Claude Code

Sandbox and devcontainers

Compare Bash sandbox, sandbox runtime, devcontainers, custom containers and VMs, including credentials, networking and cache boundaries.

Choose isolation before reducing prompts, automating tests or running untrusted repositories/CI. Permissions govern whether an action runs; isolation governs what it can reach afterwards.

Sandboxing does not change data already sent to models. It protects local files, networking and credentials, not training/retention policy.

#Compare isolation approaches

ApproachScopeDocker neededBest fit
Bash sandboxShell commands and childrenNoFewer routine command prompts
Sandbox runtimeEntire Code process, MCP and hooksNoBroader process isolation without Docker
DevcontainerDevelopment environmentYesShared toolchain, Codespaces and IDE containers
Custom containerDevelopment environmentYesExisting platforms, CI and remote work
VMOperating systemNoUntrusted repositories and strong isolation
Code on the webHosted environmentNoMobile delegation without local setup

Bash sandbox does not necessarily contain built-in Read/Edit, MCP or hooks. Use runtime/container/VM isolation when needed.

#Devcontainer baseline

Minimal devcontainer.json:

.devcontainer/devcontainer.json
{
  "image": "mcr.microsoft.com/devcontainers/base:ubuntu",
  "features": {
    "ghcr.io/anthropics/devcontainer-features/claude-code:1.0": {}
  }
}

Common additions:

.devcontainer/devcontainer.json
{
  "mounts": [
    "source=claude-code-config-${devcontainerId},target=/home/node/.claude,type=volume"
  ],
  "containerEnv": {
    "CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC": "1",
    "DISABLE_AUTOUPDATER": "1"
  }
}

~/.claude contains authentication, settings and history. Without persistence, rebuilds require login again. devcontainerId can separate project state.

#Container organization policy

Linux Code reads /etc/claude-code/managed-settings.json:

Dockerfile
RUN mkdir -p /etc/claude-code
COPY managed-settings.json /etc/claude-code/managed-settings.json

Repository Dockerfiles provide defaults but can be edited by contributors. Non-bypassable policy needs administrator/platform-controlled delivery.

#Network egress

A container firewall can restrict required domains. Reference list:

DomainPurpose
passion8.ccGateway and console
api.anthropic.comAPI, preflight and managed settings
claude.aiOfficial login/web
downloads.claude.aiBinaries, plugin executables and updates
raw.githubusercontent.comRelease notes, marketplaces and examples

To disable nonessential traffic:

export CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC=1

Installation, plugins, WebFetch, Chrome bridges and Artifacts may need more domains. Separate model traffic from auxiliary client traffic.

#Protect credentials

Avoid mounting long-lived host credentials, especially:

  • ~/.ssh
  • ~/.aws/credentials
  • ~/.config/gcloud
  • .env
  • npm, GitHub and cloud-provider long-lived tokens.

Prefer:

NeedRecommendation
GitRepository-scoped deploy key or short-lived token
CloudWorkload identity, Codespaces secrets or OIDC
Passion8 keyUser secret or helper
Package installationRead-only registry token and domain limits

When using the Code sandbox, also protect common credentials:

.claude/settings.json
{
  "sandbox": {
    "enabled": true,
    "credentials": {
      "files": [
        { "path": "~/.aws/credentials", "mode": "deny" },
        { "path": "~/.ssh", "mode": "deny" }
      ],
      "envVars": [
        { "name": "GITHUB_TOKEN", "mode": "deny" },
        { "name": "NPM_TOKEN", "mode": "deny" }
      ]
    }
  }
}

#Combine permission modes

ModeEnvironment
defaultRoutine local development
planReview before risky changes
autoReduce prompts with sandbox/container isolation
bypassPermissionsTrusted repository in nonroot container, VM or strong sandbox only

Skipping permissions removes per-action confirmation. Containers reduce host exposure but do not prevent repository changes or abuse of credentials accessible inside them.

#Caching and cost

ScenarioCache effect
Clear ~/.claude on rebuildChanges state and can reduce cache reuse
Persistent volumeMore stable same-project prefixes
Pinned client versionStable prompts and tool behavior
Fresh container per CI jobOften cold prefixes with limited short-TTL reuse
Network/permission changesTool/settings/sandbox prompts can alter keys
Passion8Verify upstream TTL and usage forwarding

#Official references

Support

Need help?

For setup, billing, or model issues, email us. Check the status page for uptime.

WeChat / QQ support is available at the bottom right.