Sign inSign up

sbx/claude-mixin

Verified Publisher

By Docker, Inc

•Updated about 3 hours ago

Anthropic's Claude Code as a mixin — the native install in an overlay, with the `anthropic` cre...

Sandbox Kit
0

157

sbx/claude-mixin repository overview

Digest

sha256:6a6757588453…

Size

93.6 MB

Schema

v3

Pushed

about 3 hours ago

Specificationspec.yaml

MIXIN

Anthropic's Claude Code as a mixin — the native install in an overlay, with the `anthropic` credential (API key or Claude subscription) resolved by the sandbox proxy, the session-state volumes, and the hooks the agent needs. Layer it onto a shell base and run `claude`.


Arguments
NameRequiredDefaultDescription
versionOptional2.1.267

Claude Code release to install



CapabilitiesExpand a row to see its full configuration. See the full spec for the complete descriptor.
TypeRequiredDescription
com.docker.sandbox/network-policy@1Required—
com.docker.sandbox/credential@1OptionalAnthropic API access (console API key or Claude subscription)
com.docker.sandbox/volume@1RequiredConversation transcripts; grows without bound, so it gets the headroom
com.docker.sandbox/volume@1RequiredPer-session state JSON; load-bearing for `claude -c`
com.docker.sandbox/volume@1RequiredTodoWrite state
com.docker.sandbox/volume@1RequiredBash state across sessions — one snapshot per shell session
com.docker.sandbox/volume@1RequiredLocal feature-flag cache; the telemetry switch suppresses event reporting, not these gate lookups
com.docker.sandbox/lifecycle@1Required—
com.docker.sandbox/agent-context@1Required—

Apply this mixin to a sandbox

sbx run <agent> --kit sbx/claude-mixin:latest

Make sure you have docker sbx installed

Run the following command to install sbx on your machine.

macOS
brew install docker/tap/sbx
Windows
winget install Docker.sbx
Learn more about docker sbx⁠

Note

Experimental: Sandbox Kit v3

This kit uses the experimental Sandbox Kit specification⁠, specifically v3⁠. The format and runtime behavior may change before v3 is stable.

⁠claude-mixin

Claude Code⁠ as a mixin (kind: mixin, schemaVersion: "3") — the same agent the claude⁠ workload kit ships, packaged as an overlay you layer onto a shell base instead of booting as the whole environment.

Use this one when the sandbox already has a workload you want to keep (a shell, a language toolchain, another team's base image) and you want claude in it. Use claude⁠ when Claude Code is the environment.

⁠Composing it

sbx run --kit ./claude-mixin/ <base-agent>

The two are mutually exclusive: both provides: ["claude"], and a composition with two providers of one name is refused — the workload already carries the agent this mixin installs.

⁠What it carries

Everything the workload declares that belongs to the agent rather than to the environment:

  • the anthropic credential, covering both a console API key and a Claude subscription, with the same deliberate omission of proxyManaged (see the workload's README⁠);
  • the same egress allow-list, including the apt hosts the background apt-get update needs;
  • the same five ~/.claude/ session-state volumes;
  • the same install and startup hooks — trust flags, settings.json seeded from the surfaced auth mode, MCP gateway registration;
  • a body for the composed CLAUDE.md.

The install itself is the unmodified upstream one, run over the workload's base in a build stage and staged into a scratch overlay. Anthropic's installer is not relocatable and the install method is what claude update drives, so the mixin keeps it rather than swapping in a --prefix build.

⁠What it deliberately leaves to the base workload

Left outWhy
ENTRYPOINTThe base's launch command stays; you run claude from the shell.
sbx@1A mixin's image config is not the composed image's, so the identity and shells that type is a claim about are the base's.
agent-context filename:CLAUDE.md names the profile, which belongs to the workload. This kit contributes a body to it.
agent-sessions@1The session verbs are argv tails on a launch command this kit does not own.
IS_SANDBOX and the telemetry switches as image ENVA mixin's ENV does not become the composed image's, so they ride the overlay as /etc/profile.d/claude-mixin-env.sh exports instead.