A corral for unbroken horses. corral wraps Lima to give every project its own agent VM — real kernel boundary, persistent per-workspace memory, full dev toolchain inside, no host home or SSH agent visible. Optional HAProxy + pf egress filter restricts outbound HTTPS to a per-workspace allowlist. Rootless containerd ships in every VM. macOS, Apple Silicon or Intel.
⚠ The trust score below reflects the collection's repository only. The bundled units are not individually verified or scanned — review them before use.
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts — it cannot prove the absence of malicious code.
A corral for unbroken horses. corral wraps Lima to give every project its own agent VM — real kernel boundary, persistent per-workspace memory, full dev toolchain inside, no host home or SSH agent visible. Optional HAProxy + pf egress filter restricts outbound HTTPS to a per-workspace allowlist. Rootless containerd ships in every VM. macOS, Apple Silicon or Intel.