Files
claude-sbx/.gitea/workflows/build.yml
T
mroberts c89e4f0568
build / build (push) Canceled after 0s
Add sandbox template image with Claude configuration and plugins
Carries CLAUDE.md, AGENTS.md, hooks and skills verbatim from the host, plus a
manifest of the 10 marketplaces and 17 plugins to reinstall at build time. The
plugin directories themselves are not committed: ~/.claude/plugins is 831 MB and
sits alongside credentials and transcripts, so the image is reproduced from the
manifest instead and the build needs no access to the host.

The Gitea registry is behind Cloudflare, which rejects request bodies over 100 MB
against a base image with a 325 MB layer, so the workflow pushes chunked through
regctl rather than docker push.

sbx v0.37.0 and v0.37.1 cannot consume the result: layers stacked on the base are
silently dropped (docker/sbx-releases#366). The image builds and pushes correctly
and is a no-op at runtime until that is fixed, so README points at
'ai:sbx setup' as the mechanism that works today.
2026-07-31 08:18:30 -05:00

56 lines
1.5 KiB
YAML

name: build
on:
push:
branches: [main]
tags: ['v*']
env:
REGISTRY: git.mroberts.dev
IMAGE: git.mroberts.dev/mroberts/claude-sbx
jobs:
build:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Install regctl
run: |
curl -fsSL -o /usr/local/bin/regctl \
https://github.com/regclient/regclient/releases/latest/download/regctl-linux-amd64
chmod +x /usr/local/bin/regctl
- name: Resolve tag
id: tag
run: |
if [[ "$GITHUB_REF" == refs/tags/* ]]; then
printf 'value=%s\n' "${GITHUB_REF#refs/tags/}" >>"$GITHUB_OUTPUT"
else
printf 'value=edge\n' >>"$GITHUB_OUTPUT"
fi
- name: Build
run: docker build -t "$IMAGE:${{ steps.tag.outputs.value }}" .
- name: Export image
run: docker save "$IMAGE:${{ steps.tag.outputs.value }}" -o image.tar
- name: Push
run: |
regctl registry login "$REGISTRY" \
--user "${{ github.actor }}" \
--pass-stdin <<<"${{ secrets.GITEA_TOKEN }}"
regctl registry set "$REGISTRY" \
--blob-chunk 50000000 \
--blob-max 50000000
regctl image import "$IMAGE:${{ steps.tag.outputs.value }}" image.tar
- name: Verify
run: |
regctl manifest get "$IMAGE:${{ steps.tag.outputs.value }}" >/dev/null
printf 'Pushed %s:%s\n' "$IMAGE" "${{ steps.tag.outputs.value }}"