Skip to content

Choosing an Image

Serge Gatezh edited this page Oct 8, 2026 · 3 revisions

Choosing an Image

Six images are published under ghcr.io/gatezh/devcontainers/. This page picks one for you; the linked README has the setup detail.


Quick answer

You are building Use Notes
A JS/TS project with Bun bun Smallest. Alpine.
A Hugo site hugo-bun Hugo Extended + Bun + Go (for Hugo Modules).
A Hugo site deployed to Cloudflare Workers hugo-bun-node Same, plus Node.js LTS for the Cloudflare CLI or Wrangler.
Anything, with Claude Code as the primary tool claude-code The most complete image. Projects pin their own tools via .mise.toml.
The same, but network-restricted claude-code-sandbox Same Dockerfile, sandbox target. iptables firewall.
A ralphex project ralphex-fe Not a devcontainer — a standalone image.
Claude Code on a Bun/Alpine base with a firewall claude-bun Predates claude-code; based on Anthropic's reference devcontainer.

The two families

The images fall into two groups that behave differently, and the difference matters more than the tool lists.

Fixed-toolchain images

bun, claude-bun, hugo-bun, hugo-bun-node

The image is the toolchain. hugo-bun bakes in Bun 1.3.8 and Hugo 0.155.1, and the tag says so (hugo0.155.1-bun1.3.8-alpine). To move to a newer Hugo you move to a newer tag. Good when you want the environment pinned and boring.

Bring-your-own-toolchain images

claude-code, claude-code-sandbox

The image ships mise — the tool manager — but not the tools. Your project's .mise.toml decides its Node, Bun, Go and Python versions, and mise install runs at container creation. Two projects can share one image on different toolchains.

What is pinned in the image is the agent tooling and CLIs: Claude Code, agent-browser, rtk, ralphex, gh, gh-stack, and Cloudflare's cf (Cloudflare CLI). Those are treated as infrastructure so projects don't each track them. See Image Tags and Rebuild Policy.

And one that is neither

ralphex-fe is a standalone Docker image, not a devcontainer — there is no devcontainer.json and VS Code will not attach to it. It is run by ralphex's own docker-wrapper script.


Platform support

Every image is built for linux/amd64 and linux/arm64, so Apple Silicon runs natively with no emulation.


What's in each

Bun Hugo Node Go Claude Code Firewall Base
bun ✅ Alpine
claude-bun ✅ ✅ ✅ Debian slim
hugo-bun ✅ ✅ ✅ Alpine + gcompat
hugo-bun-node ✅ ✅ ✅ ✅ Alpine + gcompat
claude-code via mise via mise ✅ via mise ✅ node:24-trixie-slim
claude-code-sandbox via mise via mise ✅ via mise ✅ ✅ node:24-trixie-slim
ralphex-fe ✅ ✅ ✅ ✅ ✅ node:24-trixie-slim

claude-code (both variants) and ralphex-fe also carry system Chromium. In claude-code, agents drive it with agent-browser by default and fall back to Playwright, steered by a built-in browser skill; ralphex-fe has Playwright only. See Troubleshooting if a browser fails to launch.


claude-bun or claude-code?

Both run Claude Code, and this is the most common question.

  • claude-code is the current one. Two variants from a single Dockerfile, mise-managed project toolchains, agent tooling on a Renovate-driven rebuild, browser automation wired up (agent-browser by default, Playwright as fallback), and by far the most detailed README.
  • claude-bun is older and narrower: a Bun-first take on Anthropic's reference devcontainer, with the firewall from that design.

Pick claude-code unless you specifically want the Bun-based Anthropic-reference shape.


Sources

  • #116 — Renovate-driven rebuilds for claude-code and ralphex-fe
  • #120 — describing the agent tools as pinned rather than always-latest
  • #146, #167 — gh and gh-stack pinned in claude-code
  • #175 — agent-browser as the default browser tool in both claude-code variants, via a built-in skill
  • #204 — Cloudflare's cf CLI pinned in claude-code
  • Per-image READMEs in the repo are the authority for anything specific to one image

Last verified: 2026-10-08