Inside the environment
What Claude Code does once it's running inside your VM.
Claude Code runs inside your environment's VM as the application user. From there it has the same access you do via SSH — which means full access to the project directory, the database, and all running containers.
What it can do
- Read files Claude inspects code, configs, logs, and database contents
- Run shell commands anything you can do at a bash prompt
- Edit files Claude writes patches directly to your working directory
- Run git branch, commit, push to your remote
- Open pull requests using your configured git remote, with a commit message and PR description
- Query the database runs MariaDB queries via the local socket
- Trigger Magento commands
bin/magento cache:flush,bin/magento indexer:reindex, cron, queue consumers, and more
What it knows about your environment
Claude is pre-loaded with platform context:
- The directory layout (
/var/www/<subdomain>.<domain>/application/is the Magento root) - Container names (nginx, php, mariadb, redis, opensearch, varnish, rabbitmq, nodejs, crowdsec, helio)
- The log file locations (Magento logs at
var/log/*.log; container output viadocker logs) - The deploy mechanism (Deployer PHP — see Deployments tab)
This means common requests work without you typing out paths:
- "Find why checkout is throwing a 500 in exception.log"
- "Look at the last 100 cron entries and identify any failures"
- "Show me the unprocessed messages in the RabbitMQ queue"
When Claude needs you
In the Hub Console tab, Claude runs with --dangerously-skip-permissions by default — it executes its planned actions without asking for per-step approval. See Approval gates for what this means and when to opt out.
Even with that flag set, Claude is conservative about genuinely irreversible operations. Before running a destructive database mutation, deleting files outside the repo, or forcing a git history rewrite, Claude describes the planned action in plain English and asks for explicit confirmation before proceeding.
If you want explicit approval for every action, open a Bash tab and run claude yourself without the flag.