Compare commits
2
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
ecee633479 | ||
|
|
055dd88f5e |
+27
-13
@@ -40,19 +40,21 @@ const (
|
||||
stateRunning string = "running"
|
||||
stateError string = "error"
|
||||
|
||||
imageRefWorker string = "lvmh-worker:latest"
|
||||
labelSession string = "lvmh.session"
|
||||
volumeRepoPrefix string = "lvmh-repo-"
|
||||
volumeSessions string = "lvmh-sessions"
|
||||
volumePiCache string = "lvmh-pi-cache" // pi package cache (git:/npm:), shared across spawns
|
||||
cacheMount string = "/root/.pi/agent/cache"
|
||||
authMountTarget string = "/root/.pi/agent/auth.json"
|
||||
envHostPiAgentDir string = "LVMH_HOST_PI_AGENT_DIR"
|
||||
envSecretsDir string = "LVMH_SECRETS_DIR"
|
||||
sshMountTarget string = "/root/.ssh"
|
||||
gitconfigMountTarget string = "/root/.gitconfig"
|
||||
workspaceMount string = "/workspace"
|
||||
sessionsMount string = "/pi-sessions"
|
||||
imageRefWorker string = "lvmh-worker:latest"
|
||||
labelSession string = "lvmh.session"
|
||||
volumeRepoPrefix string = "lvmh-repo-"
|
||||
volumeSessions string = "lvmh-sessions"
|
||||
volumePiCache string = "lvmh-pi-cache" // pi package cache (git:/npm:), shared across spawns
|
||||
cacheMount string = "/root/.pi/agent/cache"
|
||||
authMountTarget string = "/root/.pi/agent/auth.json"
|
||||
envHostPiAgentDir string = "LVMH_HOST_PI_AGENT_DIR"
|
||||
envSecretsDir string = "LVMH_SECRETS_DIR"
|
||||
envCloakCacheDir string = "LVMH_CLOAK_CACHE_DIR"
|
||||
envPlaywrightCacheDir string = "LVMH_PLAYWRIGHT_CACHE_DIR"
|
||||
sshMountTarget string = "/root/.ssh"
|
||||
gitconfigMountTarget string = "/root/.gitconfig"
|
||||
workspaceMount string = "/workspace"
|
||||
sessionsMount string = "/pi-sessions"
|
||||
|
||||
envWorkerDockerfile string = "LVMH_WORKER_DOCKERFILE"
|
||||
defaultDockerfile string = "/app/build/docker/worker.Dockerfile"
|
||||
@@ -374,6 +376,7 @@ func workerEnv(s *Spawner, repo, sessionID string) []string {
|
||||
"GEMINI_API_KEY=" + os.Getenv("GEMINI_API_KEY"),
|
||||
"DEEPSEEK_KEY=" + os.Getenv("DEEPSEEK_KEY"),
|
||||
"ANTHROPIC_API_KEY=" + os.Getenv("ANTHROPIC_API_KEY"),
|
||||
"PLAYWRIGHT_BROWSERS_PATH=/pw-browsers",
|
||||
envLVMHRepo + "=" + repo,
|
||||
}
|
||||
// Gitea token (write scope) so agents can push and open PRs.
|
||||
@@ -555,6 +558,17 @@ func (s *Spawner) createAndStart(ctx context.Context, repo, slug, sessionID stri
|
||||
if hostAgent := os.Getenv(envHostPiAgentDir); hostAgent != "" {
|
||||
binds = append(binds, hostAgent+"/auth.json:"+authMountTarget+":ro")
|
||||
}
|
||||
// Shared playwright browser cache (host path, read-only); the env var
|
||||
// below makes every playwright-based MCP use it instead of downloading.
|
||||
if pw := os.Getenv(envPlaywrightCacheDir); pw != "" {
|
||||
binds = append(binds, pw+":/pw-browsers:ro")
|
||||
}
|
||||
// Shared cloakbrowser chromium cache (host path, read-only): browsers
|
||||
// are ~700MB; one copy serves every container. CLOAKBROWSER_CACHE_DIR
|
||||
// points the MCP at it (see docker/mcp.json).
