Skip to main content

Docker · Sandboxes

Run an agent in a sandbox

A coding agent that runs commands needs somewhere safe to run them. Docker Sandboxes give it an isolated microVM on your own machine, and the sbx command line and local sandboxes are free to use, including for commercial work. This is the recipe for pointing one at a landing zone you build on this site.

Run an agent against your landing zone

Docker Sandboxes run a coding agent in a microVM on your own machine, with the folder you name mounted inside and nothing else. The recipe linked below builds a template with Claude Code, terraform and the Azure CLI already installed, and an AGENTS.md that tells the agent the folder is a landing zone generated for learning: validate and explain it, never plan or apply it. Build and load the template once from the recipe README, store your Anthropic key with sbx secret set anthropic, then:

  1. Build a landing zone in the Landing Zone Builder and download the zip.
  2. Unzip it and change into the folder it made, so the Terraform files are in the current directory.
  3. Create the sandbox from that folder and open the agent in it. Pick the line for the shell you are in; the folder is mounted at the same path inside the sandbox.
PowerShell
sbx run --name hcw-lz --template hcw-lz-sandbox:v1 claude .
bash
sbx run --name hcw-lz --template hcw-lz-sandbox:v1 claude .

When Claude Code opens, paste this first: Explain what this landing zone deploys, then run terraform init -backend=false, terraform fmt -check and terraform validate and tell me what each printed.

Local sandboxes are free. Cloud sandboxes (sbx --cloud) bill your own Docker subscription, cannot mount this folder, and expire after one hour by default.

The recipe on GitHub: lab-image/sandbox-template (Dockerfile, AGENTS.md, and the README with the build, load and cloud commands; opens in a new tab)

The sbx command line changes often, so these commands are checked against Docker’s documentation. They were last checked on .