Chapter 09 · CLI
Sandbox, isolated environments and devcontainers
Running commands inside a sandbox reduces the chance a tool action harms your system. You can choose between built-in sandboxing, isolated environments and devcontainers, based on the isolation level needed.
Video
Steps
- Get to know the built-in Bash sandboxing options and enable them when running unfamiliar code.
- An isolated environment (like a container or VM) fits work with more open permissions, because damage stays inside.
- Devcontainers give a defined, reproducible development environment; combining them with Claude Code is covered in the dedicated page.
- Match isolation to permission level: the more open the permissions, the stronger the isolation should be.
Common pitfall: A sandbox is not a full guarantee: network access or sensitive environment variables can still leak from an isolated environment; check what the environment exposes.
Hands-on exercise: Run a safe command inside a sandbox and check what is blocked and what passes. Record the network settings and variables the environment exposes.
Filmed demo · Video is added in the media phase
Recap
Comprehension check
What is the guiding principle when combining permissions and environments?
Recap
- Sandboxing reduces command damage
- Isolation matches the permission level
- Check what the environment exposes to the network