Security Model
The strongest documented deployment is managed NixOS on Linux/x86-64. Its agent daemon runs Montana directly under systemd with a per-agent component, an agent user, the shared hardening envelope, a network namespace, the credential proxy and Sheepdog. It does not use the OCI runtime to launch the agent. Local, ordinary Docker and optional OCI launches have different boundaries; see Deployment Paths.
This page explains the controls. The threat model states their conditions and limitations. In particular, Cowboy does not guarantee confidentiality of anything the agent can read. A prompt-injected worker with permitted outbound access can disclose readable data. The agent can also damage its own writable workspace, memory and state.
What is enforced by default
The Nix modules enable the credential proxy by default, and enable Redis ACLs and Sheepdog by default on Linux. These are deployment settings, not properties of an arbitrary core or component build. Managed daemons require the proxy; turning it off is not a supported way to run that daemon with real keys.
Process and filesystem isolation
Each managed daemon runs as its configured agent user. The systemd envelope makes the system read-only, hides other homes, binds the agent’s home back in, and applies private temporary storage, device restrictions, an empty capability bounding set and no-new-privileges. Configured mounts add access to that view. The home, runtime and explicitly writable paths remain mutable.
Inside Montana, direct guest file access uses WASI preopens. These map the workspace, home, config, data and temporary directories at their host paths, so guest reads and native execution agree about filenames. Preopens grant file access separately from custom execution effects; a review of tool policy alone is not a review of all filesystem access.
Montana sub-agents share the host process and its preopens. A filtered child tool list is not a separate OS identity or filesystem boundary.
Network isolation
The managed Linux module creates one shared namespace, cowboy-ns, with a
veth pair to the host. The daemons and agent user services join it. It is not
one namespace per agent.
Outbound TCP outside the configured subnet is redirected to the proxy. The egress filter allows loopback, the subnet, established replies and DNS to the host resolver, then drops other traffic. Operator-configured SSH destinations and passthrough ports grant direct egress exceptions.
The host Nix daemon is another network authority: its builders run outside the agent namespace. The default denial of direct Nix daemon access is a Sheepdog connect rule. Disabling Sheepdog removes that enforcement. Rebuild requests can instead go through the broker’s configured approval workflow.
Darwin uses a UID-scoped packet-filter redirect and has neither the Linux namespace boundary nor Sheepdog or the Linux Redis ACL implementation.
Credential-injecting proxy
Managed daemons require the proxy and use placeholder provider keys. The proxy reads the real secret from its configured file and injects it on a matching TLS destination route. Exact host routes take priority over wildcard routes; more specific wildcard suffixes take priority over broader ones. A mismatched Host header is rejected before credentials are attached. Upstream certificate verification is enabled by default; the explicit insecure option disables it.
These claims apply to the proxy deployment. Local and ordinary Docker agents hold credentials. Proxy configuration does not remove credentials supplied through some other input.
With egress control enabled, GET, HEAD, OPTIONS and TRACE pass the method gate. Every other method needs an allowed destination or receives HTTP 403. These are method-and-destination restrictions, not a guarantee that external state cannot change. There is no content inspection that prevents readable data from leaving through an allowed request.
Sheepdog policy
On Linux/x86-64, the managed build bakes a per-agent Sheepdog policy into the component’s tool execution path. Sheepdog uses seccomp notification to mediate selected file, execution and connection syscalls. Its policy includes read, edit, create, delete, execution and connection rules. Runtime permission grants can take precedence over baked rules when enabled.
This is conditional on the sandbox being enabled and present in the build. Portable lite builds do not enforce this policy. The optional OCI route uses its own bundle restrictions; it does not inherit all managed-service controls. The policy authority and limitations are specified in Sheepdog policy.
A command can exit successfully even when part of it was denied. Core preserves recognized Sheepdog denial messages in the tool result so the agent can see that a refused read or connection was not an empty successful result.
Per-agent message isolation
With the Linux Redis ACL configuration enabled, each agent has its own inbox and outbox streams and an identity restricted to its name prefix. It cannot read another agent’s streams or edit approval records.
The agent reaches Redis through its own Unix socket at
/run/cowboy/<agent>.sock, owned by its user with mode 0600. The host auth proxy
selects the Redis identity from the accepting socket and injects the password.
The agent holds no Redis password. Per-agent source configuration names these
streams and the socket.
Bridges route inbound messages to an agent’s inbox and consume each agent’s outbox. The outbox stream prefix determines the requester; a message’s claimed user does not. Bridge bookkeeping lives outside agent-writable prefixes. Each bridge has its own service user and Redis identity, scoped to its streams and required approval roles. A bridge that creates or resolves approvals still has authority over shared approval records; those roles must be trusted.
This separates agent mail while provider credentials remain shared through the host’s proxy. It is not a tenant boundary between mutually untrusted operators.
Approvals and operational authority
Bridge approvals hold configured outbound messages for a human decision and reject them on timeout. Declared Git effects bind approval to a host-inspected commit and base; apply rechecks policy before pushing. The rebuild bridge has privileged activation authority through its configured wrappers. Treat bridge identities and approval resolvers as part of the trusted host.
See Approvals & Outbox and Gated Effects. After a restart, inspect outcomes before retrying: message recovery can repeat work without restoring the reply’s source binding.
Agent users do not receive journal access by default. Enabling
services.cowboy.agents.<name>.allowJournal grants access to host logs as well
as the corresponding log-path policy. Logs can contain data from other trust
domains. The proxy omits query strings from its own request logs; that does not
sanitize output from other services.