claude-box — Tailscale, Buzz and Claude Code

claude-box — Tailscale, Buzz and Claude Code An architecture diagram generated by Archify. Owner devices · Browser · VS Code · Zed · Architecture component Owner devices Browser · VS Code · Zed Buzz relay · Nostr over WSS · Architecture component Buzz relay Nostr over WSS tailscale sidecar · containerboot · userspace · Shared network namespace — no ports: block on the host · owns the namespace tailscale sidecar containerboot · userspace owns the namespace ttyd + tmux · binds 127.0.0.1:7681 · Shared network namespace — no ports: block on the host › claude container — everything runs as dev (uid 1000) ttyd + tmux binds 127.0.0.1:7681 sshd · binds 127.0.0.1:22 · Shared network namespace — no ports: block on the host › claude container — everything runs as dev (uid 1000) sshd binds 127.0.0.1:22 buzz-acp · spawns claude-agent-acp · Shared network namespace — no ports: block on the host › claude container — everything runs as dev (uid 1000) buzz-acp spawns claude-agent-acp Claude Code · works in /workspace · Shared network namespace — no ports: block on the host › claude container — everything runs as dev (uid 1000) Claude Code works in /workspace Named volumes · login · identity · workspace · Shared network namespace — no ports: block on the host › claude container — everything runs as dev (uid 1000) Named volumes login · identity · workspace GitHub · token from the environment · Architecture component GitHub token from the environment Anthropic API · Pro/Max OAuth, no API key · Architecture component Anthropic API Pro/Max OAuth, no API key HTTPS · SSH serve proxy TCP forward outbound WSS, nothing listens ACP over stdio interactive session shared login + config clone · push OAuth login Shared network namespace — no ports: block on the host claude container — everything runs as dev (uid 1000) Legend Frontend Backend Database Cloud Message bus External

Access

  • • tailscale serve terminates TLS on the node's own certificate
  • • SSH is a TCP forward to 127.0.0.1:22, never a host port
  • • No password — tailnet membership plus the ACL is the gate

Agent loop

  • • buzz-acp dials out, so the agent needs no inbound port
  • • owner-only means one pubkey can trigger a turn
  • • A further agent is one file in agents/ plus one key in BUZZ_AGENTS

Isolation

  • • No ports: block and no docker.sock anywhere in the stack
  • • claude has no network stack of its own — it joins the sidecar's
  • • Egress still leaves through that namespace; only inbound is constrained