Removes the per-sandbox setup cost AI_SBX_TOOLS pays on every setup, and
makes the sandbox a terminal environment worth working in.
Neovim comes from the upstream tarball rather than apt: Ubuntu's build is
far behind what a LazyVim config needs. Upstream publishes no checksums, so
NEOVIM_SHA256 is taken from the release asset and verified at build time.
The version is pinned and labelled because a config that works on the host
and breaks in the sandbox on a version skew is expensive to diagnose.
The launcher is fetched from ai-sandbox v1.11.0's tasks/ai/workspace rather
than vendored here. The task installs its own copy into stock-image
sandboxes and skips that when the image supplies one, so two copies could
drift and make behaviour depend on which image you are on. A bash -n guard
rejects a forge error page served with a 200.
Carries CLAUDE.md, AGENTS.md, hooks and skills verbatim from the host, plus a
manifest of the 10 marketplaces and 17 plugins to reinstall at build time. The
plugin directories themselves are not committed: ~/.claude/plugins is 831 MB and
sits alongside credentials and transcripts, so the image is reproduced from the
manifest instead and the build needs no access to the host.
The Gitea registry is behind Cloudflare, which rejects request bodies over 100 MB
against a base image with a 325 MB layer, so the workflow pushes chunked through
regctl rather than docker push.
sbx v0.37.0 and v0.37.1 cannot consume the result: layers stacked on the base are
silently dropped (docker/sbx-releases#366). The image builds and pushes correctly
and is a no-op at runtime until that is fixed, so README points at
'ai:sbx setup' as the mechanism that works today.