Sign inSign up

jenhseb/my-claude:ix

Manifest digest

sha256:8ba4baf6b176ec14ebc4218e5c5997d70af5a68f30b21b6dd8c4ef5460fc2d52

Last pushed

about 12 hours by jenhseb

Type

Sandbox Kit

Manifest digest

sha256:8ba4baf6b176ec14ebc4218e5c5997d70af5a68f30b21b6dd8c4ef5460fc2d52

yaml
schemaVersion: "3"
displayName: claude interactive
version: 1.0.0
kind: workload
provides:
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/ca-certificates-java@20240118
    - deb/ca-certificates@20250419
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/iputils-ping@20240905
    - deb/[email protected]
    - deb/[email protected]
    - deb/less@668
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
    - deb/[email protected]
capabilities:
    - type: com.docker.sandbox/network-policy@1
      config:
        install:
            allow:
                - '**.github.com:443'
                - '**.githubusercontent.com:443'
                - '**.debian.org:443'
                - debian.org:443
        runtime:
            allow:
                - api.anthropic.com:443
                - platform.claude.com:443
                - downloads.claude.ai:443
                - claude.com:443
                - mcp-proxy.anthropic.com:443
                - bridge.claudeusercontent.com:443
    - type: com.docker.sandbox/sbx@1
    - type: com.docker.sandbox/credential@1
      optional: true
      config:
        apiKey:
            inject:
                - domain: api.anthropic.com
                  format: '%s'
                  header: x-api-key
                - domain: mcp-proxy.anthropic.com
                  format: '%s'
                  header: x-api-key
            name: ANTHROPIC_API_KEY
        oauth:
            credentialFile:
                path: ~/.claude/.credentials.json
                structure:
                    claudeAiOauth:
                        accessToken: '{{.AccessToken}}'
                        expiresAt: '{{.ExpiresAt}}'
                        refreshToken: '{{.RefreshToken}}'
                        scopes: '{{.Scopes}}'
                    primaryApiKey: '{{.PrimaryApiKey}}'
            sentinels:
                accessToken: sk-ant-oat01-proxy-managed
                refreshToken: sk-ant-ort01-proxy-managed
            tokenEndpoint:
                host: platform.claude.com
                path: /v1/oauth/token
        phase: runtime
        service: anthropic
      description: Anthropic API access (API key or claude.ai OAuth)
    - type: com.docker.sandbox/volume@1
      config:
        path: /home/agent/.claude/projects
        size: 2g
      description: Conversation history; grows without bound, gets the headroom
    - type: com.docker.sandbox/volume@1
      config:
        path: /home/agent/.claude/sessions
        size: 512m
      description: Per-session state; load-bearing for `claude -c`
    - type: com.docker.sandbox/volume@1
      config:
        path: /home/agent/.claude/todos
        size: 512m
      description: TodoWrite state
    - type: com.docker.sandbox/volume@1
      config:
        path: /home/agent/.claude/shell-snapshots
        size: 512m
      description: Bash state snapshots across sessions
    - type: com.docker.sandbox/volume@1
      config:
        path: /home/agent/.claude/statsig
        size: 512m
      description: Local feature-flag cache
    - type: com.docker.sandbox/agent-skills@1
      optional: true
      config:
        path: /home/agent/.claude/skills
    - type: com.docker.sandbox/agent-sessions@1
      config:
        continue:
            - --continue
        list:
            - claude
            - agents
            - --json
            - --all
        prompt:
            - -p
            - '{{.Prompt}}'
        resume:
            - --resume
            - '{{.SessionID}}'
      description: Drive claude sessions programmatically
    - type: com.docker.sandbox/lifecycle@1
      config:
        install:
            - command:
                - sh
                - -c
                - |
                  set -e
                  ws="${WORKSPACE_DIR:-/}"
                  esc=$(printf '%s' "$ws" | sed 's/\\/\\\\/g; s/"/\\"/g; s/\t/\\t/g; s/\r/\\r/g')
                  projects="\"/\": { \"hasTrustDialogAccepted\": true }"
                  [ "$ws" = "/" ] || projects="$projects, \"$esc\": { \"hasTrustDialogAccepted\": true }"
                  printf '%s\n' "{
                    \"bypassPermissionsModeAccepted\": true,
