- Nix 75.5%
- Python 24.5%
| Filename | Latest commit message | Latest commit date |
|---|---|---|
Flake lock file updates:
• Updated input 'home-manager':
'github:nix-community/home-manager/cfba7ad5886b342b8dd63ba74354b3853ea4cfc9?narHash=sha256-zIdM%2B8teujHm5hc5MIPDnV7k2UeOOT/pFyFtWjOCwsY%3D' (2026-08-23)
→ 'github:nix-community/home-manager/7b4c5ec4bedaf1e062bbc1bcaeddbc6bd242aa1b?narHash=sha256-iQ0ebhiVo64NktTnwft9hNxlFu4j5cvljVxyJaEVIP4%3D' (2026-09-25)
• Updated input 'nixpkgs':
'https://releases.nixos.org/nixos/unstable/nixos-26.11pre1059570.2c423e03bbaf/nixexprs.tar.xz?narHash=sha256-95aJfHyQTLWslCXFVNB0odgmVkpdmDezQwTg9mhqV1E%3D' (2026-08-22)
→ 'https://releases.nixos.org/nixos/unstable/nixos-26.11pre1080855.7a0f122f5090/nixexprs.tar.xz?narHash=sha256-EvoKOTtoIJ7Xflls2Nfo5WDcqjFJB0kuzwOz0nLWs0w%3D' (2026-09-28)
|
||
| clank | ||
| container | ||
| magenta | ||
| .gitignore | ||
| flake.lock | ||
| flake.nix | ||
| LICENSE | ||
| pyproject.toml | ||
| README.md | ||
Clank 🤖
clank is an AI sandbox, pre-configured to quickly start using AI.
⚡ Quick Start
Get Nix
Clank is built using the Nix package manager.
sudo apt install -y nix uidmap
echo 'experimental-features = nix-command flakes' | sudo tee -a /etc/nix/nix.conf
sudo usermod -aG nix-users $USER
At this point you need to log out and in again to effectuate the change to your user's groups.
Try Clank
Through the power of Nix, you can run Clank without installing anything else.
nix run github:magenta-aps/clank
This mounts the current directory into a sandbox, which the AI will have full
access to, so maybe don't do it in a directory with sensitive data. Get the
vibes going by running opencode or
claude. See below for more.
⚙️ Customisation and Security
Giving AI access to secrets is certainly one of the ideas ever. Fortunately, we can keep secrets out of the sandbox container by configuring the harness to use dummy credentials and a credentials-injecting proxy.
Sandbox
┌─────────────────────────────────┐
│ │
│ ┌─────────────┐ │ ┌───────────┐ ┌──────────────┐
│ │ Open Code │ apiKey: dummy │ │ Caddy │ apiKey: aHVudGVyMg== │ Mistral AI │
│ │ (harness) ├─────────────────┼───►│ (proxy) ├──────────────────────────►│ (provider) │
│ └─────────────┘ │ └───────────┘ └──────────────┘
│ │
└─────────────────────────────────┘
This requires configuring OpenCode or Claude Code to use the proxy. See the OpenCode documentation for a list of supported providers. Base URLs can be found at https://models.dev/api.json. Some providers use a custom SDK, in which case they are documented at https://ai-sdk.dev/providers/ai-sdk-providers.
See magenta/ for an example setup.
💡 Tips and Tricks
OpenCode Web
CLANK_PODMAN_OPTS='--publish=127.0.0.1:4096:4096' clank opencode web --hostname=0.0.0.0 --port=4096
Remove All State
nix run nixpkgs#podman -- rm --force --filter 'name=^clank'
nix run nixpkgs#podman -- volume rm clank-persist
🧑🔧 Development
git clone https://github.com/magenta-aps/clank.git
cd clank/
nix run .