Switch from Docker to Apple Container for macOS-native container isolation. Use when the user wants Apple Container instead of Docker, or is setting up on macOS and prefers the native runtime. Triggers on "apple container", "convert to apple container", "switch to apple container", or "use apple container".
This skill switches NanoClaw's container runtime from Docker to Apple Container (macOS-only). It uses the skills engine for deterministic code changes, then walks through verification.
What this changes:
docker → container-v path:path:ro → --mount type=bind,source=...,target=...,readonlydocker info → container system status (with auto-start)docker ps --filter → container ls --format jsondocker → container.env shadowing via mount --bind inside the container (Apple Container only supports directory mounts, not file mounts like Docker's /dev/null overlay)mount --bind, then drop privileges via setprivWhat stays the same:
--user flag)Verify Apple Container is installed:
container --version && echo "Apple Container ready" || echo "Install Apple Container first"
If not installed:
.pkg filecontainer --versionApple Container requires macOS. It does not work on Linux.
Read .nanoclaw/state.yaml. If convert-to-apple-container is in applied_skills, skip to Phase 3 (Verify). The code changes are already in place.
grep "CONTAINER_RUNTIME_BIN" src/container-runtime.ts
If it already shows 'container', the runtime is already Apple Container. Skip to Phase 3.
Run the skills engine to apply this skill's code package. The package files are in this directory alongside this SKILL.md.
If .nanoclaw/ directory doesn't exist yet:
npx tsx scripts/apply-skill.ts --init
Or call initSkillsSystem() from skills-engine/migrate.ts.
npx tsx scripts/apply-skill.ts .claude/skills/convert-to-apple-container
This deterministically:
src/container-runtime.ts with the Apple Container implementationsrc/container-runtime.test.ts with Apple Container-specific testssrc/container-runner.ts with .env shadow mount fix and privilege droppingcontainer/Dockerfile with entrypoint that shadows .env via mount --bindcontainer/build.sh to default to container runtime.nanoclaw/state.yamlIf the apply reports merge conflicts, read the intent files:
modify/src/container-runtime.ts.intent.md — what changed and invariantsmodify/src/container-runner.ts.intent.md — .env shadow and privilege drop changesmodify/container/Dockerfile.intent.md — entrypoint changes for .env shadowingmodify/container/build.sh.intent.md — what changed for build scriptnpm test
npm run build
All tests must pass and build must be clean before proceeding.
container system status || container system start
./container/build.sh
echo '{}' | container run -i --entrypoint /bin/echo nanoclaw-agent:latest "Container OK"
mkdir -p /tmp/test-ro && echo "test" > /tmp/test-ro/file.txt
container run --rm --entrypoint /bin/bash \
--mount type=bind,source=/tmp/test-ro,target=/test,readonly \
nanoclaw-agent:latest \
-c "cat /test/file.txt && touch /test/new.txt 2>&1 || echo 'Write blocked (expected)'"
rm -rf /tmp/test-ro
Expected: Read succeeds, write fails with "Read-only file system".
mkdir -p /tmp/test-rw
container run --rm --entrypoint /bin/bash \
-v /tmp/test-rw:/test \
nanoclaw-agent:latest \
-c "echo 'test write' > /test/new.txt && cat /test/new.txt"
cat /tmp/test-rw/new.txt && rm -rf /tmp/test-rw
Expected: Both operations succeed.
npm run build
launchctl kickstart -k gui/$(id -u)/com.nanoclaw
Send a message via WhatsApp and verify the agent responds.
Apple Container not found:
.pkg filecontainer --versionRuntime won't start:
container system start
container system status
Image build fails:
# Clean rebuild — Apple Container caches aggressively
container builder stop && container builder rm && container builder start
./container/build.sh
Container can't write to mounted directories: Check directory permissions on the host. The container runs as uid 1000.
| File | Type of Change |
|---|---|
src/container-runtime.ts | Full replacement — Docker → Apple Container API |
src/container-runtime.test.ts | Full replacement — tests for Apple Container behavior |
src/container-runner.ts | .env shadow mount removed, main containers start as root with privilege drop |
container/Dockerfile | Entrypoint: mount --bind for .env shadowing, setpriv privilege drop |
container/build.sh | Default runtime: docker → container |