4 ms·
Isolating Claude Code
- nezhar 8mo agoI also had the same idea when I built https://github.com/nezhar/claude-container https://github.com/nezhar/claude-container. What I was also curious about is what is actually sent and received by the agent, so I included this feature and created a CLI to make integration easier in a developer workflow. Since I started doing this for other agents as well, I considered the idea of using a VM with Vagrant. However, I want the setup to remain minimal, so I still believe there is room for improvement.
- skwee357 8mo agoI found VM to be on-par with Docker. Sure, the initial provision takes time, but this is true to for initial Docker build as well. I know that worrying about sharing kernel with the Docker container, is probably light paranoia, but I really don't trust agents to not run malicious code.
- nezhar 8mo agoDistributing pre-built images can help minimize this: https://hub.docker.com/r/nezhar/claude-container/tags https://hub.docker.com/r/nezhar/claude-container/tags. I'm not sure how large the image becomes on the VM or if the distribution process is straightforward.