← All writing
blog

Running Claude In Docker

Build a docker image for claude-code using this Dockerfile

FROM oven/bun:1.3.10-slim
RUN set -ex \
&& apt update \
&& apt install -y \
git \
jq \
sudo \
tree \
curl \
wget \
iptables \
grep \
fzf \
ripgrep \
gopls \
btop \
htop \
xxd \
fd-find \
dnsutils \
telnet \
file \
python3 \
&& bunx playwright install-deps chromium \
&& curl -L https://github.com/rust-lang/rust-analyzer/releases/latest/download/rust-analyzer-x86_64-unknown-linux-gnu.gz | gunzip -c > /usr/local/bin/rust-analyzer \
&& chmod +x /usr/local/bin/rust-analyzer
# Map the host's userid and groupid to the user in the container
ARG HOST_UID=1000
ARG HOST_GID=100
RUN set -ex \
&& groupmod -g ${HOST_GID} bun \
&& usermod -u ${HOST_UID} -g ${HOST_GID} bun \
&& chown -R bun:bun /usr/local/bin
USER bun
# install chromium for playwright and agent-browser
RUN set -ex \
&& bunx playwright install chromium
# install language servers
RUN set -ex \
&& bun install --global \
typescript-language-server \
typescript \
agent-browser \
pyright \
intelephense
ENV BUN_USER_HOME="/home/bun"
RUN set -ex \
&& mkdir -p "$BUN_USER_HOME/.local/bin" \
&& ln -s $(which fdfind) "$BUN_USER_HOME/.local/bin/fd"
RUN set -ex \
&& git config --global user.email "shenoy.ameya@gmail.com" \
&& git config --global user.name "Ameya Shenoy"
ENV PATH="$BUN_USER_HOME/.local/bin:$PATH"
ENV PATH="$BUN_USER_HOME/.bun/bin:$PATH"
ENV DISABLE_AUTOUPDATER=1
ARG CLAUDE_CODE_VERSION=latest
RUN bun i -g ccstatusline@latest
RUN curl -fsSL https://claude.ai/install.sh | bash -s "$CLAUDE_CODE_VERSION"
RUN claude install

Setup an alias for this in your bashrc or zshrc

Terminal window
docker run -it --rm \
-v "$PWD:$PWD" \
-v "$HOME/.claude:/home/bun/.claude/" \
-v "$HOME/.claude.json:/home/bun/.claude.json" \
-v "$HOME/.claude.json.backup/:/home/bun/.claude.json.backup" \
-v "$HOME/.dotfiles/ccstatusline/.config/ccstatusline/settings.json:/home/bun/.config/ccstatusline/settings.json:ro" \
-v "$HOME/Pictures/Screenshots:$HOME/Pictures/Screenshots" \
-u "$(id -u):$(id -g)" \
-e TZ="Asia/Kolkata" \
--memory="2.5g" \
--memory-swap="2.5g" \
--memory-reservation="1g" \
--network host \
--workdir "$PWD" \
codingcoffee/claude-code \
sh -c "claude"

What this allows

  • remember your claude-code settings
  • give claude-code access to Screenshots directory in case you’ve keep giving it screenshots while working on UI
  • make changes to files as your user even when inside the container
  • cap the memory usage of claude-code to 2.5 GB RAM
  • allow claude-code to access host network, so it can still access your serer at http://localhost:8000

What this prevents

  • will prevent the agent to modify anything and everything on the host, wrecking havoc
  • will prevent claude from accessing files and directories which are none of its concern, only the project directory is allowed. even if it wants to access your SSH keys it cannot