Commit Graph
7 Commits
Author SHA1 Message Date
mroberts b536a587c1 Drop the Vikunja skill from the image
build / Build and push image (push) Successful in 3m34s
The image is published to a public registry, and the skill named the
employer as its Vikunja root project and pointed at tasks.mroberts.dev.
Neither is a secret, but neither belongs in an artefact anyone can pull.

It is a host-side planning skill with nothing to do inside a sandbox, so
removing it costs the sandbox no capability.
2026-08-03 16:14:32 -05:00
mroberts 1617bb15df Add tmux, a pinned Neovim and the workspace launcher
build / Build and push image (push) Successful in 4m51s
Removes the per-sandbox setup cost AI_SBX_TOOLS pays on every setup, and
makes the sandbox a terminal environment worth working in.

Neovim comes from the upstream tarball rather than apt: Ubuntu's build is
far behind what a LazyVim config needs. Upstream publishes no checksums, so
NEOVIM_SHA256 is taken from the release asset and verified at build time.
The version is pinned and labelled because a config that works on the host
and breaks in the sandbox on a version skew is expensive to diagnose.

The launcher is fetched from ai-sandbox v1.11.0's tasks/ai/workspace rather
than vendored here. The task installs its own copy into stock-image
sandboxes and skips that when the image supplies one, so two copies could
drift and make behaviour depend on which image you are on. A bash -n guard
rejects a forge error page served with a 200.
2026-08-03 15:38:31 -05:00
mroberts 9be4122580 Record the verified CI path and its token requirement
build / Build and push image (push) Successful in 30s
The registry rejects the automatic token, so the workflow needs a personal access
token scoped to package read and write, and the runner label must match one the
forge actually has. Both cost a failed run to discover.
2026-07-31 09:06:05 -05:00
mroberts 2b61c3a639 Authenticate the registry push with a scoped token
build / Build and push image (push) Successful in 1m45s
The automatic token is rejected by the package registry regardless of the
permissions the job requests, so the push uses a personal access token scoped
to package read and write. The job no longer asks for packages: write, since
nothing it does with the automatic token touches the registry.
2026-07-31 09:02:27 -05:00
mroberts 5c0a7263e4 Harden the build workflow and grant package write
build / Build and push image (push) Failing after 36s
The v1.0.1 tag claimed this work but did not contain it: the edits were still
in the working copy when main was moved and pushed. This is that change.

The run against v1.0.1 reached the registry and failed with 'unauthorized'.
The automatic token cannot write packages without the job asking for it, so
the job now requests packages: write and nothing wider.

actions/checkout is pinned to a commit rather than a tag, at v4.4.0 rather than
the current v7.0.1, which declares node24 that act_runner does not provide.
regctl is pinned to a release instead of tracking latest. Every expansion moves
into env so nothing interpolates into a shell body.

Clean under actionlint and zizmor --persona=auditor. .shush.toml preserves the
comments those linters require, which the comment hook was otherwise removing.
2026-07-31 08:55:19 -05:00
mroberts b79bf35e70 Target the self-hosted runner label and harden the workflow
build / build (push) Failing after 3m38s
ubuntu-latest matches no runner on this forge, so both the main push and the
v1.0.0 tag queued nothing at all. The runner is labelled linux.

actions/checkout is pinned to a commit rather than a tag, and to v4.4.0 rather
than the current v7.0.1: v7 declares node24, which act_runner does not provide.
regctl moves out of /usr/local/bin, which a self-hosted runner cannot write to
without sudo, and is pinned to a release rather than tracking latest.

Clean under actionlint and zizmor --persona=auditor. Every expansion moves into
env so nothing interpolates into a shell body. secrets-outside-env is suppressed
deliberately: Gitea has no deployment environment protection rules, so a
dedicated environment would add ceremony without a security boundary.
2026-07-31 08:25:20 -05:00
mroberts c89e4f0568 Add sandbox template image with Claude configuration and plugins
build / build (push) Canceled after 0s
Carries CLAUDE.md, AGENTS.md, hooks and skills verbatim from the host, plus a
manifest of the 10 marketplaces and 17 plugins to reinstall at build time. The
plugin directories themselves are not committed: ~/.claude/plugins is 831 MB and
sits alongside credentials and transcripts, so the image is reproduced from the
manifest instead and the build needs no access to the host.

The Gitea registry is behind Cloudflare, which rejects request bodies over 100 MB
against a base image with a 325 MB layer, so the workflow pushes chunked through
regctl rather than docker push.

sbx v0.37.0 and v0.37.1 cannot consume the result: layers stacked on the base are
silently dropped (docker/sbx-releases#366). The image builds and pushes correctly
and is a no-op at runtime until that is fixed, so README points at
'ai:sbx setup' as the mechanism that works today.
2026-07-31 08:18:30 -05:00