mirror of
https://github.com/rennf93/roboco.git
synced 2026-08-03 07:23:24 +02:00
feat(grok): start the in-container SDK server + budget feed (Claude parity)
The keystone of the Grok parity work (CEO's "take Claude as baseline, create what's missing" call): the one-shot Grok container now starts the same SDK server the Claude path runs, so the per-verb circuit breaker (the flow/do MCP servers already POST /verb/attempted to it), the per-session budget/loop counters, the terminal-verb tracking, and the SessionEnd post-mortem all work on Grok instead of being silently absent. - entrypoint: launch roboco.agent_sdk.server (bare venv python, not `uv run` which would re-sync the drifted clone lock and stall), wait for /health, reset counters; run opencode WITHOUT exec so the script regains control to run the post-mortem and the silent-exit substitute after the run returns. - budget-feed.js: opencode plugin that gates on /budget/status in tool.execute.before (halt/loop deny — the only place to stop a runaway one-shot run; opencode has no PostToolUse-deny) and records the executed tool + args-hash in tool.execute.after. Fail-open; bare-verb normalization for MCP-namespaced terminal verbs. - silent-exit substitute: on a graceful exit with no terminal verb the entrypoint posts /terminal/force_substitute so the task isn't left stuck claimed/in_progress (Stop-hook parity at the boundary). - opencode_config: wire budget-feed into the plugin array; add ROBOCO_OPENCODE_EXTRA_PLUGINS so per-image role tool plugins load scoped to one role; read the per-role ROBOCO_GROK_EDIT_PERMISSION. Targeted gate green (ruff/mypy/xenon + opencode_config tests; node --check on the plugins; bash -n on the entrypoint).
This commit is contained in:
@@ -21,9 +21,13 @@ RUN npm install -g opencode-ai @ai-sdk/openai \
|
||||
&& npm cache clean --force \
|
||||
&& rm -rf /root/.npm /tmp/*
|
||||
|
||||
# Command guard / secret-scrub plugin (bash-guard parity for the opencode runtime).
|
||||
# Referenced from the generated opencode.json `plugin:` array.
|
||||
# opencode plugins (referenced from the generated opencode.json `plugin:` array):
|
||||
# secret-scrub — bash-guard parity (PAT/credential deny on tool.execute.before)
|
||||
# budget-feed — POSTs budget/loop/terminal counters to the in-container SDK
|
||||
# server (tool.execute.{before,after}); the entrypoint starts
|
||||
# that server (roboco.agent_sdk.server) for Claude-parity.
|
||||
COPY docker/grok/secret-scrub.js /app/opencode-plugins/secret-scrub.js
|
||||
COPY docker/grok/budget-feed.js /app/opencode-plugins/budget-feed.js
|
||||
|
||||
# Entrypoint: render opencode.json, then run opencode (overrides base's `claude`).
|
||||
COPY docker/scripts/grok-agent-entrypoint.sh /app/scripts/grok-agent-entrypoint.sh
|
||||
|
||||
Reference in New Issue
Block a user