# The themed interactive "computer terminal" for the agent's Terminal app: # zsh + oh-my-zsh + powerlevel10k. Runs as uid 65532 — matching the server's # nonroot uid — so the terminal and the server share read-write ownership of the # file-drive volume (~/drives). cap-drop ALL, seccomp deny profile, # no-new-privileges. Unlike the hardened tool sandboxes it keeps a writable home # so the baked p10k config, completion cache and shell history work. FROM debian:bookworm-slim ENV LANG=C.UTF-8 \ LC_ALL=C.UTF-8 \ TERM=xterm-256color # A small but useful dev toolbelt; no setuid binaries survive (no priv-esc). RUN apt-get update \ && apt-get install -y --no-install-recommends \ zsh tmux git curl ca-certificates less nano procps coreutils \ && rm -rf /var/lib/apt/lists/* \ && useradd --uid 65532 --user-group --create-home --shell /usr/bin/zsh agent \ && find / -xdev -perm /6000 -type f -delete USER 65532:65532 WORKDIR /home/agent ENV HOME=/home/agent \ ZSH=/home/agent/.oh-my-zsh # oh-my-zsh + powerlevel10k + quality-of-life plugins (built with egress; the # running container's egress is a separate, default-off config knob). RUN git clone --depth=1 https://github.com/ohmyzsh/ohmyzsh.git "$ZSH" \ && git clone --depth=1 https://github.com/romkatv/powerlevel10k.git \ "$ZSH/custom/themes/powerlevel10k" \ && git clone --depth=1 https://github.com/zsh-users/zsh-autosuggestions \ "$ZSH/custom/plugins/zsh-autosuggestions" \ && git clone --depth=1 https://github.com/zsh-users/zsh-syntax-highlighting \ "$ZSH/custom/plugins/zsh-syntax-highlighting" COPY --chown=65532:65532 zdotdir/.zshrc /home/agent/.zshrc COPY --chown=65532:65532 zdotdir/.p10k.zsh /home/agent/.p10k.zsh COPY --chown=65532:65532 zdotdir/.tmux.conf /home/agent/.tmux.conf # Pre-create the drives mount root owned by the runtime user, so when a fresh # per-agent node-local volume mounts here (node-placed terminal) Docker seeds it # with this ownership — i.e. the non-root shell can actually write ~/drives. RUN mkdir -p /home/agent/drives # Idle keep-alive; the server execs an interactive tmux/zsh into the container. CMD ["sleep", "infinity"]