AI 编程 3.0 · 值得看 2026-03-16 · 文章

Reverse-Engineering Claude Code Web's MicroVM: Anthropic's Antspace enterprise PaaS

AprilNEA 通过 Claude Code 会话内运行的标准 Linux 工具(strace/strings/objdump/go tool objdump)对未 strip 的二进制进行逆向,发现 Claude Code Web 跑在 Firecracker MicroVM 上(ACPI 表由 OEM ID FIRECK 签名)进一步追踪得出 Anthropic 内部一个未公开的应用托管平台 Antspace:基于 containerd + KVM 的多租户 PaaS,覆盖 builddeployservingproxy 全链路...

打开原文回到归档

Reverse-Engineering Claude Code Web's MicroVM: Anthropic's Antspace enterprise PaaS

Source: https://aprilnea.me/en/blog/reverse-engineering-claude-code-antspace
Author: AprilNEA
Published: 2026-03-16
Platform: blog

中文概要

AprilNEA 通过 Claude Code 会话内运行的标准 Linux 工具(strace/strings/objdump/go tool objdump)对未 strip 的二进制进行逆向,发现 Claude Code Web 跑在 Firecracker MicroVM 上(ACPI 表由 OEM ID FIRECK 签名)进一步追踪得出 Anthropic 内部一个未公开的应用托管平台 Antspace:基于 containerd + KVM 的多租户 PaaS,覆盖 builddeployservingproxy 全链路,与 Railway/E2B 同位但补齐 AI Agent 运行时的本地-云一致性文章同时还原了 Claude Code Web 的目录结构(Firecracker image + overlay)init 进程 process_api 与 Go runtime,并交叉验证了 ArcBox 团队此前的设计取舍作者声明未使用 exploit未做提权未发起网络攻击,全部结论来自二进制静态分析 + 进程观察

English Summary

AprilNEA (ArcBox) reverse-engineered Claude Code Web's runtime from inside an unstripped Go binary using only strace, strings, objdump, and go tool objdump. The Claude Code Web sandbox runs in a Firecracker MicroVM (ACPI tables signed by OEM ID FIRECK). Deeper analysis reveals Anthropic's previously undocumented internal application hosting platform 'Antspace' a multi-tenant PaaS combining containerd, KVM, and overlayfs, with build/deploy/serving/proxy pipelines competing against Railway and E2B. The post reconstructs the image layout, the process_api init process, and the Go runtime. AprilNEA emphasise that no exploits, privilege escalation, or network attacks were used; every conclusion is grounded in static binary analysis and in-sandbox process observation.