Overview
IronClaw’s container orchestration extends the sandbox system to support persistent Docker containers running full agent worker processes. Unlike ephemeral command containers, orchestrated containers maintain state and communicate with the main agent via an internal HTTP API.Architecture
Job Modes
Worker Mode
Standard IronClaw worker with proxied LLM calls:- Runs
ironclaw workercommand - LLM requests proxied to orchestrator
- Full tool access (Bash, Read, Write, etc.)
- Multi-turn agent loop
- Custom tools via WASM/MCP
- Long-running background jobs
- Isolated project work
- Multi-step workflows
- Testing in clean environment
Claude Code Mode
Bridge to the official Claude CLI:- Spawns
claudeCLI directly - Native Claude Code tool use
- Anthropic API or OAuth authentication
- Tool allowlist for security
- Automatic session management
- Use Claude’s native computer use
- Access Claude-specific features
- Compare IronClaw vs Claude behavior
- Development and testing
Container Job Manager
Creating Jobs
Stopping Jobs
- Stops the container (10 second grace period)
- Removes the container
- Revokes the auth token
- Updates job state to
Stopped
Listing Jobs
Authentication
Bearer Token System
Each job gets a unique bearer token:- Tokens are never logged or serialized
- Stored in-memory only (lost on restart)
- Automatically revoked when job completes
- Single token per job
Credential Grants
Jobs can be granted access to specific credentials:Orchestrator API
Endpoints
POST /worker//llm/complete
Proxy LLM completion request:GET /worker//job
Get job metadata:POST /worker//status
Update worker status:POST /worker//complete
Mark job complete:Container Configuration
Worker Container
Claude Code Container
Same base image plus:Volume Mounts
Project directories are bind-mounted:Resource Limits
Security
Lifecycle Management
Container States
State Transitions
Cleanup
Automatic cleanup on completion:Manual Cleanup
Remove completed job from memory:Configuration
Building Worker Images
Standard Worker
Custom Worker
Add project-specific tools:Troubleshooting
Container Creation Fails
Orchestrator Connection Failed
- Check orchestrator is running:
lsof -i :50051 - Verify firewall allows port 50051
- For Linux, ensure
172.17.0.1is accessible from containers - For macOS/Windows, ensure
host.docker.internalresolves
Token Validation Failed
- Orchestrator restarted (tokens are in-memory only)
- Job completed and token was revoked
- Token expired or corrupted
Volume Mount Rejected
~/.ironclaw/projects/.
Solution:
Source Code
Key files:src/orchestrator/mod.rs- Module overviewsrc/orchestrator/job_manager.rs- Container lifecycle managementsrc/orchestrator/api.rs- HTTP API implementationsrc/orchestrator/auth.rs- Token store and credential grantsDockerfile.worker- Worker container definition