Enhanced docker sandbox templates for running AI agents safely
652
Enhanced Docker Desktop Sandbox templates built on top of official docker/sandbox-templates images.
The base images already include common language runtimes (Python, Node.js, etc.) and development tools. These templates add on top of that:
⚠️ Docker released an independent tool
sbxon April 2, 2026. It is not tested yet if the templates in this repo are compatible withsbx. It's recommended to use the formerdocker sandboxcommand (part of the Docker Desktop) to work with the templates.
Create a sandbox container from a template image:
cd /path/to/your/repo
# Use registry image
docker sandbox create -t nlesc/sandbox:claude-code shell .
Start an interactive shell in the sandbox container:
docker sandbox exec -it -w $PWD <sandbox-name> zsh
Avoid using docker sandbox run ... shell as it always uses bash, ignoring the template's default shell.
You can also directly start AI agent:
docker sandbox exec -it -w $PWD <sandbox-name> claude-code
But it's recommended to start a shell first to set up the environment and then run the agent.
Start VS Code tunnel from the sandbox container:
code tunnel --accept-server-license-terms
The first time you run this, it will prompt you to authenticate with GitHub.
After the first time, you can start it in the background:
code tunnel --accept-server-license-terms > /tmp/tunnel.log 2>&1 &
Connect to the tunnel from VS Code on your machine:
Cmd+Shift+P > Remote-Tunnels: Connect to Tunnel...Now you can edit files in the sandbox container directly from VS Code on your machine!
Warning
If your repo has `devcontainer.json`, disable the "Dev Containers" extension before connecting to the tunnel, as it will try to start a dev container which doesn't work in this setup.
When you make some custom setup for your dev env, you can save your sandbox state as a new template image (optional):
docker sandbox save <sandbox-name> <new-template-image>
Apache License 2.0
Content type
Image
Digest
sha256:2a8bf8ac6…
Size
525.6 MB
Last updated
7 months ago
docker pull nlesc/sandbox:shell