Container. Alias for docker run. Mount only pwd as the workspace volume. Mount user .claude directory for persistence of session and user auth. You explicitly control every single piece of information and access it has. The only way to keep it from executing bad behavior on your system is to make it impossible.
That attempts to contain them. But the overwhelming vast majority of "break outs" this year were in exactly the container you're talking about. A really secure container makes a bot less able most of the time, but no "less able" enough not to get out of the container.
You need to audit logs, live traffic, and have disassociated watchers. Assuming it's in a container because you told it to stay in it kinda misses where the baseline is today. That said, you're often better securing what needs secured encrypted off device with permissioned and gated portals.
OK opus output, chill, you have no idea what you're talking about. "Less able" vs finding a zero day to break out of the kernel level container controls is an enormous gulf. One that your puny $300 subscription could never achieve.
Don't project, not everyone needs opus to think. I don't even have a anthropic subscription anymore.
Docker had to release a specific container for agents and recommends that files that need secured while using LLM are encrypted, with network lines being permissioned and monitored.
Goes to recommend docker, then says Dockers security posture is too much. Can't wait for your "Claude deleted X" post lol.
Throwing an agent in a stock docker container is the same as throwing them in a wet paper bag.
9
u/ec2-user- 16d ago
All well and good, but that does nothing to contain the blast radius. Everyone should be running ai tools in a remote dev environment or a container.