Skip to content

feat: sandbox Claude Code with nono#434

Open
stackptr wants to merge 2 commits intomainfrom
feat/nono-claude-code-sandbox
Open

feat: sandbox Claude Code with nono#434
stackptr wants to merge 2 commits intomainfrom
feat/nono-claude-code-sandbox

Conversation

@stackptr
Copy link
Copy Markdown
Owner

@stackptr stackptr commented Apr 10, 2026

Summary

  • Install nono and write a claude-code sandbox profile (extending the built-in) with Nix-specific read paths (/nix/store, /nix/var/nix/profiles, /run/current-system/sw, ~/.nix-profile) for all hosts with rc.development.ai.enable = true
  • Wrap the claude binary so it always runs inside the nono sandbox
  • On macOS, also provide a claude-login command that adds --allow-launch-services for the initial OAuth flow only
  • Set allowUnsandboxedCommands = false in Claude Code settings

Copy link
Copy Markdown
Owner Author

This stack of pull requests is managed by Graphite. Learn more about stacking.

@stackptr stackptr marked this pull request as ready for review April 10, 2026 21:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant