build / Build and push image (push) Successful in 4m51s
Removes the per-sandbox setup cost AI_SBX_TOOLS pays on every setup, and makes the sandbox a terminal environment worth working in. Neovim comes from the upstream tarball rather than apt: Ubuntu's build is far behind what a LazyVim config needs. Upstream publishes no checksums, so NEOVIM_SHA256 is taken from the release asset and verified at build time. The version is pinned and labelled because a config that works on the host and breaks in the sandbox on a version skew is expensive to diagnose. The launcher is fetched from ai-sandbox v1.11.0's tasks/ai/workspace rather than vendored here. The task installs its own copy into stock-image sandboxes and skips that when the image supplies one, so two copies could drift and make behaviour depend on which image you are on. A bash -n guard rejects a forge error page served with a 200.
52 lines
2.1 KiB
Docker
52 lines
2.1 KiB
Docker
FROM docker/sandbox-templates:claude-code-docker
|
|
|
|
# Pinned deliberately: a Neovim config that works on the host and breaks in the
|
|
# sandbox because of a version skew is expensive to diagnose. Upstream publishes
|
|
# no checksums, so this digest was taken from the release asset itself.
|
|
ARG NEOVIM_VERSION=v0.12.4
|
|
ARG NEOVIM_SHA256=012bf3fcac5ade43914df3f174668bf64d05e049a4f032a388c027b1ebd78628
|
|
|
|
# The launcher is built from ai-sandbox's tasks/ai/workspace, never written
|
|
# independently — the task skips installing its own copy when the image supplies
|
|
# one, so a drifting copy would make behaviour depend on which image you are on.
|
|
ARG AI_SANDBOX_REF=v1.11.0
|
|
|
|
LABEL dev.mroberts.claude-sbx.neovim="${NEOVIM_VERSION}" \
|
|
dev.mroberts.claude-sbx.ai-sandbox-ref="${AI_SANDBOX_REF}"
|
|
|
|
USER root
|
|
RUN apt-get update \
|
|
&& apt-get install -y --no-install-recommends jq tmux \
|
|
&& rm -rf /var/lib/apt/lists/*
|
|
|
|
# ponytail: amd64 only — the sandbox microVM is x86_64. Add a uname case and a
|
|
# second digest if this ever needs to build on arm64.
|
|
RUN curl -fsSL -o /tmp/nvim.tar.gz \
|
|
"https://github.com/neovim/neovim/releases/download/${NEOVIM_VERSION}/nvim-linux-x86_64.tar.gz" \
|
|
&& printf '%s /tmp/nvim.tar.gz\n' "${NEOVIM_SHA256}" | sha256sum -c - \
|
|
&& tar -xzf /tmp/nvim.tar.gz -C /usr/local --strip-components=1 \
|
|
&& rm -f /tmp/nvim.tar.gz \
|
|
&& nvim --version | head -1
|
|
|
|
ADD --chmod=755 \
|
|
"https://git.mroberts.dev/mroberts/ai-sandbox/raw/tag/${AI_SANDBOX_REF}/tasks/ai/workspace" \
|
|
/usr/local/bin/ai-sbx-workspace
|
|
|
|
# A forge that answers a missing path with an HTML error page would otherwise
|
|
# produce an executable that fails only when someone tries to use it.
|
|
RUN bash -n /usr/local/bin/ai-sbx-workspace
|
|
|
|
USER agent
|
|
|
|
COPY --chown=agent:agent claude/ /home/agent/.claude/
|
|
|
|
RUN curl https://mise.run | sh \
|
|
&& printf 'export PATH="$HOME/.local/bin:$HOME/.local/share/mise/shims:$PATH"\n' \
|
|
>> /home/agent/.bashrc
|
|
|
|
COPY --chown=agent:agent plugins.json /tmp/plugins.json
|
|
COPY --chown=agent:agent scripts/install-plugins.sh /tmp/install-plugins.sh
|
|
|
|
RUN /tmp/install-plugins.sh /tmp/plugins.json \
|
|
&& rm -f /tmp/plugins.json /tmp/install-plugins.sh
|