This container setup runs Codex CLI with a read-only root filesystem and a mandatory writable work directory at /work. LAN access is blocked at the host with nftables while public internet remains open. USB access is blocked at the container level by disallowing device passthrough and privileged mode.
The container has the necessary tools for basic C and C++ coding, as well as 32-bit wine, winetricks, dotnet40, and reverse engineering tools. 64-bit wine is also available but unconfigured.
docker build -t codex-sandbox:latest ~/codex-sandboxThe guard installs drop rules into Docker's DOCKER-USER chain for both ip and ip6, and uses a dedicated codex_sandbox table to store the discovered Docker bridge interface set.
sudo ~/codex-sandbox/host-network-guard.sh applyCheck status:
sudo ~/codex-sandbox/host-network-guard.sh statusRemove:
sudo ~/codex-sandbox/host-network-guard.sh removeCreate an OpenAI API key and save it to ~/.codex-key on the host. run.sh reads this file and passes it into the container as OPENAI_API_KEY.
bash ~/codex-sandbox/run.sh /path/to/workdirInside container:
codex
You may have to point Codex to read AGENTS.md in case the file is not read automatically.
- Root filesystem is read-only; only
/workis writable. /workis mounted from the host workdir you pass torun.sh.- No container device passthrough and no privileged mode.
- All Linux capabilities dropped and no-new-privileges enforced.
- LAN access blocked for Docker bridge networks using nftables; public internet remains open.
- The container runs as user
ubuntu, withHOMEandCODEX_HOMEforced to/workby the entrypoint.