* fix search path for .claude.json to account for CLAUDE_CONFIG_DIR
When `CLAUDE_CONFIG_DIR` is set, as is done in `devcontainer.json`, `claude` looks
for `.claude.json` in that folder; otherwise, `~` is used.
Learned through observation, not claude documentation :old-man-yells-at-cloud:
* add more words to the lookup behavior description
* Apply suggestion from @DarkaMaul
---------
Co-authored-by: dm <darkamaul@hotmail.fr>
* feat: add non-interactive auth via CLAUDE_CODE_OAUTH_TOKEN
Bypass the interactive onboarding wizard when CLAUDE_CODE_OAUTH_TOKEN is
set. On container create, post_install.py runs `claude -p` to populate
auth state and sets hasCompletedOnboarding so the TUI starts without the
login wizard.
Workaround for https://github.com/anthropics/claude-code/issues/8938.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix: use remoteEnv instead of containerEnv for secrets
containerEnv bakes values into the image as ENV instructions, visible
in docker inspect/history. remoteEnv is set at runtime only.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix: improve error handling in onboarding bypass
- Handle timeout as expected (claude -p writes config before API call)
- Catch FileNotFoundError/OSError if claude is not installed
- Check returncode explicitly instead of dead CalledProcessError catch
- Guard on ~/.claude.json existence before writing onboarding flag
- Replace contextlib.suppress with explicit try/except that logs
- Update module docstring and README wording
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
When the host configures `gpg.ssh.program` to use 1Password's
`op-ssh-sign` binary, commit signing fails inside the container
because that macOS-specific binary doesn't exist.
DevContainers automatically forward SSH_AUTH_SOCK from the host,
so the SSH agent (including 1Password's) is already available.
By overriding `gpg.ssh.program` to `/usr/bin/ssh-keygen` in the
container's local gitconfig (which is included after the host
config), signing uses the standard ssh-keygen against the
forwarded agent instead of the missing 1Password binary.
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>