|
||||
if cb := os.Getenv(envCloakCacheDir); cb != "" {
|
||||
binds = append(binds, cb+":/cloakbrowser-cache:ro")
|
||||
}
|
||||
// Deploy secrets (ssh key + known_hosts + config, gitconfig), read-only.
|
||||
// Bind sources resolve on the HOST (docker.sock semantics), so this env
|
||||
// must carry the host path of the secrets dir.
|
||||
|
||||
@@ -72,7 +72,7 @@ func TestSpawnerStartHappyPath(t *testing.T) {
|
||||
passthrough := map[string]bool{
|
||||
"OPENAI_API_KEY": true, "GEMINI_API_KEY": true,
|
||||
"DEEPSEEK_KEY": true, "ANTHROPIC_API_KEY": true,
|
||||
"LVMH_GITEA_TOKEN": true,
|
||||
"LVMH_GITEA_TOKEN": true, "PLAYWRIGHT_BROWSERS_PATH": true,
|
||||
}
|
||||
for _, e := range c.Env {
|
||||
if name, _, ok := strings.Cut(e, "="); ok && passthrough[name] {
|
||||
|
||||
@@ -20,6 +20,8 @@ services:
|
||||
# this must be the HOST path of the pi config (auth.json etc.).
|
||||
LVMH_HOST_PI_AGENT_DIR: ${LVMH_PI_AGENT_DIR:-/home/alarm/.dotfiles/pi/agent}
|
||||
LVMH_SECRETS_DIR: /zdata/root/lvmh-secrets
|
||||
LVMH_CLOAK_CACHE_DIR: /home/alarm/.cloakbrowser
|
||||
LVMH_PLAYWRIGHT_CACHE_DIR: /home/alarm/.cache/ms-playwright
|
||||
OPENAI_API_KEY: ${OPENAI_API_KEY:-}
|
||||
GEMINI_API_KEY: ${GEMINI_API_KEY:-}
|
||||
DEEPSEEK_KEY: ${DEEPSEEK_KEY:-}
|
||||
|
||||
@@ -8,6 +8,9 @@ RUN apt-get update \
|
||||
&& apt-get install -y --no-install-recommends \
|
||||
bash ca-certificates git ripgrep curl xz-utils make jq golang-go \
|
||||
docker.io \
|
||||
libglib2.0-0 libnss3 libnspr4 libatk1.0-0 libatk-bridge2.0-0 \
|
||||
libcups2 libdrm2 libxkbcommon0 libxcomposite1 libxdamage1 \
|
||||
libxfixes3 libxrandr2 libgbm1 libpango-1.0-0 libcairo2 libasound2 \
|
||||
&& rm -rf /var/lib/apt/lists/*
|
||||
|
||||
RUN npm install -g --ignore-scripts @earendil-works/pi-coding-agent
|
||||
@@ -34,6 +37,11 @@ COPY docker/bridge /bridge
|
||||
COPY docker/ops-context/entrypoint.sh /entrypoint.sh
|
||||
RUN chmod +x /entrypoint.sh
|
||||
|
||||
# MCP tooling (same as workers; ops also browses).
|
||||
RUN npm-real install -g --ignore-scripts cloakbrowser-mcp@1.4.0 \
|
||||
&& mkdir -p /root/.config/mcp
|
||||
COPY docker/mcp.json /root/.config/mcp/mcp.json
|
||||
|
||||
ENV PI_SESSION_DIR=/pi-sessions
|
||||
WORKDIR /ops
|
||||
ENTRYPOINT ["/entrypoint.sh"]
|
||||
|
||||
@@ -0,0 +1,13 @@
|
||||
{
|
||||
"mcpServers": {
|
||||
"playwright": {
|
||||
"command": "npx",
|
||||
"args": ["@playwright/mcp@latest", "--headless", "--browser", "chromium"]
|
||||
},
|
||||
"cloakbrowser": {
|
||||
"command": "cloakbrowser-mcp",
|
||||
"args": [],
|
||||
"env": { "CLOAKBROWSER_CACHE_DIR": "/cloakbrowser-cache" }
