psyb0t

Docker Claudebox — DevOps skill for Claude Code

DevOps community

Claude Code in Docker.

How to install Docker Claudebox

This entry records only its repository, not the path inside it, so there is no exact command to give. Open psyb0t/docker-claudebox and copy the folder into ~/.claude/skills/, or the file into ~/.claude/agents/.

What Docker Claudebox does

Claude Code in Docker. Drop-in OpenAI-compatible API, MCP server, Telegram bot, and CLI — five interfaces, one image. Persistent sessions, file ops, always-on skill injection, and a full dev toolchain (Go, Python, Node, K8s, Terraform, databases) or a minimal image with just the basics.

Alternatives in DevOps

  • Cccc — Coordinate your coding agents like a group chat — read receipts, delivery tracking, and remote ops from your p 1.1k ★
  • Claudebox — A Claude Code Docker Development Environment for running Claude AI's coding assistant in a fully containerized 964 ★
  • WP CLI And Ops — WordPress CLI and operations management 902 ★

README

claudebox

[![CI](https://github.com/psyb0t/docker-claudebox/actions/workflows/pipeline.yml/badge.svg?branch=master)](https://github.com/psyb0t/docker-claudebox/actions/workflows/pipeline.yml) [![version](https://raw.githubusercontent.com/psyb0t/docker-claudebox/badges/version.svg)](https://github.com/psyb0t/docker-claudebox/releases) [![license](https://raw.githubusercontent.com/psyb0t/docker-claudebox/badges/license.svg)](LICENSE) [![Docker Pulls](https://img.shields.io/docker/pulls/psyb0t/claudebox?style=flat-square)](https://hub.docker.com/r/psyb0t/claudebox)

A runtime harness for [Claude Code](https://claude.com/product/claude-code) — the agentic coding CLI from Anthropic — running in a fully isolated Docker container with every dev tool pre-installed, passwordless sudo, docker-in-docker support, and `--permission-mode bypassPermissions` enabled by default.

**v2.0.0 — rebased on `psyb0t/aicodebox`.** claudebox is now a thin child image of the shared aicodebox base (same pattern as `psyb0t/pibox`). Every mode surface (API / Telegram / Cron / MCP) is inherited from the base and stays in lockstep with future base fixes. See [`CHANGELOG.md`](CHANGELOG.md) for the full migration guide (endpoint shape changes, env-var namespace, path renames — all mitigated by aliases + symlinks so existing configs keep working).

**Runtime hardening (recommended `docker run` flags):**

  • --cap-drop=ALL --cap-add=NET_BIND_SERVICE — drop every Linux capability, add back only bind-below-1024 if you actually need it.
  • --security-opt no-new-privileges:true — block setuid privilege escalation inside the container.
  • --memory=2g --cpus=2 --pids-limit=512 — cap runtime resource use so a runaway process can't starve the host.
  • --read-only --tmpfs /tmp:rw,noexec,nosuid (only if you don't use /workspace for writes — otherwise skip). The container drops from root to aicode (UID 1000) at boot via setpriv in the base entrypoint, so the process running your code is never root