- agent-dev-fe / agent-qa-fe: remove playwright chromium + its system libs (~770MB each; verified unused — panel tests are vitest, e2e harness is scripted Python; pnpm kept)
- agent-grok: drop the redundant chown -R that duplicated the 149MB CLI tree into a second layer (install already runs as agent)
- agent-base + orchestrator runners: split the single /app COPY into .venv-first / source-last layers so a source-only deploy re-layers ~13MB instead of ~380MB per image
- agent-base: split the 813MB apt+node+claude-code RUN so a CLI bump no longer re-downloads the OS/node layer
- .dockerignore: exclude gitignored docs/internal from the orchestrator's docs COPY; pin uv helper image to 0.11
- verified: all four images rebuilt + runtime-probed (claude/git/jq/node/uv/pnpm/grok, import roboco, docs/alembic/agents present); .venv layer proven CACHED across a source-only change
2. Multi-image Docker architecture - Created role-specific Dockerfiles:
- agent-base.Dockerfile (shared foundation)
- agent-pm.Dockerfile, agent-dev-be.Dockerfile, agent-dev-fe.Dockerfile
- agent-qa-be.Dockerfile, agent-qa-fe.Dockerfile, agent-doc.Dockerfile, agent-ux.Dockerfile
3. Orchestrator updates - roboco/runtime/orchestrator.py:
- Added AGENT_IMAGES mapping and get_agent_image() function
- Updated _ensure_agent_image() to build base + specialized images
- Updated _spawn_container() to use role-specific image
- Made _generate_mcp_config() role-aware (though kept notify for all since they need to receive)