> ## Documentation Index
> Fetch the complete documentation index at: https://docs.outerlayer.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Security and limits

> What each way of isolating a build protects, how the host key and the item key limit a build, and what no isolation covers.

Read this before you choose a host's hooks or build repositories you do not
fully trust.

## What each kind of build protects

Each build records the kind of isolation it ran with.

| Hooks | Records | What it protects |
| - | - | - |
| `builtin:vm` | `vm` | The build runs in a Firecracker microVM with its own kernel, so it does not share the host's kernel. It has no network device: its connections go to the runner's tunnel. It gets the same tokens and limits as a container build. See [MicroVM builds](/container-builds#microvm-builds). |
| `builtin:container` | `container` | The build runs in its own container, never as root, with none of the host's files beyond its own build directory. It holds neither the item key nor Claude's credential, and can push only to the branch the claim names. See [Container builds](/container-builds). |
| `builtin:process` | `shared-user` | Nothing. The build runs as the runner's user and has the host's network. It can read that user's files, including the runner key, the host key and the Claude credential. See [The process fallback](/write-your-own-hooks#the-process-fallback). |
| Your own hooks | What `provision.out` names, else `shared-user` | Whatever your hooks build. See [Write your own hooks](/write-your-own-hooks). |

## What the keys limit

* **The host key** ties the runner key to one machine. The runner key's
  first claim binds it to the host key. From then on, a leaked runner key is
  useless without that host key. Until that first claim, anyone holding the
  runner key can bind it to their own machine. See
  [The host key](/run-a-host-as-a-service#the-host-key).
* **The item key** is what a build uses in place of the runner key. It acts
  only on the claimed item and stops working when the claim ends. A
  container or microVM build never holds it. A `builtin:process` build can
  read it from the attempt's job file. See
  [Item key](/reference/cli-runner#item-key), and [Concepts](/concepts) for
  claims and leases.

## Honest limits

* Executable hooks and `builtin:process` run the command as the host's own
  user, with the host's files in reach. That includes the runner key and the
  host key, so the host key does not protect a runner key from these builds.
  Only `builtin:vm`, `builtin:container`, or hooks with isolation of their own
  isolate a build.
* With executable hooks, a child process that leaves the process group
  (for example with `setsid`) keeps running after the build stops.
* On macOS, only the Linux VM isolates a build. The runner key lives inside
  it, so a build that escaped its container would reach the key.
* A container build has no Docker inside it. A repository whose tests start
  Docker needs `builtin:vm` and a recipe that adds the docker-in-docker
  feature, or its own hooks.
* A container build reaches only public addresses. A local, private or
  Tailscale address is unreachable from inside it.
* A build can read every value in `build.variables`, and its `gh` read
  token, and send them to any public host the tunnel allows. List the hosts
  it needs in
  [`build.allowHosts`](/container-builds#limiting-the-hosts-a-build-reaches).
* The runner checks which branch a push updates, not what it contains. The
  review covers the diff.
* On a branch under `outerlayer/`, the runner forwards any push, a
  force-push included. On any other branch it forwards only a push that
  creates the branch or moves it forward.
* A container build's disk limit is checked every thirty seconds, so the
  build can pass it briefly. A microVM build's disk is a fixed size.
* A claim made just before the runner restarts may not be recovered. It
  expires on its own within fifteen minutes.
* `outerlayer sync`'s upload checkpoint lives in the user's home directory,
  one per gateway and factory. Two runners under one account, for the same
  factory, share it.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.