pr_01m47d24b0e6n91zwymwxg0vpx/services/runner/Dockerfile

45 lines2,076 bytesCodeBlame
1# The sandbox a g1t agent works in, and where GitHub Actions jobs run:
2# git, the agent, the g1t runner, and the toolchains an agent or a
3# workflow needs to build and test a change.
4# Build context: the repository root.
5
6# The same Debian release as the runtime image, so glibc matches.
7FROM rust:1-slim-bookworm AS build
8WORKDIR /src
9COPY Cargo.toml Cargo.lock ./
10# Cargo needs every workspace member present to resolve the workspace.
11COPY apps/api apps/api
12COPY crates crates
13COPY services services
14RUN cargo build --release --package g1t-runner
15
16FROM node:24-bookworm-slim
17# Workflows expect GitHub's runner layout under /home/runner, and sudo
18# without a password.
19RUN apt-get update \
20 && apt-get install -y --no-install-recommends \
21 git ca-certificates curl build-essential pkg-config libssl-dev \
22 python3 python3-pip python3-venv golang-go ripgrep jq \
23 sudo unzip zip xz-utils wget file gnupg lsb-release \
24 && rm -rf /var/lib/apt/lists/* \
25 && npm install --global @anthropic-ai/claude-code \
26 && mkdir /work && chown node:node /work \
27 && mkdir -p /home/runner/work /home/runner/_temp /home/runner/_tool /home/runner/_actions \
28 && chown -R node:node /home/runner \
29 && echo 'node ALL=(ALL) NOPASSWD:ALL' > /etc/sudoers.d/node \
30 && chmod 0440 /etc/sudoers.d/node
31COPY --from=build /src/target/release/g1t-runner /usr/local/bin/g1t-runner
32# Claude Code refuses to skip permission prompts as root.
33USER node
34ENV HOME=/home/node
35# Rust, for the agent's own use, installed for the user it runs as, with
36# the formatter and linter that CI so often checks with: an agent that
37# cannot run them only finds out from a failed workflow.
38RUN curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs \
39 | sh -s -- -y --profile minimal --default-toolchain stable \
40 --component rustfmt --component clippy
41ENV PATH=/home/node/.cargo/bin:$PATH
42# Commits are the g1t agent's; the harness does not sign them as its own.
43RUN mkdir -p /home/node/.claude \
44 && echo '{"includeCoAuthoredBy": false}' > /home/node/.claude/settings.json
45ENTRYPOINT ["g1t-runner"]