Skip to content

The gate on a Mac

On a Mac the gate runs the same sandbox as on Linux, through Apple’s Virtualization framework: read-only root and tools disks, your folder at /workspace, no network device, and every request through the gate.

  • macOS 13 or later.
  • Apple silicon or Intel.
  • No sudo: the gate on a Mac belongs to your own user.

Run the same command as on Linux. On a Mac it installs the gate for the user who runs it:

Terminal window
curl -fsSL https://get.noset.ai/install.sh | bash

The installer downloads noset and the sandbox’s root file system from Noset, vfkit and the guest kernel from GitHub, and Claude Code from npm, and checks each file’s SHA-256. It builds the tools disk inside the sandbox, which also shows that the sandbox boots.

Then connect it, as on Linux:

Terminal window
noset login
Linux macOS
Who it belongs to the user who ran sudo your own user, no root anywhere
Files /var/lib/noset ~/Library/Application Support/Noset
The noset command /usr/local/bin/noset a link in /usr/local/bin when you can write there, else in ~/.local/bin
The daemon noset.service (systemd) the LaunchAgent ai.noset.gate
The sandbox Cloud Hypervisor vfkit on Apple’s Virtualization framework
  • Files in the workspace belong to you, as on Linux: inside the sandbox the agent runs with your user id.
  • Fail closed: when the gate stops, it stops the sandbox with it.
  • If the installer says its folder is not on your PATH, run the line it prints.