Anthropic's Claude Code as a mixin — the native install in an overlay, with the `anthropic` cre...
157
Anthropic's Claude Code as a mixin — the native install in an overlay, with the `anthropic` credential (API key or Claude subscription) resolved by the sandbox proxy, the session-state volumes, and the hooks the agent needs. Layer it onto a shell base and run `claude`.
| Name | Required | Default | Description |
|---|---|---|---|
version | Optional | 2.1.267 | Claude Code release to install |
[email protected]| Type | Required | Description | |
|---|---|---|---|
com.docker.sandbox/network-policy@1 | Required | — | |
com.docker.sandbox/credential@1 | Optional | Anthropic API access (console API key or Claude subscription) | |
com.docker.sandbox/volume@1 | Required | Conversation transcripts; grows without bound, so it gets the headroom | |
com.docker.sandbox/volume@1 | Required | Per-session state JSON; load-bearing for `claude -c` | |
com.docker.sandbox/volume@1 | Required | TodoWrite state | |
com.docker.sandbox/volume@1 | Required | Bash state across sessions — one snapshot per shell session | |
com.docker.sandbox/volume@1 | Required | Local feature-flag cache; the telemetry switch suppresses event reporting, not these gate lookups | |
com.docker.sandbox/lifecycle@1 | Required | — | |
com.docker.sandbox/agent-context@1 | Required | — | |
sbx run <agent> --kit sbx/claude-mixin:latestRun the following command to install sbx on your machine.
brew install docker/tap/sbxwinget install Docker.sbxNote
Experimental: Sandbox Kit v3This kit uses the experimental Sandbox Kit specification, specifically v3. The format and runtime behavior may change before v3 is stable.
Claude Code as a mixin (kind: mixin,
schemaVersion: "3") — the same agent the claude workload kit
ships, packaged as an overlay you layer onto a shell base instead of booting as
the whole environment.
Use this one when the sandbox already has a workload you want to keep (a shell,
a language toolchain, another team's base image) and you want claude in it.
Use claude when Claude Code is the environment.
sbx run --kit ./claude-mixin/ <base-agent>
The two are mutually exclusive: both provides: ["claude"], and a composition
with two providers of one name is refused — the workload already carries the
agent this mixin installs.
Everything the workload declares that belongs to the agent rather than to the environment:
anthropic credential, covering both a console API key and a Claude
subscription, with the same deliberate omission of proxyManaged (see the
workload's README);apt-get update needs;~/.claude/ session-state volumes;settings.json seeded from
the surfaced auth mode, MCP gateway registration;CLAUDE.md.The install itself is the unmodified upstream one, run over the workload's base
in a build stage and staged into a scratch overlay. Anthropic's installer is
not relocatable and the install method is what claude update drives, so the
mixin keeps it rather than swapping in a --prefix build.
| Left out | Why |
|---|---|
ENTRYPOINT | The base's launch command stays; you run claude from the shell. |
sbx@1 | A mixin's image config is not the composed image's, so the identity and shells that type is a claim about are the base's. |
agent-context filename: | CLAUDE.md names the profile, which belongs to the workload. This kit contributes a body to it. |
agent-sessions@1 | The session verbs are argv tails on a launch command this kit does not own. |
IS_SANDBOX and the telemetry switches as image ENV | A mixin's ENV does not become the composed image's, so they ride the overlay as /etc/profile.d/claude-mixin-env.sh exports instead. |
claude — the same agent as a standalone workload kit.claude-mem, claude-acp,
claude-sbx-statusline, ecc,
claude-model-runner — mixins that
requires: ["claude"] and therefore compose onto either shape.