and spins up disposable microVMs for AI agents and untrusted code using Firecracker nested inside a guest. A single daemon handles everything from Kubernetes clusters to ephemeral macOS guests, keeping sandboxed workloads in their own kernel and filesystem.
The interesting bit
Instead of wrapping Apple’s Hypervisor.framework in a thin layer, ArcBox brings its own VMM with hand-rolled vCPU execution, custom VirtIO devices, and a userspace network datapath that terminates TCP in userland to splice guest flows onto host sockets—no pf NAT, no utun device. That custom backend reportedly hits 22.7 Gbps in a single stream, roughly double Apple’s VirtIO-net in the same test, which is the kind of obsessive replacement you attempt only when you truly dislike dependencies.
Key highlights
- Drop-in Docker engine compatibility with support for
linux/amd64images on Apple Silicon via FEX emulation inside the guest. - Native Kubernetes via a managed local k3s cluster, plus a SwiftUI desktop app for visual management.
- Disposable microVMs for AI agents (e.g., Claude Code) that boot from snapshots in near-zero time, with no host filesystem mounts exposed.
- Full Linux VMs and ephemeral macOS guests (copy-on-write cloned from base images, capped at two per host per Apple’s license).
- A gRPC API with server reflection, so you can drive sandbox lifecycle, file transfer, and port exposure from your own tooling.
Caveats
- Sandboxes require nested virtualization, which limits them to Apple Silicon M3 or newer running macOS 15+ on the default VZ backend; older Macs get a clear error.
- The runtime is macOS-only for now, with Intel Mac support and Linux host support both listed as in progress.
- It is explicitly in public beta, so the roadmap is still shifting.
Verdict
Developers on modern Apple Silicon Macs who want an open-source, hackable alternative to Docker Desktop—and need to isolate AI agents or untrusted code in real microVMs—should take a look. If you are on Intel, Linux, or just want a stable platform, wait for the beta label to peel off.
Frequently asked
- What is arcboxlabs/arcbox?
- It’s a from-scratch Rust replacement for Docker Desktop on Mac, with a side of Firecracker microVMs for your AI agents.
- Is arcbox open source?
- Yes — arcboxlabs/arcbox is open source, released under the Apache-2.0 license.
- What language is arcbox written in?
- arcboxlabs/arcbox is primarily written in Rust.
- How popular is arcbox?
- arcboxlabs/arcbox has 4.2k stars on GitHub and is currently accelerating.
- Where can I find arcbox?
- arcboxlabs/arcbox is on GitHub at https://github.com/arcboxlabs/arcbox.