mirror of
https://github.com/rennf93/roboco.git
synced 2026-08-03 07:23:24 +02:00
fix(docker): install codex CLI via npm, not the CDN-denied installer
The chatgpt.com/codex/install.sh installer returns 'resource is denied' to non-browser clients in CI, breaking the agent-codex image build. Switch to npm install -g @openai/codex@<pinned>: the package has no postinstall network fetch (verified) — its native binary rides an optionalDependency served from the public npm registry, and node is already in the base image. Verified locally: install succeeds, codex --version runs.
This commit is contained in:
@@ -19,18 +19,17 @@ FROM roboco-agent-base
|
|||||||
|
|
||||||
USER root
|
USER root
|
||||||
|
|
||||||
# Install the official codex CLI for the agent user. Pinned — untrusted model
|
# Install the official codex CLI globally via npm. Pinned — untrusted model
|
||||||
# output runs under it, so bump the version deliberately, never float. Download
|
# output runs under it, so bump the version deliberately, never float. The
|
||||||
# the installer to a file first (a `curl | bash` pipe hides a curl failure as a
|
# npm route (not chatgpt.com/codex/install.sh, which the CDN denies to
|
||||||
# silent no-op) and verify the binary installed AND runs, so a broken install
|
# non-browser clients) has no postinstall network fetch: the native binary
|
||||||
# fails the build here, not at spawn. (curl/bash from the base.)
|
# rides an optionalDependency (@openai/codex-linux-x64) served from the
|
||||||
|
# public npm registry. Global install symlinks `codex` onto PATH for the
|
||||||
|
# agent user; verify it runs so a broken install fails the build, not spawn.
|
||||||
ARG CODEX_CLI_VERSION=0.145.0
|
ARG CODEX_CLI_VERSION=0.145.0
|
||||||
RUN su agent -s /bin/bash -c "set -euo pipefail; export HOME=/home/agent; \
|
RUN npm install -g @openai/codex@${CODEX_CLI_VERSION} \
|
||||||
curl -fsSL https://chatgpt.com/codex/install.sh -o /tmp/codex-install.sh; \
|
&& command -v codex \
|
||||||
bash /tmp/codex-install.sh ${CODEX_CLI_VERSION}; \
|
&& codex --version
|
||||||
test -x /home/agent/.codex/bin/codex || command -v codex; \
|
|
||||||
codex --version" \
|
|
||||||
&& rm -rf /tmp/*
|
|
||||||
|
|
||||||
# Entrypoint: render ~/.codex/config.toml + execpolicy rules + the per-role
|
# Entrypoint: render ~/.codex/config.toml + execpolicy rules + the per-role
|
||||||
# sandbox flag, then run codex headless (overrides the base image's `claude`
|
# sandbox flag, then run codex headless (overrides the base image's `claude`
|
||||||
|
|||||||
Reference in New Issue
Block a user