Disposable Proxmox VMs as a sandbox for Claude Code, Codex and Gemini

The short answer

The strongest sandbox for an AI coding agent is a whole virtual machine it cannot escape, on a network it cannot leave. I run these on a Proxmox host: Claude asks an MCP connector for a sandbox, the connector clones a golden image with Claude Code, Codex and Gemini preinstalled onto a walled network that reaches only allowed domains through a proxy, and a timer destroys every sandbox when its lifetime ends.

Why not just use the built-in sandbox?

Container and process sandboxes are good defaults, and Claude Code's own sandbox is a sensible first layer. For untrusted repositories, though, the guidance from Anthropic and from security writers is the same: use a dedicated VM. Filesystem isolation without network isolation lets a compromised agent send your files out; network isolation without filesystem isolation lets it reach things it should not. A VM on a walled network gives you both, and it gives you a reset button.

What does the setup look like?

  • A golden image. One Ubuntu 24.04 VM with Node, Claude Code, Codex and Gemini installed and the proxy configured. Never started, only cloned.
  • Linked clones. Each sandbox is a linked clone in its own Proxmox pool, so creating one takes seconds of disk work. In testing, a sandbox was ready, including its first boot configuration, in about 18 seconds.
  • A walled network. Sandboxes sit on a separate bridge whose only way out is a proxy with an allow-list of domains. The host's firewall stops them reaching each other, the owner's machines or the management network. The walls passed a 36-point test.
  • A guard. A hook refuses to start a machine that breaks the limits: at most 4 cores and 8 GB for one sandbox, and 20 GB for all of them together, so a fifth medium sandbox is refused with the reason.

How does Claude create one?

Through an MCP connector with seven tools: create_server, list_servers, run_command, read_file, write_file, extend_server and destroy_server. Creating takes a name, a size (small is 2 cores and 4 GB, medium is 4 cores and 8 GB) and a lifetime between 1 and 24 hours, four by default.

The connector never reaches a sandbox over the network. It talks to the Proxmox API with a token that can only touch the sandbox pool, and runs commands through the QEMU guest agent, a virtual serial channel. A compromised sandbox therefore has no network path back to the connector, and the connector's token cannot touch any other machine on the host.

How do sandboxes die?

Every sandbox carries its owner, creation time and end of life in its own Proxmox description, so there is one source of truth and nothing to drift. A timer runs every five minutes and destroys whatever is past its end of life. Forgotten machines cannot hold memory for days, and “start from clean” is one call.

What about API keys?

Model keys never pass through the chat. They live in one file on the connector's machine and are copied into each new sandbox's environment at creation, readable only by root inside it. When the sandbox is destroyed, the copy goes with it.

When is this overkill?

For a trusted repository on your own laptop, the built-in sandbox is enough. A VM pays off when agents run unattended, when the code is not yours, when several customers' agents share one host, or when you want Claude in a chat on your phone to spin up a clean machine, try something, and throw it away.

Questions people ask

What is the safest sandbox for Claude Code?

A dedicated virtual machine on a network that can only reach allowed domains, created fresh for the task and destroyed afterwards. It isolates both the filesystem and the network.

Can Claude create its own sandbox VMs?

Yes, through an MCP connector that calls the Proxmox API with a token limited to a sandbox pool. Claude asks for a size and lifetime, and the connector clones a golden image.

How do you stop AI agents reaching the internet freely?

Put their machines on a separate bridge whose only route out is a proxy with an allow-list of domains, and block traffic between that bridge and every other network on the host.

How fast can a sandbox VM be created?

With linked clones of a prepared golden image, in my setup about 18 seconds including first boot configuration.

About the author. Muhammad Tayyab Ilyas is an Applied AI & Solutions Engineer in Barcelona who builds and operates MCP servers, multi-agent systems and the infrastructure under them. He runs this sandbox host alongside his MCP connectors.