The Complete Claude Guide
Chapter 09 · CLI

Sandbox, isolated environments and devcontainers

Running commands inside a sandbox reduces the chance a tool action harms your system. You can choose between built-in sandboxing, isolated environments and devcontainers, based on the isolation level needed.

Verified against source on 2026-09-30

Video

Steps

  1. Get to know the built-in Bash sandboxing options and enable them when running unfamiliar code.
  2. An isolated environment (like a container or VM) fits work with more open permissions, because damage stays inside.
  3. Devcontainers give a defined, reproducible development environment; combining them with Claude Code is covered in the dedicated page.
  4. Match isolation to permission level: the more open the permissions, the stronger the isolation should be.
Common pitfall: A sandbox is not a full guarantee: network access or sensitive environment variables can still leak from an isolated environment; check what the environment exposes.
Hands-on exercise: Run a safe command inside a sandbox and check what is blocked and what passes. Record the network settings and variables the environment exposes.
Filmed demo · Video is added in the media phase

Recap

Comprehension check

What is the guiding principle when combining permissions and environments?

Recap

Official sources

← Previous Back to contents Next →