← ClaudeAtlas

convert-to-apple-containerlisted

Switch from Docker to Apple Container for macOS-native container isolation. Use when the user wants Apple Container instead of Docker, or is setting up on macOS and prefers the native runtime. Triggers on "apple container", "convert to apple container", "switch to apple container", or "use apple container".
sliamh11/Deus · ★ 51 · AI & Automation · score 76
Install: claude install-skill sliamh11/Deus
# Convert to Apple Container This skill switches Deus's container runtime from Docker to Apple Container (macOS-only). It uses the skills engine for deterministic code changes, then walks through verification. **What this changes:** - Container runtime binary: `docker` → `container` - Mount syntax: `-v path:path:ro` → `--mount type=bind,source=...,target=...,readonly` - Startup check: `docker info` → `container system status` (with auto-start) - Orphan detection: `docker ps --filter` → `container ls --format json` - **Preserve the instance-suffix scoping (LIA-491).** `cleanupOrphans()` only stops containers whose name ends in this install's `-i<8hex>` stamp; names without a stamp are warned about, never stopped. Dropping that partition during the port silently restores the old host-wide sweep, in which a second daemon kills the first's live containers. The stamp is a plain name suffix, so it survives any listing format — only the parsing needs porting. - Build script default: `docker` → `container` - Dockerfile entrypoint: `.env` shadowing via `mount --bind` inside the container (Apple Container only supports directory mounts, not file mounts like Docker's `/dev/null` overlay) - Container runner: main-group containers start as root for `mount --bind`, then drop privileges via `setpriv` **What stays the same:** - Mount security/allowlist validation - All exported interfaces and IPC protocol - Non-main container behavior (still uses `--user` flag) - All