Sign inSign up

nlesc/sandbox

By nlesc

•Updated 7 months ago

Enhanced docker sandbox templates for running AI agents safely

Image
Security
Machine learning & AI
Developer tools
0

652

nlesc/sandbox repository overview

⁠Enhanced Docker Sandbox Templates

Enhanced Docker Desktop Sandbox⁠ templates built on top of official docker/sandbox-templates images.

The base images already include common language runtimes (Python, Node.js, etc.) and development tools. These templates add on top of that:

  • zsh + oh-my-zsh as default shell
  • VS Code CLI for tunnel-based IDE access
  • Extra tools: bat, autojump, vim, git-delta
  • python aliased to python3

⚠️ Docker released an independent tool sbx on April 2, 2026. It is not tested yet if the templates in this repo are compatible with sbx. It's recommended to use the former docker sandbox command (part of the Docker Desktop) to work with the templates.


⁠Usage

  1. Create a sandbox container from a template image:

    cd /path/to/your/repo
    # Use registry image
    docker sandbox create -t nlesc/sandbox:claude-code shell .
    
  2. Start an interactive shell in the sandbox container:

    docker sandbox exec -it -w $PWD <sandbox-name> zsh
    

    Avoid using docker sandbox run ... shell as it always uses bash, ignoring the template's default shell.

    You can also directly start AI agent:

    docker sandbox exec -it -w $PWD <sandbox-name> claude-code
    

    But it's recommended to start a shell first to set up the environment and then run the agent.

  3. Start VS Code tunnel from the sandbox container:

    code tunnel --accept-server-license-terms
    

    The first time you run this, it will prompt you to authenticate with GitHub.

    After the first time, you can start it in the background:

    code tunnel --accept-server-license-terms > /tmp/tunnel.log 2>&1 &
    
  4. Connect to the tunnel from VS Code on your machine:

    • Install the Remote - Tunnels extension
    • Cmd+Shift+P > Remote-Tunnels: Connect to Tunnel...
    • Sign in with the same GitHub account, pick the tunnel

    Now you can edit files in the sandbox container directly from VS Code on your machine!

Warning

If your repo has `devcontainer.json`, disable the "Dev Containers" extension before connecting to the tunnel, as it will try to start a dev container which doesn't work in this setup.

When you make some custom setup for your dev env, you can save your sandbox state as a new template image (optional):

docker sandbox save <sandbox-name> <new-template-image>

⁠License

Apache License 2.0

Tag summary

Content type

Image

Digest

sha256:2a8bf8ac6…

Size

525.6 MB

Last updated

7 months ago

docker pull nlesc/sandbox:shell