# syntax=docker/dockerfile:1 # will-agent: the root-capable senses-and-muscles container. # Base is a digest-pinned Arch runtime with node, sudo, git, diagnostics. ARG AGENT_BASE=ghcr.io/bugabinga/will-agent-base:latest FROM ${AGENT_BASE} # Lockfile-pinned runtime tree: pi SDK, official MCP SDK, pinned ZAI MCP server. COPY package.json package-lock.json /app/ RUN npm ci --omit=dev && npm cache clean --force # Bundled will agent code (pi tree stays normally installed, not bundled). COPY dist/agent.js /app/ # Immutable operational resources loaded by the resident session. COPY persona/ /app/repo/persona/ # Repository-local Pi settings belong to the developer, not will. Package # only will's runtime skills; wake events are rendered by the harness. COPY .pi/skills/ /app/repo/.pi/skills/ COPY AGENTS.md /app/repo/AGENTS.md # Passwordless unrestricted sudo for user will is configured in agent-base # (spec: intentional, contained by the container boundary). USER will ENV NODE_ENV=production \ WILL_AGENT_DIR=/srv/will-agent \ WILL_RESOURCE_DIR=/app/repo \ WILL_SERVICE_INTERNAL_URL=http://127.0.0.1:3001 \ WILL_AGENT_READY_ADDR=127.0.0.1:8081 VOLUME /srv/will-agent EXPOSE 8081 ENTRYPOINT ["node", "/app/agent.js"]