Skip to main content

Container wrapper for running AI coding agents in isolated, secure containers

Project description

Paude

Run AI coding agents in secure containers. They make commits, you pull them back.

Supported Agents

Agent Flag Status
Claude Code --agent claude (default) Supported
Codex CLI --agent codex Supported
Cursor CLI --agent cursor Supported
Gas City --agent gascity Supported
Gemini CLI --agent gemini Supported
OpenClaw --agent openclaw Supported

Agents are installed automatically inside the container — no local agent installation needed. You just need authentication credentials for your chosen provider.

Why Paude?

  • Isolated execution: Your agent runs in a container, not on your host machine
  • Safe autonomous mode: Enable --yolo without fear — the agent can't send your code anywhere
  • Git-based workflow: The agent commits inside the container, you git pull the changes
  • Run anywhere: Locally with Podman or Docker, remotely via SSH, or on OpenShift

Demo

asciicast

The demo shows Claude Code, but the workflow is identical with other agents.

Quick Start

Prerequisites

Container runtime: Podman or Docker for local use, or an OpenShift cluster for remote execution.

Authentication — set up credentials for your chosen provider:

Google Cloud / Vertex AI (Claude Code, Gemini CLI, OpenClaw)

Install the Google Cloud SDK, then:

gcloud auth application-default login

Set your project (find the ID in Google Cloud Console):

# Claude Code via Vertex
export CLAUDE_CODE_USE_VERTEX=1
export ANTHROPIC_VERTEX_PROJECT_ID=your-project-id
export GOOGLE_CLOUD_PROJECT=your-project-id

# Gemini CLI / OpenClaw via Vertex
export GOOGLE_CLOUD_PROJECT=your-project-id
Anthropic API key (Claude Code, OpenClaw)
export ANTHROPIC_API_KEY=your-api-key

For OpenClaw, also pass --provider anthropic:

paude create --agent openclaw --provider anthropic ...
OpenAI API key (Codex CLI, OpenClaw)
export OPENAI_API_KEY=your-api-key
paude create --agent openclaw --provider openai ...
ChatGPT plan login (Codex CLI)
paude create --agent codex --yolo --git my-project
paude connect my-project

chatgpt is the default provider for the Codex agent and is only supported on the local Podman/Docker backend (not --backend openshift, which needs --provider openai instead — see below).

Inside the session, run codex login. Codex prints a URL and code — complete the login in any browser, on any device (no localhost callback or port forwarding is needed). The session's own proxy sidecar captures the resulting OAuth tokens and manages refresh transparently and independently; real tokens never reach the agent container. Each session has its own OAuth lineage tied to its own private state volume, so multiple ChatGPT-plan sessions can run concurrently without one session's token refresh invalidating another's.

Pass --provider openai to use the plain OPENAI_API_KEY provider instead — no ChatGPT plan, no proxy-managed auth (this is the only provider Codex supports on --backend openshift). The default Codex network policy allows chatgpt.com and auth.openai.com for the ChatGPT API and OAuth exchange. Paude selects Codex's HTTP/SSE transport by default because the local MITM proxy does not support the Responses WebSocket transport. Codex Apps are disabled for ChatGPT OAuth sessions so the Apps MCP integration does not attempt to connect from the container; standalone MCP server configuration is unchanged.

Breaking change from previous versions: paude no longer reads ~/.codex/auth.json from the host. Sessions created under the old host-seeded model must be recreated (paude delete + paude create --agent codex) and re-authenticated with codex login inside the container.

Cursor
agent login  # or set CURSOR_API_KEY=your-api-key

macOS note: On Mac hosts, CURSOR_API_KEY is the simplest authentication method. Without it, each paude session requires a separate browser-based OAuth login via agent login inside the container.

Install

uv tool install paude

First run: Paude pulls container images on first use. This takes a few minutes; subsequent runs start immediately.

