g1t/services/runner/Dockerfile

45 lines2,076 bytesCodeBlame

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

GitHub Actions on g1t, part two: running workflows1# The sandbox a g1t agent works in, and where GitHub Actions jobs run:
2# git, the agent, the g1t runner, and the toolchains an agent or a
3# workflow needs to build and test a change.
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)4# Build context: the repository root.
5
6# The same Debian release as the runtime image, so glibc matches.
7FROM rust:1-slim-bookworm AS build
8WORKDIR /src
9COPY Cargo.toml Cargo.lock ./
Build the sandbox image with the API crate present10# Cargo needs every workspace member present to resolve the workspace.
11COPY apps/api apps/api
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)12COPY crates crates
13COPY services services
14RUN cargo build --release --package g1t-runner
15
Actions: workflow_run, workflow.completed, artifacts on the run page, Node 2416FROM node:24-bookworm-slim
GitHub Actions on g1t, part two: running workflows17# Workflows expect GitHub's runner layout under /home/runner, and sudo
18# without a password.
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)19RUN apt-get update \
Show the model behind each choice; toolchains in the sandbox20 && apt-get install -y --no-install-recommends \
21 git ca-certificates curl build-essential pkg-config libssl-dev \
22 python3 python3-pip python3-venv golang-go ripgrep jq \
GitHub Actions on g1t, part two: running workflows23 sudo unzip zip xz-utils wget file gnupg lsb-release \
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)24 && rm -rf /var/lib/apt/lists/* \
25 && npm install --global @anthropic-ai/claude-code \
GitHub Actions on g1t, part two: running workflows26 && mkdir /work && chown node:node /work \
27 && mkdir -p /home/runner/work /home/runner/_temp /home/runner/_tool /home/runner/_actions \
28 && chown -R node:node /home/runner \
29 && echo 'node ALL=(ALL) NOPASSWD:ALL' > /etc/sudoers.d/node \
30 && chmod 0440 /etc/sudoers.d/node
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)31COPY --from=build /src/target/release/g1t-runner /usr/local/bin/g1t-runner
32# Claude Code refuses to skip permission prompts as root.
33USER node
34ENV HOME=/home/node
Usage while free is shown at cost; agents get rustfmt and clippy35# Rust, for the agent's own use, installed for the user it runs as, with
36# the formatter and linter that CI so often checks with: an agent that
37# cannot run them only finds out from a failed workflow.
Show the model behind each choice; toolchains in the sandbox38RUN curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs \
Usage while free is shown at cost; agents get rustfmt and clippy39 | sh -s -- -y --profile minimal --default-toolchain stable \
40 --component rustfmt --component clippy
Show the model behind each choice; toolchains in the sandbox41ENV PATH=/home/node/.cargo/bin:$PATH
Issues and pull requests replace intents and attempts42# Commits are the g1t agent's; the harness does not sign them as its own.
43RUN mkdir -p /home/node/.claude \
44 && echo '{"includeCoAuthoredBy": false}' > /home/node/.claude/settings.json
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)45ENTRYPOINT ["g1t-runner"]