# Plan A6, first of three: one image per agent CLI, independently versioned. # # Everything shared lives in agent-toolchain (git, node, rust, scanners, tea). # This layer is only the CLI and its env contract, so bumping Claude Code does # not rebuild 3 GB of toolchain and cannot disturb agent-kimi / agent-glm. # # Build (on the node that will run it — see agent-toolchain for why this is not # in AGENT_IMAGES): # # ssh osobh@tank "cd ~/clawmates && \ # docker build -f images/agent-toolchain/Dockerfile -t clawmates/agent-toolchain:dev images/agent-toolchain/ && \ # docker build -f images/agent-claude/Dockerfile -t clawmates/agent-claude:dev images/agent-claude/" # # Then turn it into a microVM rootfs and prove a VM boots from it: # # scripts/fc-build-rootfs.sh osobh@tank clawmates/agent-claude:dev claude 8G FROM clawmates/agent-toolchain:dev # Pinned: an unpinned `npm i -g` makes the image's behaviour depend on the day # it was built, and a mission that regresses would have no version to compare. # # 2.1.223, up from 2.1.220, for one reason that matters to how we use subagents: # 2.1.222 "Fixed PreToolUse auto-allow hooks bypassing tool restrictions in # background agent tasks". Subagents run in the background by default since # 2.1.198, and our `verifier` role's whole guarantee is a TOOL RESTRICTION — no # Edit, no Write — so on 2.1.220 the one property we rely on was the one the bug # could undo. 2.1.221 also fixes `--mcp-config` servers not connecting before the # first turn in print mode, which is exactly the mode we run and will matter when # the MCP door reaches a VM. ARG CLAUDE_CODE_VERSION=2.1.226 RUN npm install -g "@anthropic-ai/claude-code@${CLAUDE_CODE_VERSION}" \ && npm cache clean --force \ && rm -rf /root/.npm \ && claude --version # The CLI reads its credentials from $HOME/.claude. On the container path HOME is # /zeroclaw-data because the daemon owns it; here there is no daemon, so HOME is # just root's home. Credential injection (B4.4) writes into this directory over # vsock at VM start so the credentials live and die with the VM and are never # baked into the image. ENV HOME=/root \ CLAWMATES_AGENT_CLI=claude RUN mkdir -p /root/.claude # No ANTHROPIC_API_KEY, and none is accepted: this backend authenticates by # subscription via CLAUDE_CODE_OAUTH_TOKEN. An API key present in the # environment silently overrides the subscription OAuth (fixed once already, # task #16) and would bill per-token against a plan we already pay for.