HILO.FM · RUN INSTRUCTIONS · v2SPEC →

Running the Overnight Build
Chosen path: Anthropic dev container — full autonomy, contained blast radius

2026-08-04Companion to implementation-prompt.mdDocker image build deferred to the morning

Claude Code normally pauses for approval on every file write, shell command and web fetch. For an unattended overnight build it must run with all approvals pre-granted — and the safe way to do that is inside a dev container: an isolated Docker environment with a default-deny firewall, where Claude runs as a non-root user and --dangerously-skip-permissions is explicitly supported for unattended operation. Worst case is confined to the container and the one mounted project folder.

Deliberately out of scope tonight
The HiLo.FM Docker image build is deferred to the morning: the implementation prompt now instructs Claude to author the Dockerfile, .dockerignore, build/run commands and a reusable smoke-test script, but NOT to run docker build — there is no Docker daemon inside the dev container, and that is by design (see §4). Verification overnight happens against the natively running release binary.

1Prerequisites

2Set up the dev container

  1. Create the project folder on the host, e.g. ~/dev/hilo-fm, and git init it.
  2. Copy Anthropic's reference config: take the .devcontainer/ directory from the anthropics/claude-code GitHub repository into the project folder. Three files: devcontainer.json (settings, mounts), Dockerfile (image and tools), init-firewall.sh (default-deny network policy). Official guide: code.claude.com/docs/en/devcontainer.
  3. Add the Rust toolchain to the dev container's Dockerfile (the reference image already has Node), e.g.:
    RUN curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs \
        | sh -s -- -y --default-toolchain stable
    ENV PATH="/home/node/.cargo/bin:${PATH}"
    (Adjust the home dir to the image's non-root user.)
  4. Extend the firewall allowlist in init-firewall.sh — the Anthropic/API domains, GitHub and the npm registry are already covered; add what this build needs:
    says.hermione.online     # spec + implementation prompt
    crates.io                # Rust package registry (API)
    static.crates.io         # crate downloads
    index.crates.io          # sparse registry index
  5. Open in the container: VS Code → "Reopen in Container". First build takes a few minutes; the firewall script verifies itself at startup.

3Launch the overnight run

  1. Open a terminal inside the container (Ctrl+`), run claude once to sign in if needed.
  2. Start in full-autonomy mode:
    claude --dangerously-skip-permissions
    The usual root/sudo refusal is skipped automatically inside a recognised sandbox — the reference container runs Claude as a non-root user, which is exactly why this is the supported way to run unattended. Accept the one-time responsibility dialog before walking away.
  3. Paste the kickoff prompt:
    Fetch https://says.hermione.online/hilo-fm-spec/implementation-prompt.md
    and execute it fully and autonomously. Do not stop to ask questions; make
    reasonable decisions and record them in DECISIONS.md as the prompt requires.
    Work until the acceptance checklist passes.
  4. Leave it. Keep the machine awake (disable sleep / close-lid suspend).
Honest caveat
A dev container limits what Claude can touch, but it does not prevent code running inside it from reaching anything mounted or credentialed inside it (including Claude Code credentials). Isolation ≠ immunity — it's blast-radius management. Anthropic recommends this setup only with trusted repositories; a fresh, empty project directory qualifies.

4"Docker-in-Docker" — what that was about, in plain terms

Your overnight agent runs inside a Docker container (the dev container). The implementation prompt asks, as its final deliverable, for HiLo.FM packaged as a Docker image — which requires running docker build. But a container is a guest, not a host: it has the Docker client at most, and no Docker engine of its own. So "Docker from inside Docker" only works via one of two workarounds:

Neither is worth it for one build command. Hence the chosen plan: Claude writes the Dockerfile and build instructions overnight and verifies everything against the native binary; you run the one docker build on the host in the morning, where Docker naturally lives. The prompt has been updated accordingly, and explicitly tells Claude not to attempt or work around the missing daemon.

5Morning checklist

  1. git log --oneline — what happened, in order.
  2. Read DECISIONS.md — every choice Claude made overnight, with rationale (the deferred image build should be noted there too).
  3. cargo test — MINI fixtures (E5-A / E5-B / E6-A) and invariants must be green.
  4. Build the image on the host (outside the dev container), using the commands from the README — typically:
    docker build -t hilo-fm .
    docker run -p 8080:8080 -v hilo-data:/data hilo-fm
  5. Re-run the packaged smoke test against the container: scripts/smoke.sh (login → E6-A entry → 13 rows → batch → report).
  6. Walk the demo script of spec §10.4; open the in-app Documentation section; check the batch-console timings against spec §6.5.

6References