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -41,7 +41,12 @@ When asked to prepare a workspace for a repo (e.g. "prepare empstream"):
|
||||
|
||||
Include everything an agent working in that repo needs (compilers, DB
|
||||
clients, protobuf, etc.). The base already has: node 24, pi, golang, git,
|
||||
ripgrep, make, jq, gopls. Don't reinstall those.
|
||||
ripgrep, make, jq, gopls, **the MCP stack (cloakbrowser-mcp, playwright
|
||||
via npx, chromium runtime libs, `/root/.config/mcp/mcp.json`)** plus
|
||||
shared browser-cache mounts (`/cloakbrowser-cache`, `/pw-browsers`).
|
||||
Don't reinstall any of those — `FROM lvmh-worker:latest` inherits them.
|
||||
If a repo needs an extra MCP server, MERGE it into the image's
|
||||
`/root/.config/mcp/mcp.json` (never overwrite the existing servers).
|
||||
|
||||
3. **Build**:
|
||||
|
||||
|
||||
@@ -7,6 +7,9 @@ RUN apt-get update \
|
||||
&& apt-get install -y --no-install-recommends \
|
||||
bash ca-certificates git ripgrep curl xz-utils make jq \
|
||||
golang-go \
|
||||
libglib2.0-0 libnss3 libnspr4 libatk1.0-0 libatk-bridge2.0-0 \
|
||||
libcups2 libdrm2 libxkbcommon0 libxcomposite1 libxdamage1 \
|
||||
libxfixes3 libxrandr2 libgbm1 libpango-1.0-0 libcairo2 libasound2 \
|
||||
&& rm -rf /var/lib/apt/lists/*
|
||||
|
||||
RUN GOBIN=/usr/local/bin go install golang.org/x/tools/gopls@latest || true
|
||||
@@ -17,6 +20,8 @@ RUN npm install -g --ignore-scripts @earendil-works/pi-coding-agent
|
||||
# scripts (husky etc.) crash headless installs. Route installs through
|
||||
# --ignore-scripts so ALL dotfiles packages (pi-subagents, todo tooling,
|
||||
# async agents, every extension) survive the bake.
|
||||
# MCP servers available to pi agents (matches the host setup).
|
||||
# cloakbrowser-mcp ships the browser automation MCP (bundled deps, no postinstall).
|
||||
COPY docker/npm-real /usr/local/bin/npm-real
|
||||
COPY docker/npm-shim /usr/local/bin/npm-ignore-scripts
|
||||
# rm first: /usr/local/bin/npm is a symlink into npm's lib dir, and COPY
|
||||
@@ -39,6 +44,12 @@ COPY docker/bridge /bridge
|
||||
|
||||
# Per-session pi sessions persist here (volume lvmh-sessions); package cache
|
||||
# shared across spawns via volume lvmh-pi-cache at /root/.pi/agent/cache.
|
||||
# MCP tooling: cloakbrowser-mcp global (bundled deps), npx for playwright,
|
||||
# and the standard MCP config the pi-mcp-adapter reads.
|
||||
RUN npm-real install -g --ignore-scripts cloakbrowser-mcp@1.4.0 \
|
||||
&& mkdir -p /root/.config/mcp
|
||||
COPY docker/mcp.json /root/.config/mcp/mcp.json
|
||||
|
||||
ENV PI_SESSION_DIR=/pi-sessions
|
||||
WORKDIR /workspace
|
||||
CMD ["node", "/bridge/index.mjs"]
|
||||
|
||||
Reference in New Issue
Block a user