Cinematic deep dive Agents in Production 10 min Failure mode + fix

Remote Control vs Cloud Agents

Your agent needs you. You are not at your desk.

Claude Code, Codex and Antigravity away from your desk

Video premiering soon on @AI.JoinDev Subscribe to get it first

Chapters

  1. Intro
  2. Two questions, four boxes
  3. Claude Code Remote Control
  4. Claude Code in the cloud
  5. Codex: Remote and Cloud
  6. Antigravity: agy and Managed Agents
  7. Side by side
  8. Pitfalls and checklist

Who it's for

Developers who already use Claude Code, OpenAI Codex or Google Antigravity and want to leave long tasks running while they're away from the desk, and team leads deciding which of those modes to allow. Chapters 1–2 are plain language; the rest is technical.

Context

By autumn 2026 all three major coding agents ship both modes:

  • Claude Code — Remote Control (claude remote-control, claude --remote-control / --rc, /remote-control / /rc) lets claude.ai/code or the Claude mobile app drive a session that keeps running on your machine. Cloud sessions (Claude Code on the web, claude --cloud, the mobile and Desktop apps, routines) run Claude Code in an isolated Anthropic-managed VM configured by a cloud environment.
  • OpenAI Codex — Codex Remote (preview in the ChatGPT mobile app 14 May 2026, GA 25–26 June 2026) pairs the ChatGPT app with the Codex desktop app on a Mac or Windows PC (or an SSH devbox) by QR code, through an OpenAI relay. Codex Cloud (codex cloud, chatgpt.com/codex, @codex on GitHub) runs tasks in containers; at DevDay on 29 Sep 2026 those environments became reusable and shareable, and the older per-task experience is now labelled "Codex Cloud (Legacy)".
  • Google Antigravity 2.0 (I/O, 19 May 2026) — a desktop Agent Manager, the agy CLI, an SDK and Managed Agents in the Gemini API. Remote Control (21 Aug 2026, rolling out from Google AI Ultra to all users) drives sessions on your own machines from any browser or phone, with push notifications when an agent needs input.

Architecture

ComponentRoleNotes
Local agent processRuns the loop, tools and MCP servers on your machineClaude Code CLI / Desktop / VS Code; Codex desktop app; Antigravity desktop or agy
Relay (vendor API)Routes messages between the local process and remote clientsClaude: the local session makes outbound HTTPS requests only, registers with the Anthropic API and polls for work; no inbound ports. Codex: an OpenAI relay "keeps trusted machines reachable across devices without exposing them to the public internet"
Remote clientPhone app or browser that steers the sessionClaude app / claude.ai/code; ChatGPT app; any browser for Antigravity
Device trustTies steering rights to a known deviceClaude Trusted Devices (off by default); Codex QR pairing plus ChatGPT account MFA/SSO
Cloud VM / containerRuns the agent away from your machineOne isolated VM per Claude cloud session; one container per Codex task; a Linux sandbox per Managed Agents environment
Cloud environmentSaved config for cloud runsClaude: network level, env vars, setup script (cached if it finishes in ≈5 min), API credentials; Codex: setup + maintenance scripts, internet settings, env vars, secrets
Egress policyWhat the agent may reachClaude levels None / Trusted / Full / Custom (Trusted = package registries, GitHub, cloud SDKs); Codex agent internet off by default, setup has access; Managed Agents allow/block lists
Credential proxyKeeps secrets outside the sandboxClaude GitHub proxy attaches the token server-side; Codex secrets are removed before the agent phase; Managed Agents credential injection by network rule
HandoffMoves work between cloud and localclaude --teleport (cloud → terminal, one-way from the CLI); Codex apply diff / PR; Managed Agents reuse an environment ID

Request flow

Remote Control (Claude Code):

  1. claude remote-control (server mode) registers with the Anthropic API over outbound HTTPS and polls for work; press space for a QR code.
  2. The phone scans it (or opens the session at claude.ai/code); the session list shows it.
  3. A message typed on the phone goes to the API, which routes it down a streaming connection to the local process.
  4. Tools run locally with local files, MCP servers and config; results, permission prompts and AskUserQuestion dialogs go back to every connected device.
  5. Short-lived, single-purpose credentials expire independently; if the laptop sleeps or the network drops, the session reconnects when the machine is back.

