Claude Code’s Own Sandbox, Inside Docker

Anthropic gave Claude Code its own bubblewrap sandbox. Turn it on inside a Docker container and it dies four layers deep – and the obvious fixes make it worse. Here is what is actually going on, and the two small profiles that make it work without handing the container CAP_SYS_ADMIN.

[Read more]

Putting a Code-Review LLM in the CI/CD Pipeline

Putting a Code-Review LLM in the CI/CD Pipeline

What actually happens when you wire a self-hosted model into CI to review every push: a story of checklists that reviewed nothing, reasoning that buried its own findings, the surprisingly scientific business of measuring whether your robot reviewer is any good – and the winner’s first three days on the job.

[Read more]

WalledClaude: My Claude Container, Improved

Back in May I wrote up my setup for running Claude Code inside a Docker container, so an AI agent can work on my code without also being able to work on my workstation. The nicest thing that can happen to a post like that has now happened: someone more diligent than me read it, took the idea seriously, and built it properly.

That someone is Justin, and the result is WalledClaude. (He also asked, very courteously, whether he could license his work derived from my blog post under an MIT licence: of course the answer was yes, and I’m delighted – that’s how this is all supposed to work.)

My original post was mostly about convenience with a security boundary attached: get the agent off my filesystem, keep file ownership sane, contain the blast radius. Justin kept the convenience and then did the hardening I hand-waved past. From the repo:

  • Every Linux kernel capability dropped (--cap-drop=ALL) and no-new-privileges set, so the container can’t escalate its way to anything interesting.
  • Resource limits on CPU and memory, so a runaway agent is an annoyance rather than an outage.
  • The big one: a Squid egress proxy in front of the container, so outbound network access is controlled at the domain level – by default only the Anthropic endpoints the CLI actually needs. My version quietly trusted the container’s network access; his assumes the agent might phone somewhere it shouldn’t, which is the correct assumption.
  • Sandboxed and regular Claude data kept apart in a separate ~/.walledclaude/ tree, so the jailed agent doesn’t share state with anything outside the jail.
  • A README with an actual threat model and a “things to consider” section, including honest statements about what it does not protect against. Documentation of the limitations is the part most projects skip, and it’s the part I’d recommend reading first.

He also spotted that docker run --user takes a UID/GID directly, making my pass-the-environment-variables-to-the-entrypoint dance unnecessary.

Drafted by Claude, edited by me. I write these things mostly for my own memory – but it turns out sometimes they get compiled into other people’s better software, which is the best outcome available.

Why I Run Local Models

Why I Run Local Models

Yet again, Claude is down. Yet again, my local models just keep working. A case study in why the complexity of self-hosted AI is worth it.

[Read more]

Long time no see

It’s been a while since I last wrote here. So long that I’m not sure the site build system actually still works - which is kinda why I’m writing this post; I’ve just migrated my git repositories to self-hosted Gitlab CE (this site uses a ‘gitops’ style of build and deploy using Gitlab CI and ArgoCD), and I need to check the whole thing still works - which means, I need to write something. The excuse for waiting so long is boring: I got a new job about a year ago, and it’s been busy.

But it hasn’t just been work keeping me busy; I’ve also been busy migrating all my digital ‘stuff’ onto self-hosted or European alternatives.

Why

Well, unless you’ve been hiding under a rock, you’ll have noticed the President of the United States telling Europe that using US providers is a sign of weakness - and who am I to argue with such a towering intellect? So, over the past year, I’ve been quietly migrating everything I can to EU-based providers or self-hosted solutions. The challenge, as with any migration, has been finding suitable replacements that don’t compromise on functionality or reliability.

The What (Coming Soon!)

I’ve got quite a few migrations under my belt now, and I plan to document them properly in future posts:

  • VPS and Object Storage: Moving from Google Cloud Platform and AWS to Scaleway. Why Scaleway? Because they’re European, they’re GDPR-compliant, and their pricing is actually reasonable.

  • Cloud Storage: Ditching Google Drive and OneDrive for a self-hosted Nextcloud instance. Actually, I’ve been using Nextcloud for a few years now - but now I’ve migrated everything off Google and Microsoft, and am using it 100% - and as the storage backend for some of the solutions below.

  • Git Hosting: Migrating from GitLab.com to my own self-hosted GitLab instance. This post is the test run for that migration’s GitOps workflow. I might make this my first topic for more detail - because Dear God, the Gitlab Helm chart is badly documented…

  • Social Media: Trading Reddit for Lemmy on Kubernetes. Honestly, I’m still not sure about this one - ditching social media entirely seems an even better idea, and I can’t claim to be entirely Reddit-free yet either. But, suck it and see; first impressions are that it’s a more interesting social space than my experiments with Mastodon a few years ago, anyway.

  • Note Taking and Generally Organising Life: Moving from Notion to Joplin. Is the Joplin UI better than Notion? Absolutely not; but it is extremely nice to know where my data is being held (on my own servers!), and it’s not as if Notion was perfect either (their MCP implementation is completely broken, for a start.)

  • Collaboration Tools: Replacing Google Docs and Miro with Collabora and Nextcloud Whiteboard. Actually, replacing Google Docs (which is awful) isn’t the hard part here. The one service I really can’t find a good replacement for is Canva; on the one hand, Canva are as far as I know Australian (and Australia hasn’t threatened to annex any parts of Europe yet) so this isn’t top of my priorities, on the other it would be great to find a good open-source replacement.

Back to Work

So, in a world where the Internet is rapidly becoming overrun with the same old AI-generated SEO-optimised slop, I will endeavour to write up “How To” documents for some of the above, for any humans that do stumble this way to read. I can’t promise no AIs will be harmed in its generation (actually, writing up some more about current local-hosted AI models is also on the to-do list,) but I can promise it won’t be optimised. At all.