latest release · v0.3.1
The installer works out which computer you have, checks the download really came from us, and puts kosa8 where your terminal can find it.
macOS & Linux no account, no card check it yourself
detecting platform … darwin/arm64 verifying checksum against published fingerprints installed kosa8 0.3.1 to /usr/local/bin/kosa8 13 checks · all clear ready — try `kosa8 sandbox create first`
Every way in
Works out whether you have an Apple or Intel chip, checks the download against the published fingerprints, and puts it on your PATH.
An application with an icon, a window and a menu bar. It carries the command-line tool inside it, so this is the only thing you need. Signed, notarised and stapled, so it opens offline without a prompt.
Upgrade later with brew upgrade kosa8. Answer the one-time prompt about trusting a third-party tap.
Signed and notarised, so it opens without a security warning. Verify the checksum or browse every file.
Apple chip Macs run everything. Intel Macs get the command-line tool only — the part that runs containers needs a hypervisor feature Apple ships on its own chips.
Installs to your user profile, so no administrator rights are needed, and adds itself to PATH.
The manifest is regenerated on every release, so scoop update tracks new versions.
A single kosa8.exe, Authenticode-signed so Windows will not warn about an unknown publisher.
Windows can't run the containers itself. It needs an Apple chip Mac to do the work — this is a remote client. Set KOSA8_HOST and KOSA8_TOKEN to point at one.
Detects your architecture, verifies the download, installs to /usr/local/bin.
Also built for arm64. Uninstalls cleanly with apt remove kosa8.
Also built for arm64.
Every package, including arm64 builds of each format.
Linux can't run the containers itself either. It needs an Apple chip Mac to do the work. Point it at one with KOSA8_HOST and KOSA8_TOKEN.
Builds the client. The daemon needs the virtualization entitlement, so on macOS build it from a clone and sign it — kosa8 doctor tells you if it is missing.
Builds, signs the daemon with the entitlement, and installs the guest kernel.
Check it yourself
Every release ships checksums.txt, generated from the files that were actually published rather than from the ones that were built.
Should name AZMX AI and report the notarisation, not adhoc. The daemon carries the virtualization entitlement, which macOS honours only under a signature it trusts.
Status should be Valid. An unsigned build fails the release pipeline before it can be published, so one reaching you unsigned would be a bug worth reporting.
Before you install
The sandboxes are real virtual machines, built on a hypervisor feature Apple ships on its own silicon. Windows, Linux and Intel Macs get a remote client that connects to one — useful on a team, not a local runtime.
A folder shared from the host runs at about 29% of native speed against a 70% target we set and missed. Most of it is the unavoidable cost of the isolation. Every number, including that one.
Every plan starts with a 14-day trial and no card. After that it is paid — there is no permanently free plan, and we would rather you read that here than discover it on day fifteen. What it costs.
After it lands
Thirteen checks, each with the reason it matters and the command to fix it.
Its own kernel, its own network. Ready in about half a second.
The dashboard, on loopback, with a token that dies with the process.
One line, no account, no card.