13 comments

  • CharlesW 2 days ago ago

    Why this instead of Anthropic's reference Claude Code development container?

    https://docs.anthropic.com/en/docs/claude-code/devcontainer: "The container’s enhanced security measures (isolation and firewall rules) allow you to run claude --dangerously-skip-permissions to bypass permission prompts for unattended operation."

    • Nizoss a day ago ago

      I also use the default one by Anthropic. It's a good start and simple enough to adjust for any needa.

  • nikvdp 2 days ago ago

    I made a similar thing not long ago that lets you choose between docker, seatbelt (macOS's native sandboxing) and bubblewrap (on Linux).

    I use it on macOS primarily, and have basically stopped using docker mode in favor of the native sandboxing because features like image pasting Just Work™.

    http://github.com/nikvdp/cco

    • e1gen-v 2 days ago ago

      Claude condom is hilarious!

      • nikvdp 2 days ago ago

        I couldn't resist the pun :)

    • nhod 2 days ago ago

      This is the way Claude Code should Just Work™. Thanks for making and sharing. Hopefully someone from Anthropic sees this and incorporates it (and gives you credit and/or a job!)

      • nikvdp 2 days ago ago

        Thanks glad you enjoyed it!

    • pbronez 5 hours ago ago

      Super cool. I’m trying to think what the equivalent windows backend would be… perhaps AppContainer?

  • dvanhgier 2 days ago ago

    More safe, but not completely safe. Maybe that’s good enough?

  • jshchnz 2 days ago ago

    lol i literally just built this myself for a project this week, as I'm sure many have

    • fragmede 2 days ago ago

      That's really the future, isn't it. A workshop full of tools that we custom build for ourselves, and some loosely adopted standards, like jq.

      how do we make a composable gui?

    • tough 2 days ago ago

      yeah i call mine secure-runner lmao

      go binary

  • eunomie a day ago ago

    [dead]