Containerized environment for running AI agents
256
This project provides a containerized environment for running AI agents (such as Claude Code, Gemini, etc.) with limited access to the host system.
There are growing security concerns surrounding AI agents, particularly regarding:
By running agents in containers, you create an isolation layer that:
Trade-offs:
docker build -t linux-ai-agents .
# Create the container with volume mount
docker create -it --name linux-ai-agents \
-v ./:/src \
linux-ai-agents
# Start the container
docker start -ai linux-ai-agents
Volume Mount: The /src directory in the container enables file sharing between your host and the container. It maps to the directory where you ran the docker create command.
User Context: The container runs as a non-root user (builder) with sudo privileges for security. All commands execute under this user account.
Alternative: Use a VS Code Dev Containers extension for a more integrated development experience.
Once inside the container:
# Your current directory is accessible at /src
cd /src
# Run your AI agent commands here
# The agent can only access files within the container
# Stop the container
docker stop linux-ai-agents
# Restart the container
docker start -ai linux-ai-agents
# Remove the container (if needed)
docker rm linux-ai-agents
# Rebuild the image after changes
docker build -t linux-ai-agents .
Container won't start:
docker images | grep linux-ai-agentsdocker psPermission issues:
Missing tools:
Content type
Image
Digest
sha256:d4cb962d3…
Size
635.4 MB
Last updated
8 months ago
docker pull marcioreisjr/linux-ai-agents