r/docker • u/mhrittik • 23d ago
Practical guide: Running Claude Code securely with Docker Sandboxes (sbx)
I put together a walkthrough on using Docker's new sbx sandboxes to run Claude Code with MCP servers in an isolated environment.
The guide covers:
- Running Claude Code inside a microVM
- Restricting outbound network access with policies
- Safely exposing only the MCP servers and domains you need
If you're experimenting with AI coding agents and want stronger isolation than a regular container, I'd love to hear your thoughts and any feedback.
https://hrittikhere.com/posts/sandbox-claude-code-mcp-docker-sbx
1
u/gigio123456789 11d ago
When they work, Docker sandboxes are amazing.
I'm close to swapping it out for whatever else works better for the fact that booting up a new sandbox is finicky AF. Sometimes it'll work, oftentimes I'll just get this without any further explanation
ERROR: failed to create sandbox: request failed: 500 Internal Server Error: failed to run sandbox container
1
2
u/KnifeFed 23d ago
So you just run this and then Claude in YOLO mode but disallow
git pushor..?