Skip to content

systemd-claude-sandbox

Run Claude's code-execution sessions on hardware you control. One compose stack, one systemd unit, any Linux host.

A sandbox you own

Implements Anthropic’s self-hosted sandbox contract for Claude Managed Agents. Your worker polls the queue outbound; nothing on your host accepts inbound connections from Anthropic.

One command up

bash install.sh probes your machine for Docker, Podman, Bun, WSL, and VS Code, prints its reasoning, and launches the best mode it finds.

MCP servers, tunneled out

The bundled mcp-tunnel multiplexes any number of in-sandbox MCP servers behind one Streamable HTTP listener, with pluggable publish transports.

Two runtimes, one contract

Run sessions in local containers or on Cloudflare Sandboxes. Same filesystem contract, same worker, different runtime.