<?xml version="1.0" encoding="utf-8"?><feed xmlns="http://www.w3.org/2005/Atom"><title>Ju Lin's AI Weblog: Infrastructure</title><subtitle>An independent research notebook on AI engineering, agents, models and the systems around them.</subtitle><id>https://julin.ai/atom/tags/infrastructure/index.xml</id><link rel="self" type="application/atom+xml" href="https://julin.ai/atom/tags/infrastructure/index.xml"/><link rel="alternate" type="text/html" href="https://julin.ai/tags/infrastructure/"/><author><name>Ju Lin</name></author><updated>2026-09-29T00:00:00+13:00</updated><entry><title>Where Does a Claude Agent Run?</title><id>https://julin.ai/2026/09/29/claude-agent-runtime/</id><link rel="alternate" type="text/html" href="https://julin.ai/2026/09/29/claude-agent-runtime/"/><published>2026-09-29T00:00:00+13:00</published><updated>2026-09-29T00:00:00+13:00</updated><category term="field-notes"/><category term="agents"/><category term="infrastructure"/><content type="html">&lt;p&gt;Different Claude tools run agents in different places. The choice shapes what the agent can do.&lt;/p&gt;
&lt;h2 id="claude-claudeai"&gt;Claude (claude.ai)&lt;/h2&gt;
&lt;p&gt;The agent runs inside a gVisor container on the server side. No local setup required—everything runs remotely. The container is ephemeral; each session starts fresh and leaves no traces.&lt;/p&gt;
&lt;h2 id="claude-code"&gt;Claude Code&lt;/h2&gt;
&lt;p&gt;The agent runs on your machine. It can execute every command and access every file that your logged-in user can access. For advanced users concerned about blast radius, start a sandbox first (like a microVM) and run Claude Code inside that isolated environment.&lt;/p&gt;
&lt;h2 id="claude-cowork"&gt;Claude Cowork&lt;/h2&gt;
&lt;p&gt;The agent runs on a VM. On macOS, it uses the Virtualization framework; on Windows, it uses HCS. The VM has its own Linux kernel and filesystem. But the agent loop itself runs outside the VM—only code execution happens inside.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Each design is a tradeoff. Server-side isolation is safe but ephemeral. Local execution is powerful but risky. VM-based execution gives you isolation with some local access.&lt;/p&gt;</content></entry></feed>