Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
38 changes: 22 additions & 16 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,8 +3,9 @@
> [!NOTE]
> This project is meant for people working on the Rust Project infrastructure.

Run codex in a Linux VM using [lima](https://lima-vm.io/).
Control it from [ChatGPT desktop](https://chatgpt.com/download/).
Run Codex and Claude Code in a Linux VM using [lima](https://lima-vm.io/).
Use either CLI over SSH, or control Codex from
[ChatGPT desktop](https://chatgpt.com/download/).

The VM has read-only access to Cloud services like DataDog and Fastly.
Credentials are read automatically from the Rust Foundation 1Password.
Expand Down Expand Up @@ -50,10 +51,10 @@ Credentials are read automatically from the Rust Foundation 1Password.
you are experiencing issues, check the
[authentication docs](./docs/authentication.md).

- Enable "Device code authorization for Codex" in
- If using Codex, enable "Device code authorization for Codex" in
[ChatGPT security settings](https://chatgpt.com/#settings/Security).

- Login to Codex, Datadog and Fastly from the guest:
- Login to Codex, Claude Code, Datadog and Fastly from the guest:

```sh
just login
Expand Down Expand Up @@ -86,7 +87,12 @@ Place your projects in the host directory:
ssh lima-buddy
```

- (Optional) Launch the `codex` command inside the VM to start the Codex TUI.
- (Optional) Launch `codex` or `claude` inside the VM from your project directory:

```sh
cd ~/work/<project>
codex
```

See the [Lima SSH documentation](https://lima-vm.io/docs/usage/ssh/) for more details.

Expand Down Expand Up @@ -134,14 +140,14 @@ for more details.

The template explicitly sets `user.passwordlessSudo: true`, which is
[Lima's default for Linux guests](https://lima-vm.io/docs/config/sudo/).
This gives Codex unrestricted root access inside the guest, but does not grant
root access on the host. The VM boundary and the resources exposed to the VM,
such as the writable `$HOME/work` mount, remain the main security boundary.
This gives Codex and Claude Code unrestricted root access inside the guest, but
does not grant root access on the host. The VM boundary and the resources exposed
to the VM, such as the writable `$HOME/work` mount, remain the main security boundary.

Enabling passwordless sudo has this advantage:

- Codex and other automation can install packages, update the guest, and fix
system configuration without waiting for a password prompt.
- Codex, Claude Code, and other automation can install packages, update the guest,
and fix system configuration without waiting for a password prompt.

It also has these disadvantages:

Expand All @@ -154,10 +160,10 @@ It also has these disadvantages:

## FAQ

> Why not running Codex directly on the host?
> Why not run AI agents directly on the host?

Auditing all commands that codex wants to run is not productive. Instead, by
running it in an isolated VM, you can run codex in yolo mode.
Auditing all commands that AI agents want to run is not productive. Instead, by
running them in an isolated VM, you can run them in yolo mode.

> Why not using one VM per project?

Expand All @@ -174,10 +180,10 @@ Lima provides:
- It's an open source [CNCF project](https://www.cncf.io/projects/lima/), while Docker Desktop is a proprietary product.
- The Docker Desktop feature [Enhanced Container Isolation](https://docs.docker.com/enterprise/security/hardened-desktop/enhanced-container-isolation/), which "prevents malicious containers from compromising the host system" is restricted to Docker Business.

> I don't want to run codex with full privileges, I think it is dangerous!
> I don't want to run AI agents with full privileges, I think it is dangerous!

Nobody forces you to run codex with full privileges. You can still run it in the
`buddy` VM for improved security _and_ customize its permissions.
Nobody forces you to run AI agents with full privileges. You can
run them in the `buddy` VM for improved security _and_ customize their permissions.

## License

Expand Down
2 changes: 1 addition & 1 deletion buddy.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@ ssh:
forwardAgent: false
loadDotSSHPubKeys: false

# Codex can elevate to root inside the VM
# Codex and Claude Code can elevate to root inside the VM
# without receiving or storing the guest user's password.
user:
passwordlessSudo: true
Expand Down
6 changes: 5 additions & 1 deletion justfile
Original file line number Diff line number Diff line change
Expand Up @@ -29,11 +29,14 @@ delete: stop
delete-file path:
limactl shell "{{ vm }}" bash -lc 'rm -f "{{ path }}"'

login: login-codex login-datadog login-fastly
login: login-codex login-claude login-datadog login-fastly

login-codex:
limactl shell "{{ vm }}" bash -lc 'codex login --device-auth'

login-claude:
limactl shell "{{ vm }}" bash -lc 'claude auth login'

login-datadog:
cargo run --quiet -- login-datadog "{{ vm }}"

Expand All @@ -57,6 +60,7 @@ upgrade:
limactl shell "{{ vm }}" sudo apt-get upgrade
limactl shell "{{ vm }}" bash -lc 'brew update && brew upgrade --yes'
limactl shell "{{ vm }}" bash -lc 'curl -fsSL https://chatgpt.com/codex/install.sh | CODEX_NON_INTERACTIVE=1 sh'
limactl shell "{{ vm }}" bash -o pipefail -lc 'curl -fsSL https://claude.ai/install.sh | bash'
# stop the old running app-server and start it again using the newly installed binary.
limactl shell "{{ vm }}" bash -lc \
'pkill -x codex || true; exec codex app-server daemon bootstrap'
Expand Down
4 changes: 3 additions & 1 deletion provision/system.sh
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,8 @@ set -Eeuo pipefail

apt-get update

# Codex uses bubblewrap for its Linux sandbox. This is needed if you want to run codex withot full access.
# Codex and Claude Code use bubblewrap for their Linux sandboxes.
# Claude Code also uses socat to proxy sandbox network traffic.
apt-get install -y \
build-essential \
bubblewrap \
Expand All @@ -20,6 +21,7 @@ apt-get install -y \
python3-venv \
ripgrep \
rsync \
socat \
unzip \
zip

Expand Down
5 changes: 4 additions & 1 deletion provision/user.sh
Original file line number Diff line number Diff line change
Expand Up @@ -35,5 +35,8 @@ brew install fastly/tap/fastly
# Install or update codex
curl -fsSL https://chatgpt.com/codex/install.sh | sh

# The Codex installer adds ~/.local/bin to .bashrc
# Install or update Claude Code
curl -fsSL https://claude.ai/install.sh | bash

# Make Codex and Claude CLIs available.
append_line_if_missing "export PATH=\"\$HOME/.local/bin:\$PATH\"" "$HOME/.profile"