- Agent vs SSH (when each path is used) — When grain uses the guest agent, when it falls back to SSH, and why both exist.
- Architecture (daemon, hypervisor, guest agent) — How the grain daemon, hypervisor, guest agent, and CLI fit together.
- Images and boot (golden vs cloud) — Why base images matter, how golden boots differ from cloud images, and how to think about speed.
- Product surface (what’s done / experimental) — What grain implements for local Linux microVM sandboxes.
- Readiness protocol (custom images & bootstrap) — Full contract: guest readiness files, agent health fields, wait=bootstrap, and when a sandbox is considered ready.
- Security model (trust, proxy, secrets) — What grain isolates, what it trusts, and how proxy and secrets fit.