Anthropic's Claude Code as a mixin — the native install in an overlay, with the `anthropic` cre...
2.2K
The Claude Code CLI as a mixin — the native binary in an overlay, with the Anthropic credential (API key or claude.ai OAuth), session-state volumes, and the hooks the agent needs. Layer it onto a shell base and run `claude`.
| Name | Required | Default | Description |
|---|---|---|---|
version | Optional | 2.1.285 | Claude Code release to install |
[email protected]| Type | Required | Description | |
|---|---|---|---|
com.docker.sandbox/network-policy@1 | Required | — | |
com.docker.sandbox/credential@1 | Optional | Anthropic API access (API key or claude.ai OAuth) | |
com.docker.sandbox/volume@1 | Required | Conversation history; grows without bound, gets the headroom | |
com.docker.sandbox/volume@1 | Required | Per-session state; load-bearing for `claude -c` | |
com.docker.sandbox/volume@1 | Required | TodoWrite state | |
com.docker.sandbox/volume@1 | Required | Bash state snapshots across sessions | |
com.docker.sandbox/volume@1 | Required | Local feature-flag cache | |
com.docker.sandbox/lifecycle@1 | Required | — | |
com.docker.sandbox/agent-skills@1 | Optional | — | |
com.docker.sandbox/agent-context@1 | Required | — | |
sbx run <agent> --kit docker/sbx-kit-claude-mixin:latestRun the following command to install sbx on your machine.
brew install docker/tap/sbxwinget install Docker.sbxNote
Experimental: Sandbox Kit v3This kit uses the experimental Sandbox Kit specification, specifically v3. The format and runtime behavior may change before v3 is stable.
Claude Code as a mixin (kind: mixin,
schemaVersion: "3") — the same agent the claude workload kit
ships, packaged as an overlay you layer onto a shell base instead of booting as
the whole environment.
Use this one when the sandbox already has a workload you want to keep (a shell,
a language toolchain, another team's base image) and you want claude in it.
Use claude when Claude Code is the environment.
sbx run --kit ./claude-mixin/ <base-agent>
The two are mutually exclusive: both provides: ["claude"], and a composition
with two providers of one name is refused — the workload already carries the
agent this mixin installs.
Everything the workload declares that belongs to the agent rather than to the environment:
anthropic credential, covering both a console API key and a Claude
subscription, with the same deliberate omission of proxyManaged (see the
workload's README);apt-get update needs;~/.claude/ session-state volumes;settings.json seeded from
the surfaced auth mode, MCP gateway registration;CLAUDE.md.The install itself is the unmodified upstream one, run over the workload's base
in a build stage and staged into a scratch overlay. Anthropic's installer is
not relocatable and the install method is what claude update drives, so the
mixin keeps it rather than swapping in a --prefix build.
| Left out | Why |
|---|---|
ENTRYPOINT | The base's launch command stays; you run claude from the shell. |
sbx@1 | A mixin's image config is not the composed image's, so the identity and shells that type is a claim about are the base's. |
agent-context filename: | CLAUDE.md names the profile, which belongs to the workload. This kit contributes a body to it. |
agent-sessions@1 | The session verbs are argv tails on a launch command this kit does not own. |
IS_SANDBOX and the telemetry switches as image ENV | A mixin's ENV does not become the composed image's, so they ride the overlay as /etc/profile.d/claude-mixin-env.sh exports instead. |
claude — the same agent as a standalone workload kit.claude-mem, claude-acp,
claude-sbx-statusline, ecc,
claude-model-runner — mixins that
requires: ["claude"] and therefore compose onto either shape.Pulls:
475
Last week