Adds to permissions.allow: - ssh, scp, sftp (remote exec + file transfer) - ssh-add, ssh-keygen, ssh-copy-id (key management) - rsync (fast file sync) No Dockerfile change -> no rebuild needed; settings.json is bind-mounted into the container. After git pull, /exit + restart claude to reload.