Skip to content

Sandbox runtimes: mount Claude and cloud credentials from the coordinator by path (full profile) #462

Description

@mecattaf

What Tom ruled (2026-09-23, verbatim)

claude's credential, as with any other cloud credential, lives on the coordinator dotfiles. i m actually flexible here: keeping the same dotfiles-side nixos secrets (that is durable anyway, claude code secrets rotate frequently anyway). we can do a dotfiles gh issue to make any changes needed. i m fine having those credentials made available nix-wide by the way, without an apparent need for secrets mgmt.

Context: the successor scheduler's default full runtime profile runs a Claude Code harness inside a gVisor sandbox on the coordinator (Tom: "running carte blanche containers is the equivalent of running ultracode-workflows the same way i do it live with claude code today anyway. this would just make it async"). Evidence: ~/today/evals-2026-09-23/substrate/SANDBOX-CLASS-AND-DEFAULTS-2026-09-23.md, ~/today/START-HERE-2026-09-23.md.

Proposed change

  1. One declared source per seat. For each Claude seat (cc first), dotfiles declares the credential path the sandbox runtimes mount, instead of each runtime discovering ~/.claude* on its own. The live file is used, so a refresh by Claude Code is seen on the next job.
  2. Mount by path, never copy into the nix store. Claude Code credentials refresh often, and /nix/store is world-readable. The runtimes (gVisor full profile, the ax task image path, microvm.nix credentialFiles) mount the file read-write, so a token refreshed inside a job is not lost.
  3. Non-Claude cloud credentials follow the same pattern: an agenix path per credential, named in one module that the runtimes read.
  4. No new secrets manager. Cloudflare secrets stay available for Worker-side secrets only.

Acceptance

  • A full-profile job on the coordinator runs claude -p --model claude-opus-5-5 with the declared cc credential and succeeds.
  • nix path-info -r of every sandbox runner and image contains no credential file.
  • After Claude Code refreshes the token on the host, the next job uses the new token without a rebuild or switch.

Unknowns and proposed defaults

  • Read-write or read-only mount. Default: read-write, so a refresh inside a job persists (Tom's 2026-09-21 seat-config ruling).
  • Which seats. Default: cc only. cc2 waits on its re-login, and Codex stays out per the seat rule.
  • Open internet inside full means a hijacked job could send the token out. Tom accepted this trade. The locked profile (no network, no credential) remains the opt-in for untrusted input.

🤖 Generated with Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions