clank is an AI sandbox, pre-configured to quickly start using AI.
Clank is built using the Nix package manager.
sudo apt install -y nix uidmap
echo 'experimental-features = nix-command flakes' | sudo tee -a /etc/nix/nix.conf
sudo usermod -aG nix-users $USERAt this point you need to log out and in again to effectuate the change to your user's groups.
Through the power of Nix, you can run Clank without installing anything else.
nix run github:magenta-aps/clankThis mounts the current directory into a sandbox, which the AI will have full
access to, so maybe don't do it in a directory with sensitive data. Get the
vibes going by running opencode or
claude. See below for more.
Giving AI access to secrets is certainly one of the ideas ever. Fortunately, we can keep secrets out of the sandbox container by configuring the harness to use dummy credentials and a credentials-injecting proxy.
Sandbox
βββββββββββββββββββββββββββββββββββ
β β
β βββββββββββββββ β βββββββββββββ ββββββββββββββββ
β β Open Code β apiKey: dummy β β Caddy β apiKey: aHVudGVyMg== β Mistral AI β
β β (harness) βββββββββββββββββββΌββββΊβ (proxy) ββββββββββββββββββββββββββββΊβ (provider) β
β βββββββββββββββ β βββββββββββββ ββββββββββββββββ
β β
βββββββββββββββββββββββββββββββββββ
This requires configuring OpenCode or Claude Code to use the proxy. See the OpenCode documentation for a list of supported providers. Base URLs can be found at https://models.dev/api.json. Some providers use a custom SDK, in which case they are documented at https://ai-sdk.dev/providers/ai-sdk-providers.
See magenta/ for an example setup.
CLANK_PODMAN_OPTS='--publish=127.0.0.1:4096:4096' clank opencode web --hostname=0.0.0.0 --port=4096nix run nixpkgs#podman -- rm --force --filter 'name=^clank'
nix run nixpkgs#podman -- volume rm clank-persistgit clone https://github.com/magenta-aps/clank.git
cd clank/
nix run .