Cloud session (Claude Code):

  1. claude --cloud "task" creates a session; the VM clones the GitHub remote at the current branch (not the local checkout) or uploads a bundle when there is no usable remote.
  2. The environment's setup script runs (cached for later sessions when it finishes in ≈5 min); network access follows the environment's level.
  3. The agent works; git operations go through the GitHub proxy, which attaches credentials outside the VM.
  4. You steer from any device (claude -p "…" --cloud <session-id> queues a follow-up), review the diff, create a PR, or claude --teleport the branch and conversation into a terminal.
  5. Idle sessions pause; a paused VM can be reclaimed. Reopening restores the conversation on a fresh VM, but not background jobs.

The failure modes

  1. The mixed-up mode. A developer starts a long job with Remote Control, closes the laptop and expects it to finish overnight; the host sleeps and nothing runs. Or they send a job that needs a local database or VPN to a cloud VM that can't reach it. The two modes look alike on the phone but run in completely different places.
  2. The account is the new SSH key. Anyone signed into the account can steer a paired machine with its files and credentials. Without MFA and device verification, a phished session is remote code execution on your laptop.
  3. Leaky sandboxes. A cloud agent with full network and a token inside the VM can be prompt-injected into sending that token elsewhere.
  4. Vanishing work and runaway bills. Background jobs die when an idle VM is reclaimed; always-on cloud hosts (for example a Droplet made for Codex Remote) bill by the hour until deleted; auto-fix can reply on GitHub as you and trigger comment-driven automation.

Why it happens

Remote steering and remote execution are separate axes, but the UI for both is the same chat on a phone. And the thing that authorises steering is a consumer account login, not a network boundary.

The fix

  • Pick the mode per task: Remote Control when the job needs your local files, tools, VPN or MCP servers and you'll keep the host awake; cloud sessions for long, parallel or overnight jobs on code that's pushed.
  • Outbound-only relay: all three vendors reach the host without inbound ports; don't expose the machine yourself.
  • Harden the account: MFA, Claude Trusted Devices, revoke paired devices you don't use.
  • Least-privilege egress: start at Claude's Trusted (or None), Codex's default (agent internet off); add domains per task with Custom.
  • Credentials outside the sandbox: Claude's GitHub proxy and API credentials, Codex secrets that only exist during setup, Managed Agents credential injection.
  • Commit and push often in cloud sessions; use --teleport / apply diff to bring work home; review auto-fix on repos with comment-triggered automation.

Trade-offs

  • Remote Control: full local context and zero setup, but it depends on the host being awake and online, and each phone becomes a way into your machine.
  • Cloud sessions: survive a closed laptop and run in parallel, but only see what's pushed and what the setup script installs, and can't reach private networks unless you use a self-hosted environment.
  • Tighter egress blocks legitimate installs; a slow setup script (>≈5 min) isn't cached, so every session pays for it.
  • Reusable/persistent environments (Codex DevDay 2026, Managed Agents environment IDs) start faster but carry state between tasks.

Numbers worth knowing

  • Claude Code Remote Control server mode: --capacity default 32 concurrent sessions; server mode gives up after ≈10 min without the network; resume sessions for ≈4 hours after stopping; forwarded dialogs (other than permission prompts and questions) expire after 5 min by default.
  • Claude cloud setup script cached only if it finishes in ≈5 min; bundled uploads must be under 100 MB.
  • Codex Cloud container cache up to 12 hours; secrets are available only to setup scripts.
  • Codex Remote: mobile preview 14 May 2026, GA 25–26 June 2026; DevDay reusable environments 29 Sep 2026.
  • Antigravity 2.0 19 May 2026; Remote Control 21 Aug 2026.
  • Illustrative only: every repository, session name, command output, diff, plan and notification shown on the phone and terminal screens, and the "142 tests".

The code

terminal
# three cloud sessions, from your repo
claude --cloud "Fix the flaky test in auth.spec.ts"
claude --cloud "Update the API docs"
claude --cloud "Refactor the logger"

# queue a follow-up from any machine
claude -p "also add tests" --cloud session_01Di...

# pull finished work into your terminal
claude --teleport

# watch a PR: fix failing checks and review comments
/autofix-pr

Checklist

Guard the account

Anyone in your account can steer. Use MFA and Trusted Devices.

Keep hosts awake

Remote Control needs the host awake. Use the cloud overnight.

Idle VMs vanish

Background jobs die with the VM. Commit and push often.

Start with Trusted

Or no network. Add domains only when a task needs them.

Watch auto-fix

It replies on GitHub as you, which can trigger comment bots.

Kill idle boxes

Always-on cloud hosts bill by the hour until you delete them.

Sources

Coming next in the series: Agent sandboxing: how isolation really works

Found this useful?

Subscribe for the next episode, or share it with the person who owns this part of your stack.

Keep going