How-to Guides#
Focused recipes for specific tasks you already know you need to do.
Most are workflow conveniences. The security-relevant ones: Configure the network egress jail — read it if your host needs --device=/dev/net/tun or you address lab devices by bare IP; and Enforce sandbox use across an organisation — for IT/platform teams rolling the sandbox out as policy.
- Authenticate with forges
- Make extra paths writable
- Contribute to claude-sandbox
- Enforce sandbox use across an organisation
- Configure the network egress jail
- Pass environment variables in
- Persist your login and memory across rebuilds
- Promote a host workspace
- Run without push access
- Upgrade claude-sandbox
- Use the prebuilt container image (no devcontainer)
- Verify the sandbox