mirror of
https://github.com/block/buzz.git
synced 2026-08-18 06:50:31 +02:00
build: add Sprig agent image
Co-authored-by: npub1t2tgm7d8f995uqvmnm8h88sg3wnpp9a5xysjf6dg3tjmgt3ltulqdp8ehr <5a968df9a7494b4e019b9ecf739e088ba61097b4312124e9a88ae5b42e3f5f3e@buzz.block.builderlab.xyz> Signed-off-by: npub1t2tgm7d8f995uqvmnm8h88sg3wnpp9a5xysjf6dg3tjmgt3ltulqdp8ehr <5a968df9a7494b4e019b9ecf739e088ba61097b4312124e9a88ae5b42e3f5f3e@buzz.block.builderlab.xyz>
This commit is contained in:
parent
c370f0fcf1
commit
6f3490dd36
@@ -0,0 +1,44 @@
|
||||
# syntax=docker/dockerfile:1.7
|
||||
# Multi-arch is produced by building this file on native amd64 and arm64 runners.
|
||||
# Keep both bases pinned to manifest-list digests so either architecture resolves
|
||||
# to immutable source bytes.
|
||||
FROM rust:1.95-alpine3.22@sha256:064dfc925d68d1a63f4fd2871bd7dc6e6ea56692989a487185855d62885d90aa AS builder
|
||||
|
||||
RUN apk add --no-cache \
|
||||
build-base \
|
||||
cmake \
|
||||
git \
|
||||
musl-dev \
|
||||
openssl-dev \
|
||||
openssl-libs-static \
|
||||
perl \
|
||||
pkgconf \
|
||||
protoc
|
||||
WORKDIR /build
|
||||
COPY . .
|
||||
RUN cargo build --locked --profile sprig -p sprig \
|
||||
&& strip target/sprig/sprig
|
||||
|
||||
FROM alpine:3.22@sha256:14358309a308569c32bdc37e2e0e9694be33a9d99e68afb0f5ff33cc1f695dce
|
||||
|
||||
RUN apk add --no-cache bash ca-certificates git \
|
||||
&& adduser -D -h /home/agent agent \
|
||||
&& install -d -o agent -g agent /workspace /home/agent \
|
||||
&& git config --system gpg.format x509 \
|
||||
&& git config --system gpg.x509.program /usr/local/bin/git-sign-nostr \
|
||||
&& git config --system commit.gpgSign true \
|
||||
&& git config --system tag.gpgSign true
|
||||
|
||||
COPY --from=builder --chmod=0755 /build/target/sprig/sprig /usr/local/bin/sprig
|
||||
COPY --chmod=0755 scripts/sprig-entrypoint.sh /usr/local/bin/sprig-entrypoint
|
||||
RUN for name in \
|
||||
buzz-acp buzz-agent buzz-dev-mcp rg tree buzz \
|
||||
git-credential-nostr git-sign-nostr; do \
|
||||
ln -s sprig "/usr/local/bin/$name"; \
|
||||
done
|
||||
|
||||
ENV HOME=/home/agent \
|
||||
PATH=/usr/local/bin:/usr/local/sbin:/usr/sbin:/usr/bin:/sbin:/bin
|
||||
WORKDIR /home/agent
|
||||
USER agent
|
||||
ENTRYPOINT ["/usr/local/bin/sprig-entrypoint"]
|
||||
Executable
+16
@@ -0,0 +1,16 @@
|
||||
#!/bin/bash
|
||||
set -euo pipefail
|
||||
|
||||
# Match desktop's URL-scoped git credential configuration without installing a
|
||||
# helper globally (which would make it answer for unrelated remotes).
|
||||
if [[ -n "${BUZZ_RELAY_URL:-}" ]]; then
|
||||
relay_http_url="${BUZZ_RELAY_URL/#ws:/http:}"
|
||||
relay_http_url="${relay_http_url/#wss:/https:}"
|
||||
relay_http_url="${relay_http_url%/}"
|
||||
git config --global "credential.${relay_http_url}/git.helper" \
|
||||
/usr/local/bin/git-credential-nostr
|
||||
git config --global "credential.${relay_http_url}/git.useHttpPath" true
|
||||
fi
|
||||
|
||||
# The harness must receive Kubernetes' termination signal directly.
|
||||
exec buzz-acp "$@"
|
||||
Executable
+43
@@ -0,0 +1,43 @@
|
||||
#!/usr/bin/env bash
|
||||
set -euo pipefail
|
||||
|
||||
IMAGE="${1:-buzz-sprig:contract-test}"
|
||||
if [[ "${SKIP_BUILD:-0}" != 1 ]]; then
|
||||
docker build --file Dockerfile.sprig --tag "$IMAGE" .
|
||||
fi
|
||||
|
||||
assert_run() {
|
||||
docker run --rm --entrypoint /bin/bash "$IMAGE" -ceu "$1"
|
||||
}
|
||||
|
||||
assert_run '
|
||||
command -v bash git update-ca-certificates >/dev/null
|
||||
test "$(readlink /usr/local/bin/buzz-acp)" = sprig
|
||||
for name in buzz-agent buzz-dev-mcp rg tree buzz git-credential-nostr git-sign-nostr; do
|
||||
test "$(readlink "/usr/local/bin/$name")" = sprig
|
||||
done
|
||||
test "$(git config --system gpg.x509.program)" = /usr/local/bin/git-sign-nostr
|
||||
! git config --system --get-all credential.helper
|
||||
test "$HOME" = /home/agent
|
||||
test "$(pwd)" = /home/agent
|
||||
'
|
||||
|
||||
assert_run '
|
||||
grep -Eq "^[[:space:]]*exec buzz-acp" /usr/local/bin/sprig-entrypoint
|
||||
! grep -Eq "^[[:space:]]*(buzz-acp|bash -c .*buzz-acp)" /usr/local/bin/sprig-entrypoint
|
||||
'
|
||||
|
||||
docker run --rm --entrypoint /bin/bash \
|
||||
-e BUZZ_RELAY_URL=wss://relay.example.test/ "$IMAGE" -ceu '
|
||||
/usr/local/bin/sprig-entrypoint --help >/dev/null 2>&1 & pid=$!
|
||||
for _ in 1 2 3 4 5; do
|
||||
git config --global --get credential.https://relay.example.test/git.helper >/dev/null 2>&1 && break
|
||||
sleep 0.1
|
||||
done
|
||||
test "$(git config --global --get credential.https://relay.example.test/git.helper)" = /usr/local/bin/git-credential-nostr
|
||||
test "$(git config --global --get credential.https://relay.example.test/git.useHttpPath)" = true
|
||||
! git config --global --get-all credential.helper
|
||||
wait "$pid" || true
|
||||
'
|
||||
|
||||
echo "PASS: Sprig image runtime contract ($IMAGE)"
|
||||
Reference in New Issue
Block a user