devcontainer
CLI to create devcontainer template for running AI agents in a container
Enhanced docker sandbox templates for using AI agents in a secure vm-based sandbox
The Docker Sandbox templates are built on top of the official docker/sandbox-templates base images.
The base images already contain common language runtimes (Python, Node.js, etc.) and development tools. And the templates add on top of that:
Create a sandbox from a template image:
cd /path/to/your/repo
# Use registry image
sbx create -t nlesc/sandbox:claude-code shell .
# Or use locally built image
sbx create -t sandbox:claude-code shell .
Start an interactive shell in the sandbox:
sbx exec -it <sandbox-name> zsh
You can also directly start AI agent:
sbx exec -it <sandbox-name> claude
However, it's recommended to start a shell first to set up the environment and then run the agent.
Now you can use the sandbox as a normal Linux environment, with all the tools and runtimes installed.
[!NOTE] Known issue with
sbx run:sbx run ... shellalways uses bash as the default shell, even though the templates have set zsh as default shell. So if you want to use zsh, you need to usesbx execinstead ofsbx run.
For more info on how to use the sandbox, see the official documentation.
You can use VS Code to edit files in the sandbox directly from your host machine, which is very convenient for development.
Start VS Code tunnel from the sandbox:
code tunnel --accept-server-license-terms
The first time you run this, it will prompt you to authenticate with GitHub.
After the first time, you can start it in the background:
code tunnel --accept-server-license-terms > /tmp/tunnel.log 2>&1 &
Connect to the tunnel from VS Code on your machine:
Cmd+Shift+P > Remote-Tunnels: Connect to Tunnel...Now you can edit files in the sandbox directly from VS Code on your machine!
[!WARNING] If your repo has
devcontainer.json, disable the "Dev Containers" extension before connecting to the tunnel, as it will try to start a dev container which doesn't work in this setup.
Apache License 2.0
Leveraging GenAI for Research Software Engineering
CLI to create devcontainer template for running AI agents in a container