diff --git a/ct/t3code.sh b/ct/t3code.sh index 13e27f4c4a..8516335084 100644 --- a/ct/t3code.sh +++ b/ct/t3code.sh @@ -43,6 +43,16 @@ function update_script() { $STD npm install -g t3@latest msg_ok "Updated T3 Code" + msg_info "Configuring T3 Code Service" + mkdir -p /etc/systemd/system/t3code.service.d + cat </etc/systemd/system/t3code.service.d/claude.conf +[Service] +# Allow Claude Full access mode as root inside the LXC. +Environment=IS_SANDBOX=1 +EOF + systemctl daemon-reload + msg_ok "Configured T3 Code Service" + msg_info "Starting Service" systemctl start t3code msg_ok "Started Service" diff --git a/install/t3code-install.sh b/install/t3code-install.sh index 97359216ff..b37afc415a 100644 --- a/install/t3code-install.sh +++ b/install/t3code-install.sh @@ -46,6 +46,8 @@ Type=simple User=root Environment=PATH=/usr/local/bin:/usr/bin:/bin Environment=T3CODE_TELEMETRY_ENABLED=false +# Allow Claude Full access mode as root inside the LXC. +Environment=IS_SANDBOX=1 WorkingDirectory=/opt/t3code ExecStart=/usr/bin/t3 serve --host 0.0.0.0 --base-dir /opt/t3code Restart=on-failure diff --git a/json/t3code.json b/json/t3code.json index 27672d1f3d..9116fd1c8c 100644 --- a/json/t3code.json +++ b/json/t3code.json @@ -41,6 +41,10 @@ "text": "Provider CLIs (Codex, Claude, Grok, OpenCode, GitHub) are included in the install. Login to the CT after creation to authenticate with these services.", "type": "info" }, + { + "text": "T3 Code and its agents run as root inside the LXC. The service sets IS_SANDBOX=1 so Claude can use Full access mode without a manual environment override. This does not enable additional sandboxing: agents can modify all container data and any writable host bind mounts. Use an unprivileged container and avoid exposing sensitive host paths.", + "type": "warning" + }, { "text": "Access T3 Code at http://:3773 and pair a device with the token/QR shown after install. Regenerate it with: `pct exec -- t3 pair --base-dir /opt/t3code.`", "type": "info"