Files
clawmates/images/agent-terminal/Dockerfile
T
Omar SobhandClaude Opus 4.8 e61724ff82 Agent computer: terminal (tmux + drives + tabs), Obsidian vault, UI polish
Terminal app (xterm ⇄ WebSocket ⇄ per-agent themed container):
- zsh + oh-my-zsh + powerlevel10k image (agent-terminal), runs as uid 65532 to
  share read-write ownership of the file-drive volume with the server.
- Interactive PTY in cm-sandbox (bollard exec tty/attach + resize) + a
  TerminalManager; ticket-authed WS bridge routed straight to the backend via a
  Traefik PathRegexp(/ws) rule. MOTD greets the user by name.
- tmux resumable sessions; multi-tab (one tmux session per tab, same container),
  drag-to-reorder, rename, and a Save that persists named tabs to the server
  (terminal_tabs, migration 0014) so they survive logout / a new device.
- Files drives mounted per-agent (subpath) at ~/drives/{documents,received,
  shared}; a reconciler keeps the Files app's index in sync with terminal writes.
  Storage moved to a shared `filedata` volume (CLAWMATES_STORAGE__DATA_DIR).

Obsidian vault (a markdown "second brain" per agent):
- New `vault` FileDrive (migration 0015) mounted into the terminal at ~/obsidian;
  a file-content read route; a purple Obsidian tile + a vault viewer app.

Computer UI:
- Draggable computer-panel width (min = phone preset) keeping the size presets.
- Green Terminal glyph, "Claw Chat" → "Chat", colored gradient-outline app icons.
- Agent page: avatar↔activity-grid spacing + larger, uniform section fonts with
  colored section-tinted tag chips.

Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
2026-06-23 16:52:35 -07:00

42 lines
1.9 KiB
Docker

# The themed interactive "computer terminal" for the agent's Terminal app:
# zsh + oh-my-zsh + powerlevel10k. Runs as uid 65532 — matching the server's
# nonroot uid — so the terminal and the server share read-write ownership of the
# file-drive volume (~/drives). cap-drop ALL, seccomp deny profile,
# no-new-privileges. Unlike the hardened tool sandboxes it keeps a writable home
# so the baked p10k config, completion cache and shell history work.
FROM debian:bookworm-slim
ENV LANG=C.UTF-8 \
LC_ALL=C.UTF-8 \
TERM=xterm-256color
# A small but useful dev toolbelt; no setuid binaries survive (no priv-esc).
RUN apt-get update \
&& apt-get install -y --no-install-recommends \
zsh tmux git curl ca-certificates less nano procps coreutils \
&& rm -rf /var/lib/apt/lists/* \
&& useradd --uid 65532 --user-group --create-home --shell /usr/bin/zsh agent \
&& find / -xdev -perm /6000 -type f -delete
USER 65532:65532
WORKDIR /home/agent
ENV HOME=/home/agent \
ZSH=/home/agent/.oh-my-zsh
# oh-my-zsh + powerlevel10k + quality-of-life plugins (built with egress; the
# running container's egress is a separate, default-off config knob).
RUN git clone --depth=1 https://github.com/ohmyzsh/ohmyzsh.git "$ZSH" \
&& git clone --depth=1 https://github.com/romkatv/powerlevel10k.git \
"$ZSH/custom/themes/powerlevel10k" \
&& git clone --depth=1 https://github.com/zsh-users/zsh-autosuggestions \
"$ZSH/custom/plugins/zsh-autosuggestions" \
&& git clone --depth=1 https://github.com/zsh-users/zsh-syntax-highlighting \
"$ZSH/custom/plugins/zsh-syntax-highlighting"
COPY --chown=65532:65532 zdotdir/.zshrc /home/agent/.zshrc
COPY --chown=65532:65532 zdotdir/.p10k.zsh /home/agent/.p10k.zsh
COPY --chown=65532:65532 zdotdir/.tmux.conf /home/agent/.tmux.conf
# Idle keep-alive; the server execs an interactive tmux/zsh into the container.
CMD ["sleep", "infinity"]