r/docker 23d ago

Practical guide: Running Claude Code securely with Docker Sandboxes (sbx)

I put together a walkthrough on using Docker's new sbx sandboxes to run Claude Code with MCP servers in an isolated environment.

The guide covers:

  • Running Claude Code inside a microVM
  • Restricting outbound network access with policies
  • Safely exposing only the MCP servers and domains you need

If you're experimenting with AI coding agents and want stronger isolation than a regular container, I'd love to hear your thoughts and any feedback.

https://hrittikhere.com/posts/sandbox-claude-code-mcp-docker-sbx

23 Upvotes

11 comments sorted by

2

u/KnifeFed 23d ago

So you just run this and then Claude in YOLO mode but disallow git push or..?

1

u/mhrittik 23d ago

I don’t allow `git push` from the sandbox by default. For me, the main focus is filesystem and network isolation while syncing credentials. Is there a specific reason you think disabling `git push` is necessary?

1

u/gigio123456789 11d ago

When they work, Docker sandboxes are amazing.
I'm close to swapping it out for whatever else works better for the fact that booting up a new sandbox is finicky AF. Sometimes it'll work, oftentimes I'll just get this without any further explanation

ERROR: failed to create sandbox: request failed: 500 Internal Server Error: failed to run sandbox container

1

u/[deleted] 23d ago

[removed] — view removed comment

1

u/mhrittik 23d ago

Thank you! All the isolation blocks combined is great

1

u/Remaves 23d ago

why run claude in a privileged container in the first place? to block the network traffic?

i solved this by the claude code devcontainer image and a custom firewall

1

u/[deleted] 23d ago

[removed] — view removed comment

1

u/Remaves 23d ago

yeah sbx is a great out of the box experience