pr_01m47d24b0e6n91zwymwxg0vpx/services/runner/Dockerfile

34 lines1,468 bytesCodeBlame
1# The sandbox a g1t agent works in: git, the agent, the g1t runner, and
2# the toolchains an agent needs to build and test what it changes.
3# Build context: the repository root.
4
5# The same Debian release as the runtime image, so glibc matches.
6FROM rust:1-slim-bookworm AS build
7WORKDIR /src
8COPY Cargo.toml Cargo.lock ./
9# Cargo needs every workspace member present to resolve the workspace.
10COPY apps/api apps/api
11COPY crates crates
12COPY services services
13RUN cargo build --release --package g1t-runner
14
15FROM node:22-bookworm-slim
16RUN apt-get update \
17 && apt-get install -y --no-install-recommends \
18 git ca-certificates curl build-essential pkg-config libssl-dev \
19 python3 python3-pip python3-venv golang-go ripgrep jq \
20 && rm -rf /var/lib/apt/lists/* \
21 && npm install --global @anthropic-ai/claude-code \
22 && mkdir /work && chown node:node /work
23COPY --from=build /src/target/release/g1t-runner /usr/local/bin/g1t-runner
24# Claude Code refuses to skip permission prompts as root.
25USER node
26ENV HOME=/home/node
27# Rust, for the agent's own use, installed for the user it runs as.
28RUN curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs \
29 | sh -s -- -y --profile minimal --default-toolchain stable
30ENV PATH=/home/node/.cargo/bin:$PATH
31# Commits are the g1t agent's; the harness does not sign them as its own.
32RUN mkdir -p /home/node/.claude \
33 && echo '{"includeCoAuthoredBy": false}' > /home/node/.claude/settings.json
34ENTRYPOINT ["g1t-runner"]