- Agent vs SSH — When grain uses the guest agent, when it falls back to SSH, and why both exist.
- Architecture — How the grain daemon, hypervisor, guest agent, and CLI fit together.
- Images and boot — Why base images matter, how golden boots differ from cloud images, and how to think about speed.
- Product surface — What grain implements for local Linux microVM sandboxes.
- Readiness protocol — Contract for custom images and bootstrap authors so grain can report progress and only mark a sandbox ready when you say so.
- Security model — What grain isolates, what it trusts, and how proxy and secrets fit.