Skip to main content

Self-Hosted (Air-Gapped) Environments

Organizations with strict security policies or regulatory constraints that block outbound cloud connections can still run Claude Code in an air-gapped or closed network. This chapter covers deploying claude-code-server internally to keep the AI coding assistant fully within your security perimeter.

claude-code-server architecture​

claude-code-server is a relay and orchestration server deployed on your internal network.

  • Air-gapped support: works even when the internal network has no outbound internet access.
  • BYOM (Bring Your Own Model): connect an in-house local LLM or a model deployed on a private VPC.
  • SSO integration: enforce access control through your internal identity provider (SAML, OIDC, etc.).
  • Custom firewall and audit logs: apply internal firewall rules to every agent action (file access, shell command execution, outbound requests) and record detailed audit logs.

Installation and deployment​

An enterprise license is required. The server ships as a Docker image.

# Example: run the server as a Docker container
docker run -d -p 8080:8080 \
-v /path/to/config:/etc/claude \
-v /path/to/logs:/var/log/claude \
anthropic/claude-code-server:latest

Example config.yaml:

server:
host: 0.0.0.0
port: 8080

auth:
provider: sso
sso_url: "https://sso.yourcompany.com"

models:
default: "internal-model-v1"
providers:
- name: "internal-model-v1"
endpoint: "http://internal-llm.corp.local/v1"
type: "openai-compatible"

audit:
log_level: "debug"
destination: "syslog"

Client configuration​

Point the developer's local Claude Code client at the internal server.

# Point Claude Code at the internal server endpoint
claude config set serverEndpoint http://claude-server.corp.local:8080

# Authenticate via SSO (opens a browser popup)
claude login --sso

Self-hosted Environments (cloud session self-hosting, v2.1.224+)​

Starting with v2.1.224, Self-hosted Environments launched in public beta for Team and Enterprise plans. Organizations can run Claude Code cloud sessions directly on their own infrastructure β€” on-premise machines or containers.

1. How it works​

  • Isolated execution inside the corporate network: sessions started from the web app (claude.ai), the desktop/mobile app, or claude --cloud run inside your internal infrastructure, giving them safe access to internal services and intranet repositories.
  • Admin approval required: an admin must enable Allow self-hosted environments in admin settings (claude.ai/admin-settings/cloud-environments).

2. Runner setup​

An owner or admin runs the interactive setup from a terminal:

# Interactive setup for the self-hosted runner
claude self-hosted-runner setup

Once the runner is registered, the admin settings page shows the environment status as Healthy, and members can select that environment when creating new sessions.

Security and access control​

  • Network egress control: all outbound traffic through claude-code-server and the self-hosted runner can be restricted to an allowlist of internal intranet repositories (GitHub Enterprise, GitLab, etc.).
  • Tool execution control: central admins can push policies restricting specific shell commands (rm, curl, etc.) or file paths, enforcing agent permissions organization-wide.
  • Zero data retention: in self-hosted environments, data stays inside your own servers and is never sent externally.

이 챕터λ₯Ό μ™„λ£Œν•˜μ…¨λ‚˜μš”?

ν•™μŠ΅ 진도λ₯Ό μ²΄ν¬ν•˜μ—¬ λ‚˜μ˜ λ‘œλ“œλ§΅ 달성λ₯ μ„ λ†’μ—¬λ³΄μ„Έμš”.