Files
clawmates/images/agent-claude/Dockerfile
T
Omar Sobh 8b12245e79 chore(image): promote Claude Code 2.1.226 after the canary passed
Canary first, production second — the point of pinning is that the upgrade is a
decision, and the point of `canary-claude` is that the decision has evidence.

Taken for 2.1.225's fix to a transient 401 that replaced a long-lived
CLAUDE_CODE_OAUTH_TOKEN with a short-lived one and broke HEADLESS sessions until
restart. Our sessions are headless and our VMs are per-mission, so "until
restart" reads as a failed phase.

The 2.1.225 workspace-trust prompt does NOT apply: `--help` states the dialog is
skipped in non-interactive mode (`-p`, or stdout not a TTY) and we satisfy both.
Read from the CLI in a booted 2.1.226 VM rather than inferred from the changelog.

Verified on the production path after the rebuild: guest kernel 6.1.128,
delegation to a subagent, `--settings` stop gate installed, judge independent
(glm-4.7), single writer. 6/6.

`rootfs-canary-claude.ext4` is left on tank as the mechanism for the next
candidate, not as a leftover.
2026-08-08 05:47:25 -07:00

49 lines
2.5 KiB
Docker

# Plan A6, first of three: one image per agent CLI, independently versioned.
#
# Everything shared lives in agent-toolchain (git, node, rust, scanners, tea).
# This layer is only the CLI and its env contract, so bumping Claude Code does
# not rebuild 3 GB of toolchain and cannot disturb agent-kimi / agent-glm.
#
# Build (on the node that will run it — see agent-toolchain for why this is not
# in AGENT_IMAGES):
#
# ssh osobh@tank "cd ~/clawmates && \
# docker build -f images/agent-toolchain/Dockerfile -t clawmates/agent-toolchain:dev images/agent-toolchain/ && \
# docker build -f images/agent-claude/Dockerfile -t clawmates/agent-claude:dev images/agent-claude/"
#
# Then turn it into a microVM rootfs and prove a VM boots from it:
#
# scripts/fc-build-rootfs.sh osobh@tank clawmates/agent-claude:dev claude 8G
FROM clawmates/agent-toolchain:dev
# Pinned: an unpinned `npm i -g` makes the image's behaviour depend on the day
# it was built, and a mission that regresses would have no version to compare.
#
# 2.1.223, up from 2.1.220, for one reason that matters to how we use subagents:
# 2.1.222 "Fixed PreToolUse auto-allow hooks bypassing tool restrictions in
# background agent tasks". Subagents run in the background by default since
# 2.1.198, and our `verifier` role's whole guarantee is a TOOL RESTRICTION — no
# Edit, no Write — so on 2.1.220 the one property we rely on was the one the bug
# could undo. 2.1.221 also fixes `--mcp-config` servers not connecting before the
# first turn in print mode, which is exactly the mode we run and will matter when
# the MCP door reaches a VM.
ARG CLAUDE_CODE_VERSION=2.1.226
RUN npm install -g "@anthropic-ai/claude-code@${CLAUDE_CODE_VERSION}" \
&& npm cache clean --force \
&& rm -rf /root/.npm \
&& claude --version
# The CLI reads its credentials from $HOME/.claude. On the container path HOME is
# /zeroclaw-data because the daemon owns it; here there is no daemon, so HOME is
# just root's home. Credential injection (B4.4) writes into this directory over
# vsock at VM start so the credentials live and die with the VM and are never
# baked into the image.
ENV HOME=/root \
CLAWMATES_AGENT_CLI=claude
RUN mkdir -p /root/.claude
# No ANTHROPIC_API_KEY, and none is accepted: this backend authenticates by
# subscription via CLAUDE_CODE_OAUTH_TOKEN. An API key present in the
# environment silently overrides the subscription OAuth (fixed once already,
# task #16) and would bill per-token against a plan we already pay for.