Skip to main content

AI-Container

Podman based container for isolating AI tooling for a individual project.

Context

In the past, I have repeatedly observed and experienced coding agents accessing or using files and content which they either weren't supposed to, or even technically "did not have access to."

On one occasion, for example, file access was explicitly restricted (e.g., the path was blocked). However, the agent exploited its ability to run bash commands, using them to traverse and scan the restricted paths instead of relying on standard read/write methods.

For this reason, I believe it is essential to implement clear restrictions or a contextual sandbox that is shared with the AI, and which it cannot as easily circumvent by simply invoking a different command.

Prerequisites

  • Podman (>= 5.0) - Container runtime. Install
  • Python (>= 3.13) - Required for the CLI. Install
  • uv - Used to install and run the CLI. Install

Image builds and volume creation are performed through the Podman Python SDK, which talks to the Podman service socket. Make sure the socket is running:

systemctl --user enable --now podman.socket

Installation

Install the ai-container package:

uv tool install ai-container

Or from source:

git clone https://github.com/yourusername/ai-container.git
cd ai-container
uv tool install .

The ai command will then be available.

Usage

Basic Commands

ai agent pi /path/to/project        # Run PI coding agent
ai agent opc /path/to/project       # Run OpenCode coding agent
ai agent claude /path/to/project    # Run Claude Code
ai agent aic /path/to/project       # Run aichat
ai agent llm /path/to/project       # Run llm
ai shell /path/to/project           # Interactive shell in container

ai agent <tool> <path> [args] is the single entry point for every tool. Valid tools: pi, opc, claude, aic, llm.

Pass additional arguments directly to the tool:

ai agent pi /path/to/project --verbose --model claude-3-sonnet

Rebuilding the Container Image

The container image is built automatically on first use via the Podman SDK. When you want to pull in the latest tool versions, force a rebuild with the image rebuild command:

ai image rebuild

Custom Environments

Need a specific toolchain (Rust, Go, an extra editor, ...)? Define a custom environment: a thin image built FROM aic:base that adds your tooling on top of everything the base image already provides.

Select an environment for any command with -e/--env:

ai -e rust shell .            # shell in the rust environment
ai -e rust agent pi .         # run pi in the rust environment
ai -e rust image rebuild      # (re)build the rust image (FROM aic:base)

Manage environment definitions with the env group:

ai env list                   # show environments and whether images are built
ai env new rust               # scaffold a Containerfile (FROM aic:base)
ai env new rust --edit        # scaffold and open it in $EDITOR
ai env edit rust              # edit the Containerfile
ai env path rust              # print the Containerfile path
ai env remove rust --purge    # delete the definition (and its image)

Definitions live under ~/.config/ai-container/environments/<name>/ (honoring XDG_CONFIG_HOME). The directory is also the build context, so you can COPY local files into your image. A scaffolded Containerfile looks like:

# rust environment -- extends the ai-container base image.
FROM aic:base

RUN curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs \
    | sh -s -- -y --default-toolchain stable
ENV PATH="/root/.cargo/bin:${PATH}"

WORKDIR /workspace

Without -e, the default base environment is used. Persistence volumes (config, state, share, pi-config, claude) are shared across all environments, so credentials and config are entered once and work everywhere.

Config Files

Defaults for the global flags (-e/--env, --log-level, --dryrun) can be set in a TOML config file, so you don't have to repeat them on every invocation. Files are merged from several sources, highest precedence first:

  1. ./.ai-container.toml — project-local, in the current working directory
  2. ~/.config/ai-container/config.toml — user config (honors XDG_CONFIG_HOME)
  3. ~/.ai-container.toml — home dotfile
  4. Built-in defaults

Command-line flags always override config files. Each layer only needs to set the keys it cares about; the rest fall through to the next layer.

# .ai-container.toml
env = "rust"        # default environment
log_level = "DEBUG" # one of: DEBUG, INFO, WARNING, ERROR, CRITICAL
dryrun = false

Provided Tools

  • PI - Coding agent for generation, analysis, and refactoring
  • OpenCode - AI-powered coding assistant
  • Claude Code - Anthropic's official coding agent
  • aichat - Interactive AI chat interface
  • llm - Command-line tool for LLM interaction

Configuration & Persistence

First run: The container image is built (one-time, takes a few minutes).

Tools use their standard configuration methods (within the container):

  • aichat: ~/.config/aichat/config.toml
  • llm: ~/.config/llm/ + environment variables
  • PI: ~/.pi/
  • OpenCode: ~/.config/opencode/
  • Claude Code: ~/.claude/

Configuration persists automatically across all runs and containers through named Podman volumes (config, state, share, pi-config, claude). Configure once, use everywhere:

# First run: setup credentials
ai shell /path/to/project
# Inside container: aichat, llm keys set openai <key>, etc.

# Subsequent runs: credentials available automatically
ai agent pi /path/to/project

Other/Previous Work

Metadata

Release files for ai-container 0.16.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for ai-container 0.16.0
File Size Uploaded
ai_container-0.16.0.tar.gz 28.9 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for ai-container 0.16.0
File Interpreter ABI Platform
ai_container-0.16.0-py3-none-any.whl Python 3 none any Details

Total release size: 46.8 kB

Release files / ai_container-0.16.0.tar.gz

Download URL ai_container-0.16.0.tar.gz
Size 28.9 kB
Tags Source
SHA-256 checksum
How to use checksums
5c27738eeaf2286fb89438c72a08d9798ccd175528dada106613e55478abc35f
BLAKE2b-256 checksum
How to use checksums
820b57acd4e6a972237e324b9ba8b84ee0ec956fb8b4a0ea77d85f8ab1c73687
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.12.9 {"installer":{"name":"uv","version":"0.12.9","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"macOS","version":null,"id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}

Release files / ai_container-0.16.0-py3-none-any.whl

Download URL ai_container-0.16.0-py3-none-any.whl
Size 17.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
8a973091fd9dc13d4c4f9f6757ba01d7e47ae86e629728b330cb08825aa09708
BLAKE2b-256 checksum
How to use checksums
f6408c224a123f5090c853878a8a6649a5036d8f00ceddf4ac9f0db867d9a94e
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.12.9 {"installer":{"name":"uv","version":"0.12.9","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"macOS","version":null,"id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}

Release history Release notifications | RSS feed

This release

0.16.0 This release

2 release files

0.15.0

2 release files

0.14.0

2 release files

0.11.0

2 release files

0.10.0

2 release files

0.9.0

2 release files

0.8.1

2 release files

0.8.0

2 release files

0.7.0

2 release files

0.6.0

2 release files

0.5.0

2 release files

0.4.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page