Sandbox Claude Inside

Run Claude Code INSIDE a ca-sandbox box (`--with-claude`). Routed to when the user wants an agent loop running against an isolated, ephemeral sandbox rather than the host. Authenticates via an env-injected CLAUDE_CODE_OAUTH_TOKEN with no host bind of ~/.claude; the image pins the CLI and disables the autoupdater; HOME is backed by a named volume so the .claude state persists across restart. Five gated phases — posture, image, token, run, teardown. The hard default is offline or Anthropic-domains-only egress, and the token volume is NEVER co-mounted with an untrusted-code run; both are enforced, not advised.

majiayu000 769d76e 2 files · 10.9 KB Updated 567 repo stars

File contents

majiayu000/claude-skill-registry-data/tree/main/devops/sandbox-claude-inside commit 769d76ea65

Frequently asked questions

npx skillmds add majiayu000/sandbox-claude-inside