# Plan A6, second of three: Claude Code pointed at GLM.
#
# The same CLI as `agent-claude`, the same toolchain underneath, and a different
# endpoint. That is the whole difference, and it is deliberate: z.ai serves an
# Anthropic-compatible API, so a second provider costs an env contract rather
# than a second agent harness with its own failure modes.
#
# Why this image exists at all: a composed mission's `verifier` node reviewing
# work its own model wrote is a correlated failure — the same one the
# cross-provider judge exists to break, one layer down. A roster can only put a
# node on another provider if another provider's rootfs is on the fleet.
#
# Build (on the node that will run it):
#
#   ssh osobh@tank "cd ~/clawmates && \
#     docker build -f images/agent-glm/Dockerfile -t clawmates/agent-glm:dev images/agent-glm/"
#   scripts/fc-build-rootfs.sh osobh@tank clawmates/agent-glm:dev glm 8G
FROM clawmates/agent-toolchain:dev

# Pinned to the SAME version as agent-claude on purpose. A solo run and a
# composed run's verifier node should differ by provider and by nothing else; two
# CLI versions in one graph would make "the verifier disagreed" ambiguous between
# the model and the harness.
ARG CLAUDE_CODE_VERSION=2.1.223
RUN npm install -g "@anthropic-ai/claude-code@${CLAUDE_CODE_VERSION}" \
    && npm cache clean --force \
    && rm -rf /root/.npm \
    && claude --version

# The endpoint is baked in; the CREDENTIAL never is. `mission_runtime::
# microvm_provider_env` injects `ANTHROPIC_AUTH_TOKEN` from the server's
# `ZAI_API_KEY` at turn time, so the key lives and dies with the VM.
#
# Baking the base URL rather than injecting it is the safer half of the split: an
# image whose URL is fixed cannot be handed a token for one provider and an
# endpoint for another. That mix-up — an Anthropic subscription token sent to
# z.ai — is precisely what `microvm_credential_for` refuses to allow.
ENV HOME=/root \
    CLAWMATES_AGENT_CLI=claude \
    ANTHROPIC_BASE_URL=https://api.z.ai/api/anthropic
RUN mkdir -p /root/.claude

# No CLAUDE_CODE_OAUTH_TOKEN and no ANTHROPIC_API_KEY: this backend authenticates
# with a z.ai key alone. The subscription token must never reach this image —
# it would be sent, verbatim, to another company's endpoint.
