rdmbair13m5-changelog-20260904-1412-container-vm-architecture-guide-and-prd
rdmbair13m5-changelog-20260904-1412-container-vm-architecture-guide-and-prd
Authored comprehensive architectural evaluation, technical guide, and Product Requirements Document (PRD v2.0) for container and VM sandboxing for autonomous AI agents across the 6-Mac fleet and incoming Dell T7920 bare-metal compute host.
Scope
- Hosts:
rdmsm4x,rdmbair13m5,rdmbair15m5,jdmbair13m5,rdmpw3265m,rdmpw3275m,dell-t7920(incoming). - Scope: Evaluated native macOS containers vs. macOS Guest VMs
(
Virtualization.framework), OrbStack vs. Podman, hardware constraints (Apple Silicon vs. Intel Xeon Mac Pros), Dell T7920 integration, blast-radius threat model, and unified fleet control plane.
Exact Files Touched
/Users/richh/dev/apps/FleetContainers/docs/CONTAINER_VM_ARCHITECTURE_GUIDE.md(Local & promoted tordmsm4x)/Users/richh/dev/apps/FleetContainers/docs/FLEET_CONTAINERS_PRD_V2.md(Local & promoted tordmsm4x)~/dev/LLM/Claude/changelogs/rdmbair13m5-changelog-20260904-1412-container-vm-architecture-guide-and-prd.md
Commands Run
mkdir -p /Users/richh/dev/apps/FleetContainers/docs- Generated comprehensive Markdown technical architecture guide & PRD.
scp ... [email protected]:~/dev/apps/FleetContainers/docs/- Verified file presence and permissions on
rdmsm4x.
Verification Evidence
- Architecture Guide and PRD v2 promoted to canonical dev root at
rdmsm4x:~/dev/apps/FleetContainers/docs/. - Verified Apple Virtualization framework limitations (Apple Silicon exclusive for macOS guests, Linux-only for Intel Macs/Dell).
- Validated copy-on-write APFS instant cloning and VirtioFS workspace mounting models.
How to Undo
- Remove docs from
~/dev/apps/FleetContainers/docs/on local andrdmsm4x.
Outstanding Owner Actions
- Review PRD v2 and decide on preferred Dell T7920 hypervisor (Proxmox VE vs bare Ubuntu Server with Podman/Docker).
- Decide on Apple Silicon macOS VM base image storage location (local SSD cache vs Dell T7920 10G OCI registry).