-
Notifications
You must be signed in to change notification settings - Fork 1
Expand file tree
/
Copy pathDockerfile.sandbox-runtime
More file actions
63 lines (57 loc) · 2.04 KB
/
Copy pathDockerfile.sandbox-runtime
File metadata and controls
63 lines (57 loc) · 2.04 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
# Local-dev code sandbox for ContextMemory self-hosted-sandbox tools.
# Runs shell / python / node via POST /execute. Not full gVisor isolation.
FROM node:22-bookworm-slim
LABEL org.opencontainers.image.source="https://github.com/Kortexio/ContextMemory"
LABEL org.opencontainers.image.description="ContextMemory local-dev code sandbox"
# System deps: Python, jq, git, Azure CLI (ops triage fallback), and Chromium for Playwright.
RUN apt-get update \
&& apt-get install -y --no-install-recommends \
python3 \
python3-pip \
curl \
ca-certificates \
jq \
git \
apt-transport-https \
lsb-release \
gnupg \
&& curl -sL https://aka.ms/InstallAzureCLIDeb | bash \
&& pip3 install --no-cache-dir --break-system-packages \
requests \
httpx \
beautifulsoup4 \
lxml \
html2text \
pyyaml \
python-dateutil \
openpyxl \
PyJWT \
duckduckgo-search \
playwright \
&& playwright install --with-deps chromium \
&& pip3 install --no-cache-dir --break-system-packages ddgs \
&& rm -rf /var/lib/apt/lists/* \
&& mkdir -p /app \
&& useradd -m -u 10001 sandboxuser \
&& mkdir -p /home/sandboxuser/.cache \
&& cp -a /root/.cache/ms-playwright /home/sandboxuser/.cache/ms-playwright \
&& chown -R sandboxuser:sandboxuser /home/sandboxuser \
&& az version >/dev/null \
&& git --version >/dev/null
WORKDIR /app
COPY sandbox-runtime/package.json ./
COPY sandbox-runtime/server.mjs ./
COPY sandbox-runtime/docker-entrypoint.sh ./docker-entrypoint.sh
RUN chmod +x /app/docker-entrypoint.sh \
&& chown -R sandboxuser:sandboxuser /app
ENV PORT=8080 \
NODE_ENV=production \
SANDBOX_TIMEOUT_MS=60000 \
SANDBOX_MAX_OUTPUT_CHARS=32000 \
SANDBOX_ALLOW_EGRESS=true \
PLAYWRIGHT_BROWSERS_PATH=/home/sandboxuser/.cache/ms-playwright
USER sandboxuser
EXPOSE 8080
HEALTHCHECK --interval=15s --timeout=5s --start-period=20s --retries=5 \
CMD curl -fsS http://127.0.0.1:8080/health || exit 1
ENTRYPOINT ["/app/docker-entrypoint.sh"]