Bubblewrap provides a simpler, more secure alternative to Docker or dedicated user accounts for sandboxing AI coding agents like Claude Code. By wrapping agent invocations with Bubblewrap at the OS level, you control filesystem access, prevent secret exposure, and avoid trusting vendor implementations. The approach uses Linux
Table of contents
What Changed Since My Last PostThe Security Problem We’re SolvingWhat Is Bubblewrap?How This Command WorksWhy Bubblewrap Beats DockerQuick Start: Running Claude Code with BubblewrapWhy Not a Dedicated User Account?Why Use Your Own Bubblewrap Instead of Anthropic’s Sandbox?A comparison of what you’re trusting with user-wrapped invocation of bubblewrap versus embedded bubblewrap in a clientThe Trust MatrixDon’t trust me either!Wrapping UpSort: