Sandboxing Claude across three iterations: Docker, mitm, Kubernetes pod
This entire blog series was drafted by Claude inside a sandboxed pod; the sandbox got rebuilt three times — Docker, mitm plus credential proxy, then a K8s pod — to make that safe.
