Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 10 additions & 0 deletions ct/t3code.sh
Original file line number Diff line number Diff line change
Expand Up @@ -43,6 +43,16 @@ function update_script() {
$STD npm install -g t3@latest
msg_ok "Updated T3 Code"

msg_info "Configuring T3 Code Service"
mkdir -p /etc/systemd/system/t3code.service.d
cat <<EOF >/etc/systemd/system/t3code.service.d/claude.conf
[Service]
# Allow Claude Full access mode as root inside the LXC.
Environment=IS_SANDBOX=1
EOF
systemctl daemon-reload
msg_ok "Configured T3 Code Service"

msg_info "Starting Service"
systemctl start t3code
msg_ok "Started Service"
Expand Down
2 changes: 2 additions & 0 deletions install/t3code-install.sh
Original file line number Diff line number Diff line change
Expand Up @@ -46,6 +46,8 @@ Type=simple
User=root
Environment=PATH=/usr/local/bin:/usr/bin:/bin
Environment=T3CODE_TELEMETRY_ENABLED=false
# Allow Claude Full access mode as root inside the LXC.
Environment=IS_SANDBOX=1
WorkingDirectory=/opt/t3code
ExecStart=/usr/bin/t3 serve --host 0.0.0.0 --base-dir /opt/t3code
Restart=on-failure
Expand Down
4 changes: 4 additions & 0 deletions json/t3code.json
Original file line number Diff line number Diff line change
Expand Up @@ -41,6 +41,10 @@
"text": "Provider CLIs (Codex, Claude, Grok, OpenCode, GitHub) are included in the install. Login to the CT after creation to authenticate with these services.",
"type": "info"
},
{
"text": "T3 Code and its agents run as root inside the LXC. The service sets IS_SANDBOX=1 so Claude can use Full access mode without a manual environment override. This does not enable additional sandboxing: agents can modify all container data and any writable host bind mounts. Use an unprivileged container and avoid exposing sensitive host paths.",
"type": "warning"
},
{
"text": "Access T3 Code at http://<IP>:3773 and pair a device with the token/QR shown after install. Regenerate it with: `pct exec <CTID> -- t3 pair --base-dir /opt/t3code.`",
"type": "info"
Expand Down
Loading