- Restore workspace auto-entry on ai user login - Use systemd-nspawn -q -D to enter workspace - Start claude with --dangerously-skip-permissions (no approval needed) - Grant wheel group full sudo access (NOPASSWD: ALL) for container operation - ai user can perform all root operations via sudo in workspace