Claude Code normally pauses for approval on every file write, shell command and web fetch. For an
unattended overnight build it must run with all approvals pre-granted — and the safe way to do that is
inside a dev container: an isolated Docker environment with a default-deny firewall, where Claude runs
as a non-root user and --dangerously-skip-permissions is explicitly supported for unattended
operation. Worst case is confined to the container and the one mounted project folder.
.dockerignore, build/run commands and a reusable smoke-test
script, but NOT to run docker build — there is no Docker daemon inside the dev container, and
that is by design (see §4). Verification overnight happens against the natively running release binary.~/dev/hilo-fm, and git init it..devcontainer/ directory from the
anthropics/claude-code GitHub repository into the project folder. Three files:
devcontainer.json (settings, mounts), Dockerfile (image and tools),
init-firewall.sh (default-deny network policy). Official guide:
code.claude.com/docs/en/devcontainer.RUN curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs \
| sh -s -- -y --default-toolchain stable
ENV PATH="/home/node/.cargo/bin:${PATH}"
(Adjust the home dir to the image's non-root user.)init-firewall.sh — the Anthropic/API domains, GitHub
and the npm registry are already covered; add what this build needs:
says.hermione.online # spec + implementation prompt
crates.io # Rust package registry (API)
static.crates.io # crate downloads
index.crates.io # sparse registry indexclaude once to sign in if needed.claude --dangerously-skip-permissions
The usual root/sudo refusal is skipped automatically inside a recognised sandbox — the reference container
runs Claude as a non-root user, which is exactly why this is the supported way to run unattended. Accept the
one-time responsibility dialog before walking away.Fetch https://says.hermione.online/hilo-fm-spec/implementation-prompt.md
and execute it fully and autonomously. Do not stop to ask questions; make
reasonable decisions and record them in DECISIONS.md as the prompt requires.
Work until the acceptance checklist passes.Your overnight agent runs inside a Docker container (the dev container). The implementation prompt
asks, as its final deliverable, for HiLo.FM packaged as a Docker image — which requires running
docker build. But a container is a guest, not a host: it has the Docker client at most,
and no Docker engine of its own. So "Docker from inside Docker" only works via one of two workarounds:
Neither is worth it for one build command. Hence the chosen plan: Claude writes the Dockerfile and
build instructions overnight and verifies everything against the native binary; you run the one
docker build on the host in the morning, where Docker naturally lives. The prompt has been
updated accordingly, and explicitly tells Claude not to attempt or work around the missing daemon.
git log --oneline — what happened, in order.DECISIONS.md — every choice Claude made overnight, with rationale (the deferred image
build should be noted there too).cargo test — MINI fixtures (E5-A / E5-B / E6-A) and invariants must be green.docker build -t hilo-fm .
docker run -p 8080:8080 -v hilo-data:/data hilo-fmscripts/smoke.sh (login → E6-A entry
→ 13 rows → batch → report).