mirror of
https://github.com/rennf93/roboco.git
synced 2026-08-03 07:23:24 +02:00
* feat(kimi): Kimi K3 provider on the official kimi-code CLI (Wave 1) ModelProvider.KIMI routes through KimiCliProvider driving Moonshot's kimi CLI on a Kimi subscription (OAuth device-code, no metered key). One-shot delivery roles only (V1), interactive ban wired in both guard lists. Auth: one shared RW auth mount; containers symlink credentials/ and oauth/ (the CLI's cross-process refresh-lock dir) into a container-local KIMI_CODE_HOME so every container and the host redeem the SAME rotating refresh chain - live-verified that per-copy chains cross-invalidate after the reuse-grace window. No orchestrator refresh daemon; an expires_at preflight exits 78. Config renderer mirrors the login-managed provider/model blocks field-for-field (live-captured; the model value is the CLI-side name, never the raw API id), plus per-role deny rules and the bash-guard as a PreToolUse hook via a wrapper script (an env key on a hooks entry makes the CLI silently drop ALL hooks - live-verified). Usage capture sums wire.jsonl usage.record 4-bucket events; sniff classifies rate-limit/auth from structured error text only, mapped to the shared 75/78 park contract. Image installs the CLI latest-at-build (no version pin, by policy) with the resolved version stamped as provenance, binary split to /usr/local away from mutable state. Migrations 090 (enum) + 091 (provider seed); catalog, pricing, routing mode, and orchestrator park/usage wiring mirror the codex integration. * feat(kimi): surface sweep + fleet-wide pin drop (Wave 2) Compose x3 gain the agent-kimi-image service and the orchestrator's read-write ~/.kimi-code mount + kimi-usage dir; .env.example documents the Kimi block. Panel mirrors ModelProvider.KIMI and adds the kimi routing mode (catalog filter, mode button, mix-picker group, badge) with tests; provider routes gain the kimi remediation entry. CLAUDE.md and docs/map document the runtime. Per the no-pins policy, agent-grok/ gemini/codex Dockerfiles drop their version pins for latest-at-build with resolved-version provenance stamps (grok resolves 0.2.112 vs the old 0.2.56 pin - verified by real builds of all four images). --------- Co-authored-by: Renn F <rennf93@users.noreply.github.com>
51 lines
2.5 KiB
Docker
51 lines
2.5 KiB
Docker
# Gemini (Google) Agent Image
|
|
# =============================================================================
|
|
# Runs Gemini through Google's official `gemini` CLI, authenticated by an OAuth
|
|
# login via a mounted ~/.gemini/oauth_creds.json — the parity analogue of the
|
|
# Claude Code path's mounted ~/.claude and the grok path's mounted ~/.grok (no
|
|
# metered API key). Reuses the base image's roboco venv + uv + the RoboCo MCP
|
|
# gateway servers, and the base image's Node.js 22 (the CLI needs node >= 20).
|
|
# The entrypoint copies the staged read-only OAuth credential into a writable
|
|
# ~/.gemini, renders ~/.gemini/settings.json + a Policy Engine TOML from the
|
|
# mounted mcp-config.json (see roboco.llm.providers.gemini_cli_config), and
|
|
# runs the CLI headless. One runtime image serves every role — role behaviour
|
|
# comes from the mounted system prompt / manifest / mcp-config, exactly as on
|
|
# the Claude/grok paths.
|
|
# =============================================================================
|
|
|
|
FROM roboco-agent-base
|
|
|
|
USER root
|
|
|
|
# Install the official Gemini CLI. NO version pin (2026-07-28 policy:
|
|
# latest-at-build, always adapt — fleet-wide across grok/gemini/codex/kimi).
|
|
# npm installs to the global node_modules the base image's Node 22 already
|
|
# resolves onto PATH; the resolved version is stamped to /etc/gemini-cli-version
|
|
# for per-image provenance (a record, not a pin).
|
|
RUN npm install -g @google/gemini-cli \
|
|
&& npm cache clean --force \
|
|
&& rm -rf /root/.npm /tmp/* \
|
|
&& command -v gemini \
|
|
&& gemini --version | tee /etc/gemini-cli-version
|
|
|
|
# Entrypoint: copy the staged OAuth credential into a writable ~/.gemini,
|
|
# render settings.json + policy TOML, then run gemini headless (overrides the
|
|
# base image's `claude` entrypoint). Owned by agent (mirrors the grok image).
|
|
COPY docker/scripts/gemini-cli-agent-entrypoint.sh /app/scripts/gemini-cli-agent-entrypoint.sh
|
|
RUN chmod 0755 /app/scripts/gemini-cli-agent-entrypoint.sh \
|
|
&& mkdir -p /home/agent/.gemini \
|
|
&& chown -R agent:agent /home/agent/.gemini
|
|
|
|
USER agent
|
|
|
|
LABEL role="gemini-cli-runtime"
|
|
LABEL description="Gemini (Google) agent runtime — Gemini Build via the official gemini CLI"
|
|
LABEL gemini.cli.pinned="false"
|
|
|
|
# advanced.autoConfigureMemory=false (rendered into settings.json) pins Node's
|
|
# heap sizing away from auto-detection against a shared host; this bounds it
|
|
# explicitly instead. Tunable per-deploy without a rebuild.
|
|
ENV NODE_OPTIONS="--max-old-space-size=2048"
|
|
|
|
ENTRYPOINT ["/app/scripts/gemini-cli-agent-entrypoint.sh"]
|