Luigit
repositories / will

will

owned by admin

Containerfile.agent-base

Raw
# syntax=docker/dockerfile:1
# will-agent-base: full-dev Arch runtime for the agent container (spec AC2/AC3):
# passwordless sudo for will, git + ssh client (never a running sshd),
# diagnostics, man pages, arch-wiki-lite. OpenSSH provides the client only;
# no host keys are generated and no sshd unit exists.
FROM docker.io/library/archlinux:base

RUN pacman-key --init && pacman -Sy --noconfirm --needed \
      archlinux-keyring ca-certificates \
    && pacman -Su --noconfirm \
    && pacman -S --noconfirm --needed \
      sudo git openssh grep findutils ripgrep fd curl vim jq sqlite htop less \
      base-devel tmux man-db man-pages arch-wiki-lite zstd nodejs \
    && paccache -rfk0 || true \
    && useradd --create-home --shell /bin/bash will \
    && mkdir -p /etc/sudoers.d \
    && printf 'will ALL=(ALL) NOPASSWD: ALL\n' > /etc/sudoers.d/will \
    && chmod 440 /etc/sudoers.d/will \
    && rm -f /etc/ssh/ssh_host_* \
    && systemctl disable sshd 2>/dev/null || true \
    && mkdir -p /srv/will-agent && chown will:will /srv/will-agent