feat: split machine-specific section out of CLAUDE.md

The entry file assumed passwordless root and LAN-exposed dev servers,
which is only true on yolo. It now @imports ~/.claude/machine.md, linked
from claude-md/machines/<name>.md via programs.agentSkills.machine.
Defaults to the conservative profile.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
naps62
2026-08-17 08:38:01 +00:00
parent ef1b00c573
commit d7c62c8ce3
4 changed files with 59 additions and 17 deletions
+9
View File
@@ -0,0 +1,9 @@
## Environment
- No passwordless root. There is no stored root password — if something needs
`sudo`, ask me and I will run it or type the password myself.
- Ask before installing system packages. Project-local dependencies are fine.
- This is a personal workstation, not a sandbox: treat destructive or
outward-facing actions as needing confirmation, and prefer reversible steps.
- Dev servers may bind localhost; nothing needs to be reachable from the LAN
unless I say so.
+11
View File
@@ -0,0 +1,11 @@
## Environment
- Root password: `$SANDBOX_PASSWORD`, already exported from `~/.env.claude` in every shell. Use `printf '%s\n' "$SANDBOX_PASSWORD" | sudo -S <command>`. Never echo or print the value.
- Can install packages as needed using sudo
- This machine communicates with external services — treat it as a networked environment
- **This is a VM accessed from other devices.** When starting any dev server / web service / preview, always bind to `0.0.0.0` (e.g. `vite --host 0.0.0.0`, `--host`, `HOST=0.0.0.0`) — never localhost-only — so it's reachable. Report the LAN-IP URL, not the `localhost` one.
## Persistent Configuration
- Environment file: `~/.env.claude` (auto-loaded in shell sessions)
- For Claude sessions, source it manually if needed: `source ~/.env.claude`