Run Claude Code, Codex CLI, pi, Mistral Vibe, and OpenCode in one shared Docker sandbox. Host paths, user identity, shell, Git configuration, and normal Docker Compose workflows are mirrored closely enough that each harness still feels native.
This is an opinionated daily-driver safety net for bad prompts, not bad actors. It reduces accidental damage without claiming to contain deliberately hostile code. Do not mount sensitive data or expose Docker access when adversarial-code isolation is required. See Security and accepted security issues.
| Harness | Launcher | Guide |
|---|---|---|
| Claude Code | claude-docker |
Claude Code |
| Codex CLI | codex-docker |
Codex |
| pi | pi-docker |
pi |
| Mistral Vibe | vibe-docker |
Mistral Vibe |
| OpenCode | opencode-docker |
OpenCode |
Requirements are macOS or Linux on amd64 or arm64, Docker Compose v2, and host authentication for at least one harness. Go 1.23 or newer is needed only to build optional host tools such as the beeper and MCP gateway.
export PATH="/path/to/harness-docker/bin:$PATH"
cp config/docker-compose.local.example.yml config/docker-compose.local.yml
# Edit the local file to mount only the project roots the sandbox may access.
harness-docker-ctrl start
harness-docker-ctrl status
codex-dockerLaunch from a mounted working directory. Arguments are forwarded to the selected
harness. Use harness-docker-ctrl shell, exec, rebuild, gc, or stop for
shared lifecycle operations. Read Setup before first use.
rebuild refreshes the harness CLIs while reusing cached base layers; pass
--no-cache for a full rebuild. Successful builds also tag the image as
harness-docker:latest for direct external runs.
- Setup and host integration
- Harnesses: Claude Code, Codex, pi, Mistral Vibe, and OpenCode
- Session lifecycle
- Generations and zero-downtime rebuilds
- Updates
- Security model and known limitations
- AWS credential proxy
- GPG signing
- Beeper and notifications
- Host MCP gateway
- Migration from the standalone stacks
- Development and testing
This repository replaces the separate claude-docker, codex-docker,
pi-docker, and vibe-docker repositories with one image, lifecycle, security
policy, and set of host integrations. Existing launcher names remain unchanged.
See the migration guide before retiring an old stack.
See LICENSE.