2 Commits
Author SHA1 Message Date
mroberts b536a587c1 Drop the Vikunja skill from the image
build / Build and push image (push) Successful in 3m34s
The image is published to a public registry, and the skill named the
employer as its Vikunja root project and pointed at tasks.mroberts.dev.
Neither is a secret, but neither belongs in an artefact anyone can pull.

It is a host-side planning skill with nothing to do inside a sandbox, so
removing it costs the sandbox no capability.
2026-08-03 16:14:32 -05:00
mroberts c89e4f0568 Add sandbox template image with Claude configuration and plugins
build / build (push) Canceled after 0s
Carries CLAUDE.md, AGENTS.md, hooks and skills verbatim from the host, plus a
manifest of the 10 marketplaces and 17 plugins to reinstall at build time. The
plugin directories themselves are not committed: ~/.claude/plugins is 831 MB and
sits alongside credentials and transcripts, so the image is reproduced from the
manifest instead and the build needs no access to the host.

The Gitea registry is behind Cloudflare, which rejects request bodies over 100 MB
against a base image with a 325 MB layer, so the workflow pushes chunked through
regctl rather than docker push.

sbx v0.37.0 and v0.37.1 cannot consume the result: layers stacked on the base are
silently dropped (docker/sbx-releases#366). The image builds and pushes correctly
and is a no-op at runtime until that is fixed, so README points at
'ai:sbx setup' as the mechanism that works today.
2026-07-31 08:18:30 -05:00