Files
mroberts 1617bb15df
build / Build and push image (push) Successful in 4m51s
Add tmux, a pinned Neovim and the workspace launcher
Removes the per-sandbox setup cost AI_SBX_TOOLS pays on every setup, and
makes the sandbox a terminal environment worth working in.

Neovim comes from the upstream tarball rather than apt: Ubuntu's build is
far behind what a LazyVim config needs. Upstream publishes no checksums, so
NEOVIM_SHA256 is taken from the release asset and verified at build time.
The version is pinned and labelled because a config that works on the host
and breaks in the sandbox on a version skew is expensive to diagnose.

The launcher is fetched from ai-sandbox v1.11.0's tasks/ai/workspace rather
than vendored here. The task installs its own copy into stock-image
sandboxes and skips that when the image supplies one, so two copies could
drift and make behaviour depend on which image you are on. A bash -n guard
rejects a forge error page served with a 200.
2026-08-03 15:38:31 -05:00

52 lines
2.1 KiB
Docker

FROM docker/sandbox-templates:claude-code-docker
# Pinned deliberately: a Neovim config that works on the host and breaks in the
# sandbox because of a version skew is expensive to diagnose. Upstream publishes
# no checksums, so this digest was taken from the release asset itself.
ARG NEOVIM_VERSION=v0.12.4
ARG NEOVIM_SHA256=012bf3fcac5ade43914df3f174668bf64d05e049a4f032a388c027b1ebd78628
# The launcher is built from ai-sandbox's tasks/ai/workspace, never written
# independently — the task skips installing its own copy when the image supplies
# one, so a drifting copy would make behaviour depend on which image you are on.
ARG AI_SANDBOX_REF=v1.11.0
LABEL dev.mroberts.claude-sbx.neovim="${NEOVIM_VERSION}" \
dev.mroberts.claude-sbx.ai-sandbox-ref="${AI_SANDBOX_REF}"
USER root
RUN apt-get update \
&& apt-get install -y --no-install-recommends jq tmux \
&& rm -rf /var/lib/apt/lists/*
# ponytail: amd64 only — the sandbox microVM is x86_64. Add a uname case and a
# second digest if this ever needs to build on arm64.
RUN curl -fsSL -o /tmp/nvim.tar.gz \
"https://github.com/neovim/neovim/releases/download/${NEOVIM_VERSION}/nvim-linux-x86_64.tar.gz" \
&& printf '%s /tmp/nvim.tar.gz\n' "${NEOVIM_SHA256}" | sha256sum -c - \
&& tar -xzf /tmp/nvim.tar.gz -C /usr/local --strip-components=1 \
&& rm -f /tmp/nvim.tar.gz \
&& nvim --version | head -1
ADD --chmod=755 \
"https://git.mroberts.dev/mroberts/ai-sandbox/raw/tag/${AI_SANDBOX_REF}/tasks/ai/workspace" \
/usr/local/bin/ai-sbx-workspace
# A forge that answers a missing path with an HTML error page would otherwise
# produce an executable that fails only when someone tries to use it.
RUN bash -n /usr/local/bin/ai-sbx-workspace
USER agent
COPY --chown=agent:agent claude/ /home/agent/.claude/
RUN curl https://mise.run | sh \
&& printf 'export PATH="$HOME/.local/bin:$HOME/.local/share/mise/shims:$PATH"\n' \
>> /home/agent/.bashrc
COPY --chown=agent:agent plugins.json /tmp/plugins.json
COPY --chown=agent:agent scripts/install-plugins.sh /tmp/install-plugins.sh
RUN /tmp/install-plugins.sh /tmp/plugins.json \
&& rm -f /tmp/plugins.json /tmp/install-plugins.sh