Sign inSign up

sbx/t3code-kit

Verified Publisher

By Docker, Inc

•Updated 1 day ago

Installs the t3 npm package that T3 Code's SSH integration runs inside a sandbox, so the first co...

Sandbox Kit
0

2.2K

sbx/t3code-kit repository overview

Digest

sha256:23a3556a8226…

Size

2 Bytes

Schema

v2

Pushed

1 day ago

Specificationspec.yaml

MIXIN

Installs the t3 npm package that T3 Code's SSH integration runs inside a sandbox, so the first connection starts a pre-installed server.


Network Egress

registry.npmjs.org:443

archive.ubuntu.com:80

security.ubuntu.com:80

ports.ubuntu.com:80

download.docker.com:443

Apply this mixin to a sandbox

sbx run <agent> --kit sbx/t3code-kit:latest

Make sure you have docker sbx installed

Run the following command to install sbx on your machine.

macOS
brew install docker/tap/sbx
Windows
winget install Docker.sbx
Learn more about docker sbx⁠

⁠t3code

A mixin kit that prepares a sandbox for T3 Code⁠'s SSH integration: it installs the t3 npm package, and the libatomic1 its binaries need, so the first T3 Code connection starts a server that is already there instead of fetching it from the npm registry on the spot. Pair it with any agent kit.

⁠Usage

sbx run claude --kit "docker.io/sbx/t3code-kit:latest" .

Or straight from this repository over git:

sbx run --kit "git+https://github.com/docker/sbx-kits-contrib.git#dir=t3code" claude

Or with a local clone of this repo:

sbx run claude --kit ./t3code/ .

Prerequisites:

  • A base image with Node.js ≥ 18 and npm. All standard agent templates ship both. The install fails loudly with a clear message if npm is missing.

Inside the sandbox:

t3 --version

Then connect the sandbox to T3 Code over SSH as usual, see Connect T3 Code to a sandbox⁠.

⁠How it works

⁠Why libatomic1

t3 installs a platform package, @t3code/t3-linux-<arch>, carrying prebuilt native modules including node-pty. Nothing compiles at install time, so the base image needs no toolchain, but those binaries do link against libatomic1. Without it npm install still succeeds and the binary it installed does not run:

t3: error while loading shared libraries: libatomic.so.1: cannot open shared
object file: No such file or directory

T3 Code reports nothing more specific than a connection timeout when that happens, so the kit installs libatomic1 itself rather than counting on the base image to carry it. The check is ldconfig -p, so a base that already has it runs no apt-get at all.

⁠Why t3 is installed at build time

T3 Code's own remote bootstrap resolves t3 by falling back to npx --package t3@latest when it isn't already on PATH. That works, but it means every first connection depends on npm registry access, and pays the download during the connection attempt. Installing t3 globally at kit-install time does that work once, up front, so connecting is just SSH plus starting a binary that is already there.

⁠Why these domains

permissions.network.allow is the kit's complete outbound contract. CI runs e2e under a deny-all policy.

DomainWhy
registry.npmjs.orgnpm tarballs for t3 and its platform package (install time)
archive.ubuntu.comUbuntu apt archive, amd64
security.ubuntu.comUbuntu security pocket, amd64, refreshed by the same apt-get update
ports.ubuntu.comUbuntu archive and security for arm64 (Apple Silicon sandboxes)
download.docker.comDocker's apt repo, pre-added by the *-docker templates. apt-get update refreshes every configured source and fails if any is blocked

⁠Cleanup

Everything is sandbox-local: the global t3 npm package and libatomic1 disappear with the sandbox (sbx rm <name>). Nothing touches the host.

This listing is prepared by Docker. All third-party product names, logos, and trademarks are the property of their respective owners and are used solely for identification. Docker claims no interest in those marks, and no affiliation, sponsorship, or endorsement is implied.