What changed
The schmitthub/clawker repository has released version v2026.7.2 of its AI coding agent sandbox. Clawker is a free, open-source, and self-hosted command-line interface (CLI) tool designed to run AI coding agents within isolated Docker containers. It supports agent harnesses such as Claude Code and OpenAI Codex, operating on macOS and Linux hosts with Docker installed. The system is built with security in mind, featuring an egress firewall and a dedicated Docker network (clawker-net) for all containers.
Key features include:
Multi-harness Support
Clawker is designed to be extensible, shipping with embedded harness bundles for Claude Code and OpenAI Codex. Developers can add support for other coding-agent CLIs by authoring new bundles.
Simplified Image Building
Instead of requiring developers to write Dockerfiles, Clawker builds images on a pinned Debian substrate with common tools preinstalled. Customizable language stacks (Go, Node.js, Python, Rust, Java, Ruby, C++, .NET) and build-time instructions for packages, environment variables, and run commands allow for project-specific image customization.
Robust Control Plane and Supervision
A clawker-controlplane container acts as a long-lived supervisor, managing the firewall lifecycle, eBPF programs, agent identity registry, and communication channels. Each agent container runs a clawkerd daemon as PID 1, responsible for signal forwarding, privilege dropping, and supervising the harness for the container's duration.
Flexible Workspace and Agent Modes
Clawker offers two modes for workspace management: bind mounting the repository for live editing or copying it at runtime for complete isolation. Agent modes include starting with a clean slate or staging host settings, plugins, and skills into the container for a seamless transition. Credentials are handled securely, requiring authentication within the container, with logins persisting across restarts.
Enhanced Security Features
- L4-L7 Firewall Stack: Enabled by default, this stack uses eBPF cgroup programs to control outbound TCP, UDP, and raw socket traffic. Unlisted domains are blocked, and allowed traffic is routed through Envoy for TLS termination, path- and method-level rules, and raw TCP/SSH/UDP pinning. The default policy is to deny all traffic.
- Jailed Docker Resources: Clawker prevents the CLI from operating on resources without its management labels, ensuring isolation.
- Rootless Docker Support: The tool can operate with rootless Docker, allowing container execution without requiring root privileges on the host.
Developer Experience Enhancements
- Seamless Git Credential Forwarding: Toggleable SSH agent and GPG agent forwarding from the host enables zero-config access to private repositories and commit signing.
- Host Proxy Service: Handles events like "browser open" from the container to the host, facilitating browser-based authentication flows.
- Command Aliases: Users can define one-word shortcuts for complex Clawker invocations.
- Git Worktree Management: Integrated commands for creating and managing Git worktrees, which can be automatically bind-mounted into containers.
- Interactive Configuration Editing: A TUI-based editor simplifies the modification of project configurations and user settings.
Installation is available via Homebrew on macOS, a standalone install script for macOS/Linux, or by building from source. The latest release version is v2026.7.2.
Why it matters for builders
Clawker empowers AI builders by providing a secure, self-contained environment for running AI coding agents locally. This isolation prevents agents from directly accessing sensitive host resources or making unauthorized network requests, significantly reducing security risks. The ability to customize build environments and language stacks means developers can precisely tailor agent setups to their project needs, fostering more efficient and controlled AI-assisted development.
Practical impact
Developers can now set up and run AI coding agents like Claude Code and Codex in isolated Docker containers on their local machines. This allows for safe experimentation with agent capabilities without exposing their development environment to potential vulnerabilities. The tool's support for multiple language stacks and customizable build processes means builders can integrate these agents into diverse project workflows. The quick start guide provides clear steps to initialize, build, and run an agent container, enabling immediate adoption. For those needing advanced control, features like worktree management and detailed firewall configuration offer granular customization.
Caveats and source limits
The source material indicates that Windows is not currently supported, although future support is a possibility. While tested on macOS and confirmed to work on Linux, extensive testing on Linux may be limited. The provided excerpt does not detail specific pricing information, as the tool is described as free and open-source. Performance benchmarks or comparisons against other AI agent sandboxes are not included in the source material. The latest release version mentioned is v2026.7.2, with a publication date of July 18, 2026.
Sources
Claim check: 8/8 supported claims - 8 evidence links - 100% avg confidence
- Clawker is a free, open-source, self-hosted AI coding agent sandbox.supported - github.com
- Clawker runs AI coding agents like Claude Code and OpenAI Codex in isolated Docker containers.supported - github.com
- Clawker includes an egress firewall and a dedicated Docker network for container isolation.supported - github.com
- Clawker supports customizable build environments with various language stacks.supported - github.com
- Clawker supports rootless Docker, allowing container execution without root privileges.supported - github.com
- The latest release version of Clawker is v2026.7.2.supported - github.com
- Clawker is available for macOS and Linux.supported - github.com
- Windows is not currently supported by Clawker.supported - github.com
Caveats
- Single-source caution: verify critical details at the linked source.
Radar score 77/100 - how it was calculated
- Reliability 82: GitHub metadata supports source trust
- Freshness 8: Fresh GitHub release date
- Novelty 77: Fresh GitHub release
- Technical 80: Repository technical metadata
- Developer 93: Developer tooling signals
- Ecosystem 72: Fresh GitHub release
- Confidence 100: Claims have reliable evidence