Your First Session

# OpenClaw — browser-based, no local agent install needed
paude create --agent openclaw --allowed-domains "default openclaw" my-project

# Claude Code (default)
cd your-project
paude create --yolo --git my-project

# Codex CLI
paude create --agent codex --yolo --git my-project

# Cursor CLI
paude create --agent cursor --yolo --git my-project

# Gemini CLI
paude create --agent gemini --yolo --git my-project

# Connect to a CLI agent's running session
paude connect my-project

# Pull the agent's commits (use your branch name):
git pull paude-my-project main

You'll know it's working when: For CLI agents, paude connect shows the agent interface and git pull brings back commits. For OpenClaw, paude connect prints a URL — open it in your browser.

OpenTelemetry Export

Export agent telemetry (metrics, logs, traces) to any OTLP-compatible collector:

paude create --otel-endpoint http://collector:4318 my-project

The endpoint hostname is automatically added to the proxy allowlist and non-standard ports (like 4318) are opened in the proxy. Supported agents: Claude Code, Gemini CLI, OpenClaw. Set otel-endpoint in ~/.config/paude/defaults.json to apply globally.

Passing a Task

paude create --yolo my-project -a '-p "refactor the auth module"'

Or just start the session and type your request in the agent interface.

Something Not Working?

  • Run paude --help for all options and examples
  • Run paude list to check session status
  • Use paude create --dry-run to verify configuration
  • Use paude start -v for verbose output (shows sync progress)
  • Check credentials: gcloud auth application-default print-access-token (Vertex/Gemini) or verify your API key is exported

Learn more:

How It Works

Your Machine                    Container
    |                              |
    |-- git push ----------------▶ |  Agent works here
    |                              |  (network-filtered)
    ◀-- git pull -----------------|
    |                              |
  • Git is the sync mechanism — your local files stay untouched until you pull
  • --yolo is safe because network filtering blocks the agent from sending data to arbitrary URLs
  • The agent can only reach its API (e.g., Vertex AI) and package registries (e.g., PyPI) by default

Install from Source

git clone https://github.com/bbrowning/paude
cd paude
uv venv --python 3.12 --seed
source .venv/bin/activate
pip install -e .

Requirements

  • Python 3.11+ (for the Python package)
  • Podman or Docker (for local backend)
  • OpenShift CLI oc (for OpenShift backend)
  • Auth credentials for your provider (Google Cloud SDK, API key, etc.)

Development

See CONTRIBUTING.md for development setup, testing, and release instructions.

License

MIT

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

paude-0.20.0a5.tar.gz (353.0 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

paude-0.20.0a5-py3-none-any.whl (210.2 kB view details)

Uploaded Python 3

File details

Details for the file paude-0.20.0a5.tar.gz.

File metadata

  • Download URL: paude-0.20.0a5.tar.gz
  • Upload date:
  • Size: 353.0 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.14

File hashes

Hashes for paude-0.20.0a5.tar.gz
Algorithm Hash digest
SHA256 768c7cd41854fa93b0ca43cbc606e225bdcbfabae92c35ab93a5e694d362d2e5
MD5 fb3bfe815cb14eaeb6e1914336425ae8
BLAKE2b-256 5caf75f6b093f31a0f1388ab0e3d8b129654169e6ff997f90657de8f44c7b43a

See more details on using hashes here.

Provenance

The following attestation bundles were made for paude-0.20.0a5.tar.gz:

Publisher: release.yml on bbrowning/paude

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file paude-0.20.0a5-py3-none-any.whl.

File metadata

  • Download URL: paude-0.20.0a5-py3-none-any.whl
  • Upload date:
  • Size: 210.2 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.14

File hashes

Hashes for paude-0.20.0a5-py3-none-any.whl
Algorithm Hash digest
SHA256 b2b936b142dbf0aad6df0c434f2c334bcb143189cdc75314b843c8eadf77bb50
MD5 8da9cd86159688a563b4f91338a4ed0f
BLAKE2b-256 5b5e7d6e515b40a34e3051066ed53c1e9da254dea31c42bc58558817df302b87

See more details on using hashes here.

Provenance

The following attestation bundles were made for paude-0.20.0a5-py3-none-any.whl:

Publisher: release.yml on bbrowning/paude

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page