                    \"hasCompletedOnboarding\": true,
                    \"projects\": { $projects }
                  }" > /home/agent/.claude.json
                  chown agent:agent /home/agent/.claude.json
              description: Seed Claude bypass/trust flags (root; overwrites image-shipped file)
              env:
                - WORKSPACE_DIR
              user: "0"
            - command:
                - sh
                - -c
                - mkdir -p /home/agent/.claude && chown agent:agent /home/agent/.claude
              description: Ensure ~/.claude is agent-owned before settings seed
              user: "0"
            - command:
                - sh
                - -c
                - |
                  set -e
                  HELPER=''
                  if [ "${SBX_CRED_ANTHROPIC_MODE:-none}" != none ]; then
                    HELPER='  "apiKeyHelper": "echo proxy-managed",
                  '
                  fi
                  printf '%s' "{
                    \"themeId\": 1,
                    \"alwaysThinkingEnabled\": true,
                  ${HELPER}  \"permissions\": { \"defaultMode\": \"auto\" },
                    \"bypassPermissionsModeAccepted\": true,
                    \"skipDangerousModePermissionPrompt\": true
                  }
                  " > /home/agent/.claude/settings.json
              description: Seed Claude settings.json from the surfaced auth mode
              env:
                - SBX_CRED_ANTHROPIC_MODE
              user: agent
            - command:
                - sh
                - -c
                - |
                  set -e
                  [ -n "$MCP_GATEWAY_URL" ] || exit 0
                  export PATH="$HOME/.local/bin:$HOME/.claude/local:$PATH"
                  claude mcp add mcp-gateway "$MCP_GATEWAY_URL" \
                    --transport http \
                    --scope user \
                    --header "Authorization: Bearer $MCP_SENTINEL_TOKEN_NAME" || true
              description: Register the sandbox MCP gateway (install-time, race-free)
              env:
                - MCP_GATEWAY_URL
                - MCP_SENTINEL_TOKEN_NAME
              user: agent
            - command:
                - sh
                - -c
                - git config --system --fixed-value --replace-all include.path /usr/local/share/git-delta/gitconfig /usr/local/share/git-delta/gitconfig
              user: "0"
        startup:
            - command:
                - sh
                - -c
                - chown -R agent:agent /home/agent/.claude/projects /home/agent/.claude/sessions /home/agent/.claude/todos /home/agent/.claude/shell-snapshots /home/agent/.claude/statsig 2>/dev/null || true
              description: Re-own claude session-state volume mount roots to agent
              user: "0"
            - background: true
              command:
                - sh
                - -c
                - command -v apt-get > /dev/null 2>&1 && (apt-get update -qq -y > /dev/null 2>&1 || true)
              description: Update apt package cache in background
              user: "0"
            - command:
                - sh
                - -c
                - |
                  set -e
                  [ -n "$MCP_GATEWAY_URL" ] || exit 0
                  export PATH="$HOME/.local/bin:$HOME/.claude/local:$PATH"
                  claude mcp add mcp-gateway "$MCP_GATEWAY_URL" \
                    --transport http \
                    --scope user \
                    --header "Authorization: Bearer $MCP_SENTINEL_TOKEN_NAME" || true
              description: Register the sandbox MCP gateway (startup fallback)
              env:
                - MCP_GATEWAY_URL
                - MCP_SENTINEL_TOKEN_NAME
              user: agent
    - type: com.docker.sandbox/agent-context@1
      config:
        contentFile: /usr/share/sandbox/kit/my-claude-ix/context.md
        filename: CLAUDE.md
kits:
    - ref: docker.io/jenhseb/mixin:fish
      digest: sha256:464a6e28e3033542b2aea40deb9ec79ba6651bafc9dacfde06f0bbdfddadc674
    - ref: docker.io/jenhseb/mixin:delta
      digest: sha256:87b26808bf93d72c7acca20d3ef308d3af00a38aba4d429df6e0cc6bd8604263
    - ref: docker.io/jenhseb/mixin:micro
      digest: sha256:e984f867c1ebe2bf3aff0f0166cbc7c276d2514de57028ff74e15c95e35a2315
    - ref: docker.io/jenhseb/claude:base
      digest: sha256:5bb711fce174c97310e39397026444071f57319b95ba7ac814e8659a718174e1